AffiliateWP – Leaderboard Security & Risk Analysis

wordpress.org/plugins/affiliatewp-leaderboard

Display an affiliate leaderboard on your website

1K active installs v1.2.0 PHP 7.4+ WP 5.2+ Updated May 8, 2025
affiliate-performanceaffiliatewpleaderboardshortcodetop-affiliates
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AffiliateWP – Leaderboard Safe to Use in 2026?

Generally Safe

Score 100/100

AffiliateWP – Leaderboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The affiliatewp-leaderboard v1.2.0 plugin presents a generally good security posture, primarily due to its adherence to secure coding practices in the analyzed areas. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the lack of external HTTP requests are strong indicators of careful development. Furthermore, the plugin has no recorded vulnerabilities, which suggests a history of stable and secure operation.

However, the static analysis does reveal some areas for concern that could be exploited. The presence of one shortcode as an entry point, without any explicit capability checks or nonce validation, represents a potential vector for unauthorized actions or information disclosure if the shortcode's functionality is not inherently secure. While the taint analysis found no critical or high-severity flows, the limited scope of analysis (0 flows analyzed) means this finding should be interpreted with caution. The output escaping, while at 78%, still leaves a portion of outputs unescaped, which could lead to cross-site scripting vulnerabilities in specific scenarios.

In conclusion, the plugin demonstrates a solid foundation in secure coding, particularly concerning database interactions and the avoidance of common risky functions. The most significant weaknesses lie in the unprotected shortcode and the potential for XSS due to incomplete output escaping. While the vulnerability history is clean, the identified weaknesses warrant attention to ensure the plugin remains secure.

Key Concerns

  • Unprotected shortcode entry point
  • Partially unescaped output (22%)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

AffiliateWP – Leaderboard Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AffiliateWP – Leaderboard Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
40 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped51 total outputs
Attack Surface

AffiliateWP – Leaderboard Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[affiliate_leaderboard] includes\class-affiliatewp-leaderboard.php:186
WordPress Hooks 6
actionaffwp_plugins_loadedaffiliatewp-leaderboard.php:111
actionplugins_loadedaffiliatewp-leaderboard.php:113
actionadmin_noticesincludes\class-activation.php:69
actionwp_headincludes\class-affiliatewp-leaderboard.php:189
filterplugin_row_metaincludes\class-affiliatewp-leaderboard.php:192
actionwidgets_initincludes\class-widget.php:137
Maintenance & Trust

AffiliateWP – Leaderboard Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 8, 2025
PHP min version7.4
Downloads22K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

AffiliateWP – Leaderboard Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect AffiliateWP – Leaderboard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliatewp-leaderboard/assets/css/frontend.css/wp-content/plugins/affiliatewp-leaderboard/assets/js/frontend.js
Script Paths
/wp-content/plugins/affiliatewp-leaderboard/assets/js/frontend.js
Version Parameters
affiliatewp-leaderboard/assets/css/frontend.css?ver=affiliatewp-leaderboard/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
affwp-leaderboard-wrapperaffwp-leaderboard-rankaffwp-leaderboard-nameaffwp-leaderboard-earningsaffiliatewp-leaderboard-empty
JS Globals
affwp_leaderboard_frontend_params
Shortcode Output
[affiliatewp_leaderboard]
FAQ

Frequently Asked Questions about AffiliateWP – Leaderboard