Grow by Tradedoubler – Advertiser Plugin for WooCommerce Security & Risk Analysis
wordpress.org/plugins/tradedoubler-affiliate-trackerGrow is an affiliate marketing solution for small businesses and start-ups wanting to increase online visibility, traffic, and product sales.
Is Grow by Tradedoubler – Advertiser Plugin for WooCommerce Safe to Use in 2026?
Generally Safe
Score 89/100Grow by Tradedoubler – Advertiser Plugin for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "tradedoubler-affiliate-tracker" plugin v2.0.23 presents a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices by ensuring all SQL queries use prepared statements and all output is properly escaped. The absence of critical or high-severity taint analysis findings is also a good sign. However, significant concerns arise from the attack surface and its vulnerability history.
The plugin exposes a single AJAX handler that lacks authentication checks, creating a direct entry point for potential attackers. This is compounded by a history that includes a past critical vulnerability classified as PHP Remote File Inclusion. While currently unpatched CVEs are zero, the nature of the past critical vulnerability suggests a potential for severe impact if similar weaknesses were to be re-introduced or if this existing unprotected AJAX endpoint could be leveraged in conjunction with other, as yet undiscovered, flaws.
In conclusion, while the code exhibits good practices in data handling and output, the unprotected AJAX endpoint and the historical presence of a critical RFI vulnerability represent significant security risks that require immediate attention. The plugin has strengths in its query and output sanitization but fundamental weaknesses in access control for its entry points.
Key Concerns
- Unprotected AJAX handler
- Past critical vulnerability (RFI)
- No nonce checks on AJAX handlers
Grow by Tradedoubler – Advertiser Plugin for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Grow by Tradedoubler <= 2.0.21 - Unauthenticated Local File Inclusion
Grow by Tradedoubler – Advertiser Plugin for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Grow by Tradedoubler – Advertiser Plugin for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
Grow by Tradedoubler – Advertiser Plugin for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Grow by Tradedoubler – Advertiser Plugin for WooCommerce Alternatives
Sovrn
viglink
Maximize your affiliate revenue with Sovrn Commerce - link optimization, price comparisons, and unified reporting.
LeadDyno WordPress Plugin
leaddyno
Integrates the LeadDyno affiliate tracking and web analytics service into your blog/wordpress/woocommerce site.
TradeTracker Connect
tradetracker-connect
TradeTracker Connect enables Merchants using WooCommerce to start selling products or services using TradeTracker's Affiliate Marketing Network.
WC Affiliate – WooCommerce Affiliate Plugin
wc-affiliate
The most complete WooCommerce affiliate plugin - unlimited affiliates, real-time tracking, flexible commissions. Free to start.
Shoparize Partner
shoparize
Shoparize Partner Plugin for Woocommerce
Grow by Tradedoubler – Advertiser Plugin for WooCommerce Developer Profile
1 plugin · 200 total installs
How We Detect Grow by Tradedoubler – Advertiser Plugin for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tradedoubler-affiliate-tracker/src/TradedoublerHotspot/TradedoublerHotspot.js/wp-content/plugins/tradedoubler-affiliate-tracker/src/TradedoublerRouting/TradedoublerRouting.js/wp-content/plugins/tradedoubler-affiliate-tracker/src/TradedoublerViews/TradedoublerViews.js/wp-content/plugins/tradedoubler-affiliate-tracker/src/TradedoublerActions/TradedoublerActions.js/wp-content/plugins/tradedoubler-affiliate-tracker/src/TradedoublerAPI/TradedoublerAPI.js/wp-content/plugins/tradedoubler-affiliate-tracker/src/TradedoublerDiscount/TradedoublerDiscount.js/wp-content/plugins/tradedoubler-affiliate-tracker/assets/css/tradedoubler-hotspot.css/wp-content/plugins/tradedoubler-affiliate-tracker/assets/css/tradedoubler.css+2 more/wp-content/plugins/tradedoubler-affiliate-tracker/assets/js/tradedoubler-hotspot.js/wp-content/plugins/tradedoubler-affiliate-tracker/assets/js/tradedoubler.jstradedoubler-affiliate-tracker/assets/css/tradedoubler-hotspot.css?ver=tradedoubler-affiliate-tracker/assets/css/tradedoubler.css?ver=tradedoubler-affiliate-tracker/assets/js/tradedoubler-hotspot.js?ver=tradedoubler-affiliate-tracker/assets/js/tradedoubler.js?ver=HTML / DOM Fingerprints
tradedoublerAppdata-td-action-urldata-td-api-keydata-td-affiliate-iddata-td-campaign-iddata-td-tracker-idtradedoublerApp