Partnero – Affiliate & Referral Program Management for WooCommerce Security & Risk Analysis

wordpress.org/plugins/partnero

Partnero is a powerful tool designed to effortlessly manage affiliate and refer-a-friend programs directly within your WooCommerce store.

200 active installs v2.0.3 PHP 7.4+ WP 5.3+ Updated Mar 27, 2025
affiliateaffiliate-pluginaffiliate-programreferralwoocommerce-affiliates
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Partnero – Affiliate & Referral Program Management for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Partnero – Affiliate & Referral Program Management for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'partnero' v2.0.3 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of known CVEs and the plugin's code signals, such as proper SQL statement preparation and a high percentage of output escaping, are significant strengths. Furthermore, the lack of an apparent attack surface through AJAX, REST API, shortcodes, or cron events suggests a limited exposure to common web vulnerabilities.

However, there are specific areas that warrant attention. The taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this analysis, represent potential avenues for exploitation if user-controlled data is not properly validated and sanitized before being used. The presence of a single external HTTP request also introduces a dependency on external services, which could be a vector for certain attacks if not handled securely. The complete lack of nonce checks across all entry points is a notable concern, as nonces are a fundamental security mechanism in WordPress for preventing cross-site request forgery (CSRF) attacks.

In conclusion, 'partnero' v2.0.3 is a relatively secure plugin with good development practices evident in its SQL handling and output escaping. Its lack of past vulnerabilities further reinforces this. The primary areas for improvement are addressing the identified unsanitized paths in the taint analysis and implementing nonce checks on any user-facing functionalities to bolster its defenses against common web attacks. The absence of capability checks on any entry points is also a potential weakness if functionalities are intended to be protected.

Key Concerns

  • Taint flow with unsanitized path
  • Taint flow with unsanitized path
  • External HTTP request detected
  • No nonce checks on entry points
  • Capability checks only on 1 entry point
Vulnerabilities
None known

Partnero – Affiliate & Referral Program Management for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Partnero – Affiliate & Referral Program Management for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
5
111 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

96% escaped116 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
init_admin_page (admin\class-partnero-admin.php:95)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Partnero – Affiliate & Referral Program Management for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_menuincludes\class-partnero.php:116
actionadmin_enqueue_scriptsincludes\class-partnero.php:117
actionwp_headincludes\class-partnero.php:130
actionuser_registerincludes\class-partnero.php:131
actionwoocommerce_new_orderincludes\class-partnero.php:132
actionwoocommerce_sco_session_dataincludes\class-partnero.php:139
actionwoocommerce_order_status_processingincludes\class-partnero.php:152
actionwoocommerce_order_status_completedincludes\class-partnero.php:153
actionwoocommerce_order_status_cancelledincludes\class-partnero.php:155
actionwoocommerce_order_status_refundedincludes\class-partnero.php:156
actionwoocommerce_pre_payment_completeincludes\class-partnero.php:163
Maintenance & Trust

Partnero – Affiliate & Referral Program Management for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMar 27, 2025
PHP min version7.4
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Partnero – Affiliate & Referral Program Management for WooCommerce Developer Profile

Partnero

1 plugin · 200 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Partnero – Affiliate & Referral Program Management for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/partnero/public/css/partnero-public.css/wp-content/plugins/partnero/public/js/partnero-public.js/wp-content/plugins/partnero/admin/css/partnero-admin.css/wp-content/plugins/partnero/admin/js/partnero-admin.js
Script Paths
partnero/public/js/partnero-public.jspartnero/admin/js/partnero-admin.js
Version Parameters
partnero/public/css/partnero-public.css?ver=partnero/public/js/partnero-public.js?ver=partnero/admin/css/partnero-admin.css?ver=partnero/admin/js/partnero-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
partnero-admin-pagepartnero-api-key-form
HTML Comments
<!-- Partnero Admin Page --><!-- Partnero API Key Form -->
Data Attributes
data-partnero-program-typedata-partnero-api-key-type
JS Globals
window.partneroAdminwindow.partneroPublic
REST Endpoints
/wp-json/partnero/v1/settings/wp-json/partnero/v1/programs
Shortcode Output
[partnero_affiliate_dashboard][partnero_referral_link][partnero_signup_form]
FAQ

Frequently Asked Questions about Partnero – Affiliate & Referral Program Management for WooCommerce