
ReferralCandy for WooCommerce – Advanced Referral & Affiliate Program Security & Risk Analysis
wordpress.org/plugins/referralcandy-for-woocommerceDrive sales and customer loyalty with ReferralCandy. Set up effective referral and affiliate programs easily to reward and grow your customer base.
Is ReferralCandy for WooCommerce – Advanced Referral & Affiliate Program Safe to Use in 2026?
Generally Safe
Score 100/100ReferralCandy for WooCommerce – Advanced Referral & Affiliate Program has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of referralcandy-for-woocommerce v2.5.5 indicates a generally strong security posture. The absence of detectable entry points like AJAX handlers, REST API routes, shortcodes, and cron events, particularly without authentication checks, significantly reduces the potential attack surface. The code also appears to handle SQL queries securely using prepared statements and avoids dangerous functions and file operations. However, there are areas for improvement. A notable concern is the presence of external HTTP requests, which could be a vector for certain types of attacks if not handled with extreme care. Furthermore, the output escaping is only moderately effective, with 37% of outputs not properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. The lack of nonce and capability checks on potential, albeit currently undiscovered, entry points is also a weakness. The plugin's clean vulnerability history is a positive sign, suggesting good development practices, but it doesn't negate the risks identified in the static analysis.
Key Concerns
- Moderate output escaping (37% unescaped)
- External HTTP requests present
- No nonce checks found
- No capability checks found
ReferralCandy for WooCommerce – Advanced Referral & Affiliate Program Security Vulnerabilities
ReferralCandy for WooCommerce – Advanced Referral & Affiliate Program Code Analysis
Output Escaping
ReferralCandy for WooCommerce – Advanced Referral & Affiliate Program Attack Surface
WordPress Hooks 13
Maintenance & Trust
ReferralCandy for WooCommerce – Advanced Referral & Affiliate Program Maintenance & Trust
Maintenance Signals
Community Trust
ReferralCandy for WooCommerce – Advanced Referral & Affiliate Program Alternatives
EchoRewards — Refer-a-Friend & Referral Program for WooCommerce
echo-rewards
Create a WooCommerce refer-a-friend program. Generate coupons, reward customers, and run a customer referral program for your store.
Customer Referral Program | Refer a Friend Software
invitereferrals-customer-referral-program
Design and launch customer referral campaigns within minutes in Wordpress.
Customer Referral Program For WooCommerce
invitereferrals-referral-program-for-woocommerce
Design and launch customer referral campaigns within minutes in WooCommerce.
OSI Affiliate
osi-affiliate
OSI Affiliate plugin allows customers to add affiliate tracking code to a WordPress website. It makes it easy for you to create a referral marketing p …
IQ Referral System for WooCommerce
iq-referral-program-for-woocommerce
A productive affiliate program system that will help you motivate you to attract more customers by your users Lang: [EN/RU]
ReferralCandy for WooCommerce – Advanced Referral & Affiliate Program Developer Profile
1 plugin · 400 total installs
How We Detect ReferralCandy for WooCommerce – Advanced Referral & Affiliate Program
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/referralcandy-for-woocommerce/includes/referralcandy.js/wp-content/plugins/referralcandy-for-woocommerce/includes/referralcandy-tracking.js/wp-content/plugins/referralcandy-for-woocommerce/includes/referralcandy-checkout.js/wp-content/plugins/referralcandy-for-woocommerce/includes/referralcandy.css/wp-content/plugins/referralcandy-for-woocommerce/includes/referralcandy.js/wp-content/plugins/referralcandy-for-woocommerce/includes/referralcandy-tracking.js/wp-content/plugins/referralcandy-for-woocommerce/includes/referralcandy-checkout.jsHTML / DOM Fingerprints
referralcandy-widget-containerreferralcandy-post-purchase-popupreferralcandy-signup-button<!-- ReferralCandy tracking code start --><!-- ReferralCandy tracking code end --><!-- ReferralCandy post-purchase popup start --><!-- ReferralCandy post-purchase popup end -->data-referralcandy-app-iddata-referralcandy-tracking-pagedata-referralcandy-api-keydata-referralcandy-campaign-idreferralCandySettingsReferralCandy