Refer A Friend for WooCommerce by WPGens Security & Risk Analysis

wordpress.org/plugins/refer-a-friend-for-woocommerce-by-wpgens

Referral System for WooCommerce. Each customer has referral link that rewards them with a coupon after someone makes a purchase through their link

1K active installs v1.3.5 PHP + WP 4.2+ Updated Jul 11, 2025
affiliateecommercerefer-a-friendreferralwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Refer A Friend for WooCommerce by WPGens Safe to Use in 2026?

Generally Safe

Score 100/100

Refer A Friend for WooCommerce by WPGens has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The plugin 'refer-a-friend-for-woocommerce-by-wpgens' v1.3.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and has no recorded vulnerabilities or CVEs. This suggests a history of stable and relatively secure development. However, the static analysis reveals significant concerns. The plugin has a single identifiable entry point via an AJAX handler that lacks any authentication checks. This creates a direct and unprotected attack vector. Furthermore, a substantial portion (73%) of its output is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if malicious data is processed and displayed to users. The absence of nonce checks on the AJAX handler exacerbates this risk.

Key Concerns

  • AJAX handler without auth check
  • High percentage of unescaped output
  • Missing nonce checks
Vulnerabilities
None known

Refer A Friend for WooCommerce by WPGens Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Refer A Friend for WooCommerce by WPGens Release Timeline

v1.3.5Current
v1.3.4
v1.3.3
v1.3.2
v1.3.1
v1.3.0
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.9
v1.1.8
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
v1.1.2
v1.1.1
Code Analysis
Analyzed Mar 16, 2026

Refer A Friend for WooCommerce by WPGens Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

27% escaped11 total outputs
Attack Surface
1 unprotected

Refer A Friend for WooCommerce by WPGens Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_dismiss_admin_notificationadmin\gens-notifications.php:101
WordPress Hooks 16
filterwoocommerce_settings_tabs_arrayadmin\class-gens-raf-woo-integration.php:55
actionadmin_noticesadmin\gens-notifications.php:99
actionnetwork_admin_noticesadmin\gens-notifications.php:100
actionadmin_headadmin\gens-notifications.php:102
actionplugins_loadedgens-raf.php:51
filterwoocommerce_get_settings_pagesincludes\class-gens-raf.php:147
filterplugin_action_links_refer-a-friend-for-woocommerce-by-wpgens/gens-raf.phpincludes\class-gens-raf.php:149
filterplugin_action_links_refer-a-friend-for-woocommerce-by-wpgens/gens-raf.phpincludes\class-gens-raf.php:150
filterplugin_action_links_refer-a-friend-for-woocommerce-by-wpgens/gens-raf.phpincludes\class-gens-raf.php:151
actionwp_enqueue_scriptsincludes\class-gens-raf.php:166
actionwoocommerce_order_status_completedincludes\class-gens-raf.php:168
actionwoocommerce_checkout_update_order_metaincludes\class-gens-raf.php:170
actionwoocommerce_before_my_accountincludes\class-gens-raf.php:172
actionwoocommerce_before_my_accountincludes\class-gens-raf.php:174
actionwoocommerce_thankyouincludes\class-gens-raf.php:176
actionwoocommerce_admin_order_data_after_order_detailsincludes\class-gens-raf.php:178
Maintenance & Trust

Refer A Friend for WooCommerce by WPGens Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 11, 2025
PHP min version
Downloads99K

Community Trust

Rating98/100
Number of ratings38
Active installs1K
Developer Profile

Refer A Friend for WooCommerce by WPGens Developer Profile

Goran87

4 plugins · 2K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Refer A Friend for WooCommerce by WPGens

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/refer-a-friend-for-woocommerce-by-wpgens/public/css/gens-raf-public.css/wp-content/plugins/refer-a-friend-for-woocommerce-by-wpgens/public/js/gens-raf-public.js
Script Paths
/wp-content/plugins/refer-a-friend-for-woocommerce-by-wpgens/public/js/gens-raf-public.js
Version Parameters
refer-a-friend-for-woocommerce-by-wpgens/public/css/gens-raf-public.css?ver=refer-a-friend-for-woocommerce-by-wpgens/public/js/gens-raf-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
gens-raf-account-linkgens-raf-coupon-wrapper
Data Attributes
data-gens-raf-nonce
JS Globals
gens_raf_params
FAQ

Frequently Asked Questions about Refer A Friend for WooCommerce by WPGens