
AffiliateWP – Leaderboard Security & Risk Analysis
wordpress.org/plugins/affiliatewp-leaderboardDisplay an affiliate leaderboard on your website
Is AffiliateWP – Leaderboard Safe to Use in 2026?
Generally Safe
Score 100/100AffiliateWP – Leaderboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The affiliatewp-leaderboard v1.2.0 plugin presents a generally good security posture, primarily due to its adherence to secure coding practices in the analyzed areas. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the lack of external HTTP requests are strong indicators of careful development. Furthermore, the plugin has no recorded vulnerabilities, which suggests a history of stable and secure operation.
However, the static analysis does reveal some areas for concern that could be exploited. The presence of one shortcode as an entry point, without any explicit capability checks or nonce validation, represents a potential vector for unauthorized actions or information disclosure if the shortcode's functionality is not inherently secure. While the taint analysis found no critical or high-severity flows, the limited scope of analysis (0 flows analyzed) means this finding should be interpreted with caution. The output escaping, while at 78%, still leaves a portion of outputs unescaped, which could lead to cross-site scripting vulnerabilities in specific scenarios.
In conclusion, the plugin demonstrates a solid foundation in secure coding, particularly concerning database interactions and the avoidance of common risky functions. The most significant weaknesses lie in the unprotected shortcode and the potential for XSS due to incomplete output escaping. While the vulnerability history is clean, the identified weaknesses warrant attention to ensure the plugin remains secure.
Key Concerns
- Unprotected shortcode entry point
- Partially unescaped output (22%)
- No nonce checks
- No capability checks
AffiliateWP – Leaderboard Security Vulnerabilities
AffiliateWP – Leaderboard Code Analysis
Output Escaping
AffiliateWP – Leaderboard Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
AffiliateWP – Leaderboard Maintenance & Trust
Maintenance Signals
Community Trust
AffiliateWP – Leaderboard Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
AffiliateWP – Leaderboard Developer Profile
94 plugins · 23.5M total installs
How We Detect AffiliateWP – Leaderboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/affiliatewp-leaderboard/assets/css/frontend.css/wp-content/plugins/affiliatewp-leaderboard/assets/js/frontend.js/wp-content/plugins/affiliatewp-leaderboard/assets/js/frontend.jsaffiliatewp-leaderboard/assets/css/frontend.css?ver=affiliatewp-leaderboard/assets/js/frontend.js?ver=HTML / DOM Fingerprints
affwp-leaderboard-wrapperaffwp-leaderboard-rankaffwp-leaderboard-nameaffwp-leaderboard-earningsaffiliatewp-leaderboard-emptyaffwp_leaderboard_frontend_params[affiliatewp_leaderboard]