
ReferralYard Security & Risk Analysis
wordpress.org/plugins/referralyardReferralYard helps you build relationships with customers by rewarding them for driving referral sales.
Is ReferralYard Safe to Use in 2026?
Generally Safe
Score 85/100ReferralYard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ReferralYard plugin version 1.3 presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no recorded vulnerability history, suggesting a history of secure development. The absence of file operations and bundled libraries also reduces potential attack vectors. However, significant concerns arise from the analysis of its entry points and code signals. The plugin exposes one unprotected REST API route, which represents a direct and potentially exploitable attack surface. Furthermore, only 42% of output escaping is properly implemented, indicating a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with care before being rendered. While taint analysis shows no critical or high severity unsanitized flows, the combination of an unprotected endpoint and insufficient output escaping warrants careful consideration.
Key Concerns
- REST API route without permission callback
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
ReferralYard Security Vulnerabilities
ReferralYard Code Analysis
Output Escaping
Data Flow Analysis
ReferralYard Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 6
Maintenance & Trust
ReferralYard Maintenance & Trust
Maintenance Signals
Community Trust
ReferralYard Alternatives
MyRewards
woorewards
Free top-rated points and rewards program to retain your customers, grow your sales and get new customers.
Loyalty Points Rewards and Referral for WooCommerce – WPLoyalty
wployalty
Create WooCommerce points and rewards program with WPLoyalty to increase customer loyalty and boost sales. Reward customers to drive repeat purchases.
RewardsWP – Loyalty Points & Referral Program for WooCommerce
rewardswp
Turn customers into brand advocates with loyalty points and referral programs for WooCommerce and Easy Digital Downloads.
Lootly Loyalty & Rewards
lootly-for-woocommerce
Version 1.43 Lootly helps you build relationships with customers by rewarding them for interacting with your store or for driving referral sales.
Lynked Loyalty
lynked-loyalty
Lynked Loyalty's Woocommerce plugin lets businesses integrate our rewards system both online and in-store, offering a seamless and modern loyalty …
ReferralYard Developer Profile
1 plugin · 0 total installs
How We Detect ReferralYard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/referralyard/js/integrations/script.jshttps://referralyard.com/js/integrations/script.jsHTML / DOM Fingerprints
window.ReferralYard/wp-json/referralyard/generate-coupon