Afi.to – Integration Security & Risk Analysis

wordpress.org/plugins/afi-to-integrations

Reward your customers for making purchases in your online store!

10 active installs v1.0.1 PHP 7.1+ WP 5.7.2+ Updated Jun 17, 2021
affiliate-programawardsbonusesreferralreferral-link
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Afi.to – Integration Safe to Use in 2026?

Generally Safe

Score 85/100

Afi.to – Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of "afi-to-integrations" v1.0.1 reveals a mixed security posture. While the plugin boasts a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and demonstrates a good practice of performing capability checks on its single identified entry point, several areas raise concerns. The absence of nonce checks on potential entry points, the presence of SQL queries that are not parameterized, and a high percentage of unescaped output in the code analysis are significant weaknesses. Furthermore, the taint analysis indicates flows with unsanitized paths, which is a critical indicator of potential vulnerabilities, even though no "critical" or "high" severity issues were explicitly flagged in this analysis. The plugin's vulnerability history being completely clean is a positive sign, suggesting responsible development or a lack of targeting, but it does not negate the identified technical risks.

Key Concerns

  • SQL queries without prepared statements
  • Output escaping is not properly handled
  • No nonce checks detected
  • Taint flows with unsanitized paths
Vulnerabilities
None known

Afi.to – Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Afi.to – Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
12
0 prepared
Unescaped Output
3
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared12 total queries

Output Escaping

79% escaped14 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
afi_check_referal_link (includes\wc_store.php:67)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Afi.to – Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_enqueue_scriptsafi_sys.php:84
actionadmin_enqueue_scriptsafi_sys.php:85
actionadmin_menuafi_sys.php:86
actionwoocommerce_thankyouafi_sys.php:91
Maintenance & Trust

Afi.to – Integration Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJun 17, 2021
PHP min version7.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Afi.to – Integration Developer Profile

afitoltd

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Afi.to – Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/afi-to-integrations/admin/css/main.css/wp-content/plugins/afi-to-integrations/admin/js/points_mode.js
Script Paths
/wp-content/plugins/afi-to-integrations/admin/js/points_mode.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Afi.to – Integration