Refer a Friend Program for WooCommerce Security & Risk Analysis

wordpress.org/plugins/refer-a-friend-program-for-woocommerce

Create a customer referral program Now! Have your customers driving their friends to your store ready to make a purchase

20 active installs v01 PHP + WP 3.0+ Updated May 5, 2019
discountecommercefriendsrefer-a-friendreferrals
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Refer a Friend Program for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Refer a Friend Program for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of the "refer-a-friend-program-for-woocommerce" plugin version 01 reveals a generally strong security posture in several key areas. The plugin has no recorded vulnerabilities (CVEs) in its history, indicating a history of secure development or effective patching. Furthermore, the code analysis shows no dangerous functions, no file operations, no external HTTP requests, and no taint flows, all of which are positive indicators. The absence of raw SQL queries and the use of prepared statements for all SQL queries is a significant strength, mitigating the risk of SQL injection vulnerabilities.

However, there are notable concerns. The most significant is the complete lack of output escaping for all identified outputs (8 total outputs, 0% properly escaped). This presents a serious risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the site through the plugin's output. Additionally, the plugin has zero nonce checks, which, combined with an attack surface that is explicitly stated as having zero entry points *without* auth checks, is confusing. If there are any hidden or undocumented entry points or if the capability checks are insufficient, the lack of nonces could still be exploitable.

While the plugin's vulnerability history is clean and it boasts secure handling of SQL and external requests, the critical flaw in output escaping cannot be overlooked. The clean CVE history is positive, but it doesn't negate the immediate, high-risk issues present in the current code. A balanced conclusion is that while the plugin demonstrates good practices in areas like SQL handling and avoiding dangerous functions, the severe deficiency in output escaping presents a substantial risk that must be addressed promptly.

Key Concerns

  • Unescaped output
  • No nonce checks
Vulnerabilities
None known

Refer a Friend Program for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Refer a Friend Program for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Refer a Friend Program for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitstoreya-refer-a-friend.php:12
actionadmin_noticesstoreya-refer-a-friend.php:13
filterplugin_action_linksstoreya-refer-a-friend.php:14
actionadmin_menustoreya-refer-a-friend.php:19
actionadmin_initstoreya-refer-a-friend.php:131
actionwoocommerce_thankyoustoreya-refer-a-friend.php:135
Maintenance & Trust

Refer a Friend Program for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedMay 5, 2019
PHP min version
Downloads11K

Community Trust

Rating78/100
Number of ratings11
Active installs20
Developer Profile

Refer a Friend Program for WooCommerce Developer Profile

storeya

5 plugins · 1K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Refer a Friend Program for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/refer-a-friend-program-for-woocommerce/storeya-refer-a-friend.png

HTML / DOM Fingerprints

HTML Comments
<!-- Begin StoreYa script --><!-- End StoreYa script -->
JS Globals
_storeya_storeya_order_details
FAQ

Frequently Asked Questions about Refer a Friend Program for WooCommerce