SteeplyRef – Affiliate & Referral Security & Risk Analysis

wordpress.org/plugins/steeplyref-affiliate-referral

Affiliate & Referral System for easy integration into your website.

0 active installs v1.1.1 PHP 5.6+ WP 4.5+ Updated Jun 28, 2019
affiliateallsteeplyreferralsteeplyref
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SteeplyRef – Affiliate & Referral Safe to Use in 2026?

Generally Safe

Score 85/100

SteeplyRef – Affiliate & Referral has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "steeplyref-affiliate-referral" v1.1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and has no known historical vulnerabilities. The absence of external HTTP requests and file operations further reduces its attack surface. However, a significant concern arises from the complete lack of output escaping, meaning any data rendered by the plugin is vulnerable to Cross-Site Scripting (XSS) attacks if it originates from user-controlled input. Additionally, the absence of nonce checks and capability checks on its entry points (shortcodes) means that any authenticated user could potentially trigger these functionalities, even if they are not intended to. While the attack surface is small and has no authentication bypasses, the lack of proper input validation and output sanitization creates a notable risk.

While there are no currently recorded vulnerabilities and the taint analysis shows no critical or high severity flows, this does not negate the risks identified in the static analysis. The lack of output escaping is a critical oversight that could lead to serious security issues. The absence of nonce and capability checks also presents potential for unintended actions by authenticated users. The plugin's history of no vulnerabilities might indicate a small user base or a lack of rigorous security auditing, rather than an inherently secure codebase. Therefore, while the plugin has some strengths in its handling of SQL and its historical vulnerability record, the critical omission of output escaping and the lack of proper authorization checks on shortcodes significantly elevate its risk profile.

Key Concerns

  • Outputs not properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

SteeplyRef – Affiliate & Referral Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SteeplyRef – Affiliate & Referral Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

SteeplyRef – Affiliate & Referral Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
29
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared10 total queries

Output Escaping

0% escaped29 total outputs
Attack Surface

SteeplyRef – Affiliate & Referral Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[st_ref_link] includes/class-steeply-ref.php:194
[st_ref_count] includes/class-steeply-ref.php:195
[st_ref_top_list] includes/class-steeply-ref.php:196
WordPress Hooks 13
actionplugins_loadedincludes/class-steeply-ref.php:149
actionadmin_enqueue_scriptsincludes/class-steeply-ref.php:164
actionadmin_enqueue_scriptsincludes/class-steeply-ref.php:165
actioninitincludes/class-steeply-ref.php:167
actionwp_logoutincludes/class-steeply-ref.php:168
actionadmin_menuincludes/class-steeply-ref.php:170
actionadmin_initincludes/class-steeply-ref.php:171
actionwp_dashboard_setupincludes/class-steeply-ref.php:173
actioninitincludes/class-steeply-ref.php:175
actionuser_registerincludes/class-steeply-ref.php:176
actionwp_enqueue_scriptsincludes/class-steeply-ref.php:191
actionwp_enqueue_scriptsincludes/class-steeply-ref.php:192
filtertemplate_includeincludes/class-steeply-ref.php:198
Maintenance & Trust

SteeplyRef – Affiliate & Referral Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 28, 2019
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SteeplyRef – Affiliate & Referral Developer Profile

Artur Khylskyi

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SteeplyRef – Affiliate & Referral

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/steeplyref-affiliate-referral/admin/css/steeply-ref-admin.css/wp-content/plugins/steeplyref-affiliate-referral/admin/js/steeply-ref-admin.js
Version Parameters
steeply-ref-admin.css?ver=steeply-ref-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
st-switchst-sliderst-round
HTML Comments
General Setting Page - Extended EngineGeneral Setting Page - Theme Select
Data Attributes
aria-describedby
FAQ

Frequently Asked Questions about SteeplyRef – Affiliate & Referral