Goaffpro Affiliate Marketing Security & Risk Analysis

wordpress.org/plugins/goaffpro

The complete affiliate marketing solution for your WordPress and WooCommerce website.

4K active installs v2.7.11 PHP + WP 4.6+ Updated Mar 11, 2026
affiliateaffiliate-marketinggoaffproinfluencer-marketingmulti-level-marketing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Goaffpro Affiliate Marketing Safe to Use in 2026?

Generally Safe

Score 100/100

Goaffpro Affiliate Marketing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The GoAffPro v2.7.11 plugin exhibits a mixed security posture. On the positive side, the code analysis reveals no instances of dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, there are no recorded vulnerabilities (CVEs) for this plugin, which suggests a potentially stable and well-maintained codebase. However, significant concerns arise from the identified attack surface. The plugin exposes two REST API routes that lack any permission callbacks, making them accessible to any user. This presents a critical risk as these endpoints could be exploited for various malicious purposes if they handle sensitive data or functionality. The absence of nonce checks on AJAX handlers is also a notable weakness, potentially allowing for Cross-Site Request Forgery (CSRF) attacks.

The lack of observed taint flows and the absence of known CVEs are positive indicators. Nevertheless, the unprotected REST API routes and the missing nonce checks on AJAX handlers represent a significant security gap. The plugin's attack surface, specifically the unprotected entry points, is a primary area of concern. While the absence of past vulnerabilities is encouraging, it does not negate the risks introduced by the current code analysis findings. Therefore, while the plugin demonstrates good practices in areas like SQL handling and output escaping, the exposed and unprotected entry points necessitate immediate attention to mitigate potential security threats.

Key Concerns

  • REST API routes without permission callbacks
  • AJAX handlers without nonce checks
Vulnerabilities
None known

Goaffpro Affiliate Marketing Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Goaffpro Affiliate Marketing Release Timeline

v2.7.10
Code Analysis
Analyzed Mar 16, 2026

Goaffpro Affiliate Marketing Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface
2 unprotected

Goaffpro Affiliate Marketing Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

GET/wp-json/goaffpro/configgoaffpro.php:121
GET/wp-json/goaffpro/public_tokengoaffpro.php:126
WordPress Hooks 9
actionwp_footergoaffpro.php:59
actionwoocommerce_thankyougoaffpro.php:69
actionwoocommerce_checkout_update_order_metagoaffpro.php:101
actionrest_api_initgoaffpro.php:118
actionwoocommerce_before_cart_tablegoaffpro.php:220
actioninitgoaffpro.php:240
actiontemplate_redirectgoaffpro.php:283
filterwoocommerce_rest_prepare_product_objectgoaffpro.php:286
filterwoocommerce_rest_prepare_product_variation_objectgoaffpro.php:287
Maintenance & Trust

Goaffpro Affiliate Marketing Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version
Downloads63K

Community Trust

Rating96/100
Number of ratings43
Active installs4K
Developer Profile

Goaffpro Affiliate Marketing Developer Profile

goaffpro

1 plugin · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Goaffpro Affiliate Marketing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/goaffpro/goaffpro.php
Script Paths
https://api.goaffpro.com/loader.jshttps://api.goaffpro.com/checkout_widget.js

HTML / DOM Fingerprints

JS Globals
window.goaffpro_order
REST Endpoints
/wp-json/goaffpro/config/wp-json/goaffpro/public_token
FAQ

Frequently Asked Questions about Goaffpro Affiliate Marketing