Referral Link Tracker Security & Risk Analysis

wordpress.org/plugins/referral-link-tracker

Our WordPress plugin brings a streamlined solution for effortless URL tracking and URL generation – a game-changer for tracking URL and generation!

0 active installs v1.1.4 PHP 7.2+ WP 4.7+ Updated Sep 11, 2025
affiliate-linklink-trackinglog-visitor-ipsharable-tracking-linkurl-tracking
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 28, 2025
Safety Verdict

Is Referral Link Tracker Safe to Use in 2026?

Mostly Safe

Score 78/100

Referral Link Tracker is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Sep 28, 2025Updated 8mo ago
Risk Assessment

The referral-link-tracker plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent output escaping practices, with 100% of outputs properly escaped, and it does not engage in file operations or external HTTP requests. The absence of critical or high-severity taint flows and dangerous functions is also a good sign. However, significant concerns arise from its attack surface. With 8 AJAX handlers, 3 of which lack any authentication checks, this presents a direct avenue for unauthenticated attackers to interact with the plugin's functionality. Furthermore, the plugin has a history of a known medium-severity vulnerability, specifically related to missing authorization, and one such vulnerability remains unpatched. This pattern of missing authorization, coupled with the current lack of capability checks and the presence of unprotected AJAX endpoints, suggests a recurring weakness that needs immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Unpatched CVE (medium severity)
  • Missing capability checks on entry points
  • SQL queries not always using prepared statements
Vulnerabilities
1 published

Referral Link Tracker Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62906medium · 4.3Missing Authorization

Referral Link Tracker <= 1.1.4 - Missing Authorization

Sep 28, 2025Unpatched
Version History

Referral Link Tracker Release Timeline

v1.1.4Current1 CVE
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.1.01 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 17, 2026

Referral Link Tracker Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
4 prepared
Unescaped Output
0
31 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

57% prepared7 total queries

Output Escaping

100% escaped31 total outputs
Attack Surface
3 unprotected

Referral Link Tracker Attack Surface

Entry Points8
Unprotected3

AJAX Handlers 8

authwp_ajax_get_tracking_logsreferral-link-tracker.php:311
authwp_ajax_delete_single_log_linkreferral-link-tracker.php:349
authwp_ajax_delete_all_log_linkreferral-link-tracker.php:377
authwp_ajax_register_generated_linkreferral-link-tracker.php:536
authwp_ajax_get_generated_linksreferral-link-tracker.php:685
authwp_ajax_delete_generated_linkreferral-link-tracker.php:699
authwp_ajax_bulk_delete_generated_linkreferral-link-tracker.php:735
authwp_ajax_bulk_delete_tracking_logsreferral-link-tracker.php:770
WordPress Hooks 3
actioninitreferral-link-tracker.php:26
actionadmin_enqueue_scriptsreferral-link-tracker.php:175
actionadmin_menureferral-link-tracker.php:246
Maintenance & Trust

Referral Link Tracker Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 11, 2025
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Referral Link Tracker Developer Profile

epiphanyit321

2 plugins · 1K total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Referral Link Tracker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/referral-link-tracker/bootstrap/css/bootstrap.min.css/wp-content/plugins/referral-link-tracker/css/custom.css/wp-content/plugins/referral-link-tracker/css/datatable.css
Script Paths
/wp-content/plugins/referral-link-tracker/js/activitytracker.js/wp-content/plugins/referral-link-tracker/js/datatable.js/wp-content/plugins/referral-link-tracker/bootstrap/js/bootstrap.bundle.min.js
Version Parameters
referral-link-tracker/bootstrap/css/bootstrap.min.css?ver=referral-link-tracker/css/custom.css?ver=referral-link-tracker/css/datatable.css?ver=referral-link-tracker/js/activitytracker.js?ver=referral-link-tracker/js/datatable.js?ver=referral-link-tracker/bootstrap/js/bootstrap.bundle.min.js?ver=

HTML / DOM Fingerprints

JS Globals
ajax_object
FAQ

Frequently Asked Questions about Referral Link Tracker