
AffiliateWP – Sign Up Bonus Security & Risk Analysis
wordpress.org/plugins/affiliatewp-sign-up-bonusEntice more affiliates to register by offering them a sign up bonus
Is AffiliateWP – Sign Up Bonus Safe to Use in 2026?
Generally Safe
Score 100/100AffiliateWP – Sign Up Bonus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of affiliatewp-sign-up-bonus v1.3.1 reveals a seemingly strong security posture with no identified dangerous functions, SQL injection vulnerabilities, file operations, or external HTTP requests. The absence of any identified taint flows, critical or high severity, further suggests that the code might be well-sanitized against common injection attacks. The plugin also boasts zero known CVEs, indicating a history of security diligence or a lack of prior exploitation.
However, the analysis also highlights significant areas of concern. The complete lack of nonces and capability checks across all identified code signals is a substantial weakness. While the attack surface is reported as zero, this likely means there are no publicly exposed AJAX handlers, REST API routes, or shortcodes in this version that the analysis could detect. If any functionality is present, its absence of proper authorization and integrity checks leaves it vulnerable to various attacks, especially if any hidden entry points exist or are introduced in future versions.
Despite the clean bill of health regarding known vulnerabilities and injection flaws, the lack of fundamental security controls like nonces and capability checks represents a significant risk. This absence means that even if no direct code execution vulnerabilities are present, an attacker could potentially manipulate the plugin's intended behavior through unauthorized actions or by exploiting a Cross-Site Request Forgery (CSRF) if any form of interaction is possible. The overall risk is moderate, leaning towards higher due to the missing essential security measures.
Key Concerns
- No nonce checks found
- No capability checks found
- 60% of output escaping is not properly escaped
AffiliateWP – Sign Up Bonus Security Vulnerabilities
AffiliateWP – Sign Up Bonus Code Analysis
Output Escaping
AffiliateWP – Sign Up Bonus Attack Surface
WordPress Hooks 7
Maintenance & Trust
AffiliateWP – Sign Up Bonus Maintenance & Trust
Maintenance Signals
Community Trust
AffiliateWP – Sign Up Bonus Alternatives
AffiliateWP – Affiliate Area Tabs
affiliatewp-affiliate-area-tabs
Add and reorder tabs in AffiliateWP's Affiliate Area
AffiliateWP – Affiliate Product Rates
affiliatewp-affiliate-product-rates
Allows you to set product referral rates on a per-affiliate level in AffiliateWP.
AffiliateWP – Order Details For Affiliates
affiliatewp-order-details-for-affiliates
Allow affiliates to see order details on referrals they generated
AffiliateWP – Affiliate Info
affiliatewp-affiliate-info
Display information based on the affiliate's referral URL.
AffiliateWP – Affiliate QR Codes
affiliatewp-affiliate-qr-codes
Allows affiliates to save, print, or share their affiliate URL as a QR code.
AffiliateWP – Sign Up Bonus Developer Profile
94 plugins · 23.5M total installs
How We Detect AffiliateWP – Sign Up Bonus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/affiliatewp-sign-up-bonus/assets/css/affiliatewp-sign-up-bonus.css/wp-content/plugins/affiliatewp-sign-up-bonus/assets/js/affiliatewp-sign-up-bonus.js/wp-content/plugins/affiliatewp-sign-up-bonus/assets/js/affiliatewp-sign-up-bonus.jsaffiliatewp-sign-up-bonus/assets/css/affiliatewp-sign-up-bonus.css?ver=affiliatewp-sign-up-bonus/assets/js/affiliatewp-sign-up-bonus.js?ver=HTML / DOM Fingerprints
affiliatewp-sign-up-bonus-requirementsdata-affwp-sb-referral-idaffwp_sign_up_bonus_params