Cross Domain Tracker for AffiliateWP Security & Risk Analysis

wordpress.org/plugins/cross-domain-tracker-for-affiliatewp

Track referrals from different domains.

200 active installs v1.0.5 PHP 5.6+ WP 4.4+ Updated Jan 19, 2026
affiliatewpcross-domain-tracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Cross Domain Tracker for AffiliateWP Safe to Use in 2026?

Generally Safe

Score 100/100

Cross Domain Tracker for AffiliateWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "cross-domain-tracker-for-affiliatewp" plugin v1.0.5 demonstrates a mixed security posture. On the positive side, it boasts a small attack surface with only one AJAX handler, and importantly, this entry point appears to have authorization checks, significantly reducing the risk of direct unauthorized access. Furthermore, all SQL queries utilize prepared statements, which is excellent practice and prevents common SQL injection vulnerabilities. The absence of known CVEs and a clean vulnerability history suggest a generally well-maintained codebase.

However, concerns arise from the static analysis. A significant portion (59%) of output is not properly escaped, presenting a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is ever incorporated into these outputs. The taint analysis also highlights two high-severity flows with unsanitized paths, which could potentially lead to path traversal or other file system-related vulnerabilities if these paths are influenced by external input. While there are no direct signs of SQL injection or missing nonce checks on the identified entry point, these unsanitized paths and unescaped outputs are significant areas of concern that require immediate attention.

Key Concerns

  • High severity taint flows with unsanitized paths
  • Significant percentage of unescaped output
Vulnerabilities
None known

Cross Domain Tracker for AffiliateWP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Cross Domain Tracker for AffiliateWP Release Timeline

v1.0.5Current
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Cross Domain Tracker for AffiliateWP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
19
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

41% escaped32 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
check_store_connection (includes\class-affiliate-wp-track-external-visits.php:91)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Cross Domain Tracker for AffiliateWP Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_cdtawp_check_connectionincludes\class-affiliate-wp-track-external-visits.php:49
WordPress Hooks 5
actionadmin_menuincludes\class-affiliate-wp-track-external-visits.php:44
actionadmin_initincludes\class-affiliate-wp-track-external-visits.php:45
actionadmin_initincludes\class-affiliate-wp-track-external-visits.php:47
actionplugins_loadedincludes\class-affiliate-wp-track-external-visits.php:597
actionwp_enqueue_scriptsincludes\class-affiliate-wp-visits-tracking.php:46
Maintenance & Trust

Cross Domain Tracker for AffiliateWP Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 19, 2026
PHP min version5.6
Downloads7K

Community Trust

Rating60/100
Number of ratings2
Active installs200
Developer Profile

Cross Domain Tracker for AffiliateWP Developer Profile

Pratik Chaskar

16 plugins · 14K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
131 days
View full developer profile
Detection Fingerprints

How We Detect Cross Domain Tracker for AffiliateWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cross-domain-tracker-for-affiliatewp/assets/js/admin-settings.js
Script Paths
/wp-content/plugins/cross-domain-tracker-for-affiliatewp/assets/js/admin-settings.js
Version Parameters
cross-domain-tracker-for-affiliatewp/assets/js/admin-settings.js?ver=

HTML / DOM Fingerprints

JS Globals
cdtawp_vars
REST Endpoints
/wp-json/affwp/v1/affiliates/
FAQ

Frequently Asked Questions about Cross Domain Tracker for AffiliateWP