
i-Refer Security & Risk Analysis
wordpress.org/plugins/i-referTransform online referrals with i-Refer. Connect your brand to a targeted audience and get rewarded for referrals with instant payments.
Is i-Refer Safe to Use in 2026?
Generally Safe
Score 92/100i-Refer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the i-refer plugin version 2.0.8 exhibits a generally strong security posture with no identified critical vulnerabilities. The absence of known CVEs and a clean vulnerability history suggest that the developers have a good track record of addressing security issues. The code also demonstrates good practices by using prepared statements for its single SQL query and properly escaping a high percentage of its outputs. The limited attack surface with no unprotected entry points is also a positive indicator.
However, there are some areas that warrant attention. The complete absence of nonce checks and capability checks, particularly given the presence of file operations and external HTTP requests, represents a significant potential risk. While the static analysis didn't identify any direct flows indicating these vulnerabilities, the lack of these fundamental WordPress security mechanisms leaves the plugin susceptible to various attacks if new entry points or vulnerabilities are introduced in the future or if the existing ones are indirectly exploitable. The presence of file operations and external HTTP requests without explicit authorization checks is a concern that could lead to unauthorized actions or information disclosure.
In conclusion, while the plugin is currently in a seemingly secure state with no known vulnerabilities and good coding practices in SQL and output handling, the complete lack of nonce and capability checks for all identified entry points is a notable weakness. This omission significantly increases the potential risk of privilege escalation or unauthorized operations, especially when considering the plugin's ability to perform file operations and external requests. Addressing these checks would greatly enhance the plugin's overall security.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
- File operations without explicit auth checks
- External HTTP requests without explicit auth checks
- Low percentage of output escaping (6%)
i-Refer Security Vulnerabilities
i-Refer Code Analysis
SQL Query Safety
Output Escaping
i-Refer Attack Surface
WordPress Hooks 10
Maintenance & Trust
i-Refer Maintenance & Trust
Maintenance Signals
Community Trust
i-Refer Alternatives
Sovrn
viglink
Maximize your affiliate revenue with Sovrn Commerce - link optimization, price comparisons, and unified reporting.
Sharkdropship & affiliate for AliExpress
wooshark-aliexpress-importer
Transform your WooCommerce store into a profitable AliExpress dropshipping or affiliate business with ease!
AFFI – Affiliate Marketing for WooCommerce
affi-affiliate-marketing-for-woo
Support affiliate management with flexible commissions, real-time performance record, auto payouts, email notifications for events, etc...
Refer a Friend Program for WooCommerce
refer-a-friend-program-for-woocommerce
Create a customer referral program Now! Have your customers driving their friends to your store ready to make a purchase
Roundups.ai – Instant Product Roundups With AI
roundups-ai
Let AI research products, write SEO-friendly guides, and help you earn affiliate income by helping others make informed buying decisions.
i-Refer Developer Profile
1 plugin · 10 total installs
How We Detect i-Refer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/i-refer/vendor/composer/../micropackage/requirements/src/Requirements.php/wp-content/plugins/i-refer/vendor/composer/../micropackage/requirements/src/Exception.php/wp-content/plugins/i-refer/vendor/composer/autoload_real.php/wp-content/plugins/i-refer/vendor/composer/autoload_static.php/wp-content/plugins/i-refer/vendor/composer/autoload_namespaces.php/wp-content/plugins/i-refer/vendor/composer/autoload_classmap.php+3 moreHTML / DOM Fingerprints
irefer_send_logirefer_get_vendor_infoirefer_deactivate_and_send_log/wp-json/wp/v2/calc/wp-json/wp/v2/demo/example