Affiliatly Security & Risk Analysis

wordpress.org/plugins/affiliatly

Affiliatly Integration for WooCommerce.

300 active installs v3.3.1 PHP 7.4+ WP 4.4+ Updated Apr 30, 2025
affiliate-marketingaffiliatlyinfluencer-marketingreferralwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Affiliatly Safe to Use in 2026?

Generally Safe

Score 100/100

Affiliatly has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The plugin "affiliatly" v3.3.1 demonstrates a strong security posture based on the provided static analysis. The absence of any identified attack surface, including AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks, is a significant strength. Furthermore, the code adheres to best practices by using prepared statements for all SQL queries and properly escaping all output, eliminating risks associated with injection and cross-site scripting vulnerabilities originating from these areas. The lack of any recorded vulnerabilities, including CVEs across all severities, further reinforces its secure implementation. The single external HTTP request and the presence of nonce and capability checks indicate a level of awareness for common security measures, although the limited scope of these checks (one of each) warrants further investigation if the plugin were to expand its functionality.

While the static analysis reveals a clean bill of health with no evident critical or high-severity issues in taint flows, and no dangerous functions used, the overall picture is one of a well-maintained and secure plugin. The consistent application of security best practices, particularly in output escaping and SQL handling, suggests a proactive approach to security by the developers. The absence of historical vulnerabilities and a minimal attack surface are positive indicators. However, it's important to note that the analysis is based on a specific version, and future updates or additional features could introduce new risks. The presence of an external HTTP request, though not flagged as problematic in this analysis, could be a potential vector if not handled with utmost care.

Vulnerabilities
None known

Affiliatly Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Affiliatly Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
30 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped30 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
affiliatly_plugin_options (affiliatly.php:466)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Affiliatly Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionwoocommerce_new_orderaffiliatly.php:559
actionwoocommerce_order_status_changedaffiliatly.php:562
actionwoocommerce_order_refundedaffiliatly.php:565
actionwoocommerce_subscription_renewal_payment_completeaffiliatly.php:568
actionwp_footeraffiliatly.php:571
actionadmin_menuaffiliatly.php:574
actionwp_footeraffiliatly.php:577
actionwoocommerce_initaffiliatly.php:580
actionwoocommerce_add_to_cartaffiliatly.php:583
Maintenance & Trust

Affiliatly Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 30, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

Affiliatly Developer Profile

overcodebg

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Affiliatly

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliatly/assets/css/affiliatly.css/wp-content/plugins/affiliatly/assets/js/affiliatly.js
Script Paths
/wp-content/plugins/affiliatly/assets/js/affiliatly.js
Version Parameters
affiliatly/assets/css/affiliatly.css?ver=affiliatly/assets/js/affiliatly.js?ver=

HTML / DOM Fingerprints

CSS Classes
affiliatly_tracking_code
HTML Comments
<!-- AFFILIATLY TRACKING CODE START --><!-- AFFILIATLY TRACKING CODE END -->
Data Attributes
data-affiliatly-tracking
JS Globals
affiliatly_tracking
FAQ

Frequently Asked Questions about Affiliatly