AffiliateWP – Order Details For Affiliates Security & Risk Analysis

wordpress.org/plugins/affiliatewp-order-details-for-affiliates

Allow affiliates to see order details on referrals they generated

2K active installs v1.3.0 PHP 7.4+ WP 5.2+ Updated May 8, 2025
affiliate-dashboardaffiliatewpcustomer-informationorder-detailsreferral-details
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AffiliateWP – Order Details For Affiliates Safe to Use in 2026?

Generally Safe

Score 100/100

AffiliateWP – Order Details For Affiliates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The plugin 'affiliatewp-order-details-for-affiliates' v1.3.0 demonstrates a generally good security posture based on the provided static analysis. The absence of any known CVEs and a lack of critical or high severity taint flows are positive indicators. The plugin also appears to handle its SQL queries using prepared statements, which is a strong practice against SQL injection vulnerabilities. However, there are areas for concern. The most significant is the low percentage of properly escaped output (15%), suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care before being displayed. The lack of nonce checks on the single shortcode entry point also raises a red flag, as it could be exploited in certain scenarios, especially if the shortcode performs sensitive actions. While the plugin has a clean vulnerability history, the presence of unescaped output and missing nonce checks indicates that it is not entirely free from risk. Continuous monitoring and addressing these specific coding practices are crucial for maintaining a secure plugin.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks on shortcode
Vulnerabilities
None known

AffiliateWP – Order Details For Affiliates Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AffiliateWP – Order Details For Affiliates Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

15% escaped27 total outputs
Attack Surface

AffiliateWP – Order Details For Affiliates Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[affiliate_order_details] includes\class-shortcodes.php:21
WordPress Hooks 15
actionaffwp_plugins_loadedaffiliatewp-order-details-for-affiliates.php:109
actionplugins_loadedaffiliatewp-order-details-for-affiliates.php:111
actionadmin_noticesincludes\class-activation.php:108
actionaffwp_update_affiliateincludes\class-admin.php:18
actionaffwp_edit_affiliate_bottomincludes\class-admin.php:21
filteraffwp_settings_integrationsincludes\class-admin.php:24
actionaffwp_affiliate_dashboard_tabsincludes\class-affiliatewp-order-details-for-affiliates.php:184
actiontemplate_redirectincludes\class-affiliatewp-order-details-for-affiliates.php:187
actionwp_headincludes\class-affiliatewp-order-details-for-affiliates.php:190
filterplugin_row_metaincludes\class-affiliatewp-order-details-for-affiliates.php:193
filteraffwp_template_pathsincludes\class-affiliatewp-order-details-for-affiliates.php:196
filteraffwp_affiliate_area_tabsincludes\class-affiliatewp-order-details-for-affiliates.php:199
actionaffwp_complete_referralincludes\class-emails.php:18
filterwp_mail_content_typeincludes\class-emails.php:77
filteraffwp_force_frontend_scriptsincludes\class-shortcodes.php:18
Maintenance & Trust

AffiliateWP – Order Details For Affiliates Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 8, 2025
PHP min version7.4
Downloads29K

Community Trust

Rating0/100
Number of ratings0
Active installs2K
Developer Profile

AffiliateWP – Order Details For Affiliates Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect AffiliateWP – Order Details For Affiliates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliatewp-order-details-for-affiliates/assets/css/odfa-public.css/wp-content/plugins/affiliatewp-order-details-for-affiliates/assets/js/odfa-public.js
Version Parameters
affiliatewp-order-details-for-affiliates/assets/css/odfa-public.css?ver=affiliatewp-order-details-for-affiliates/assets/js/odfa-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
affwp-odfa-order-details
Shortcode Output
[affiliatewp_odfa_order_details]
FAQ

Frequently Asked Questions about AffiliateWP – Order Details For Affiliates