
Tracking Code for cj.com (on WooCommerce checkout) Security & Risk Analysis
wordpress.org/plugins/code-for-cj-affiliate-networkInstalls the tracking code for cj.com
Is Tracking Code for cj.com (on WooCommerce checkout) Safe to Use in 2026?
Generally Safe
Score 85/100Tracking Code for cj.com (on WooCommerce checkout) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "code-for-cj-affiliate-network" plugin v3.3 exhibits a mixed security posture. While the absence of known CVEs and the exclusive use of prepared statements for SQL queries are positive indicators, significant concerns arise from its attack surface and output escaping practices.
A substantial portion of the plugin's AJAX handlers (14 out of 18) lack authentication checks, creating a considerable entry point for potential attacks. Furthermore, the taint analysis, while limited in scope, revealed that all analyzed flows had unsanitized paths, although no critical or high severity issues were found. The low percentage of properly escaped output (32%) is a critical weakness, exposing the plugin to cross-site scripting (XSS) vulnerabilities.
Despite the lack of a vulnerability history, the identified code signals suggest that the plugin is not following many security best practices. The presence of a dangerous function ('assert') and file operations also warrant attention. The plugin's strengths lie in its SQL query handling, but these are overshadowed by the significant risks associated with its unprotected entry points and inadequate output sanitization.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping percentage
- Unsanitized paths in taint flows
- Dangerous function 'assert' used
- File operations present
- No capability checks on entry points
Tracking Code for cj.com (on WooCommerce checkout) Security Vulnerabilities
Tracking Code for cj.com (on WooCommerce checkout) Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Tracking Code for cj.com (on WooCommerce checkout) Attack Surface
AJAX Handlers 18
WordPress Hooks 26
Maintenance & Trust
Tracking Code for cj.com (on WooCommerce checkout) Maintenance & Trust
Maintenance Signals
Community Trust
Tracking Code for cj.com (on WooCommerce checkout) Alternatives
CJ Network Integration
cj-affiliate-network-integration
Seamlessly integrate with CJ Network, the world’s leading performance-based marketing platform.
Affiliates Ecwid Light
affiliates-ecwid-light
This plugin integrates Affiliates with Ecwid.
Affiliates Ready! Ecommerce Integration Light
affiliates-ready-light
This plugin integrates Affiliates with Ready! Ecommerce Shopping Cart.
Affiliates WP e-Commerce Integration
affiliates-wp-e-commerce
This integrates the Affiliates plugins with the WP e-Commerce shopping cart.
HTML Landing Page
html-landing-page
Allows you to upload customized HTML files to display as a landing page. Ideal for internet marketers promoting multiple products from the same site.
Tracking Code for cj.com (on WooCommerce checkout) Developer Profile
1 plugin · 10 total installs
How We Detect Tracking Code for cj.com (on WooCommerce checkout)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/code-for-cj-affiliate-network/assets/save_affiliate_referral_info.js/wp-content/plugins/code-for-cj-affiliate-network/assets/tag.js/wp-content/plugins/code-for-cj-affiliate-network/assets/save_affiliate_referral_info.js/wp-content/plugins/code-for-cj-affiliate-network/assets/tag.jscode-for-cj-affiliate-network/assets/save_affiliate_referral_info.js?ver=code-for-cj-affiliate-network/assets/tag.js?ver=HTML / DOM Fingerprints
cj_tracking_cookie_durationcj_from_php