WooNinjas Salesforce WP to Lead with AffiliateWP Security & Risk Analysis

wordpress.org/plugins/wooninjas-salesforce-wp-to-lead-with-affiliate-wp

This add-on integrates Salesforce Wordpress To Lead with AffiliateWP

0 active installs v1.0 PHP + WP 4.0+ Updated Unknown
affiliate-wpform-submission-referralssalesforcesalesforce-referralswp-to-lead
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WooNinjas Salesforce WP to Lead with AffiliateWP Safe to Use in 2026?

Generally Safe

Score 100/100

WooNinjas Salesforce WP to Lead with AffiliateWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "wooninjas-salesforce-wp-to-lead-with-affiliate-wp" plugin version 1.0 presents a generally good security posture based on the provided static analysis. The plugin has a remarkably small attack surface with no apparent entry points like AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. However, a significant concern arises from the SQL queries: both queries are not using prepared statements, which is a common vector for SQL injection vulnerabilities. While the plugin has a clean vulnerability history with no known CVEs, this lack of history doesn't negate the inherent risk posed by the raw SQL queries. The moderate percentage of properly escaped outputs is also a minor concern, suggesting a potential for cross-site scripting (XSS) vulnerabilities in the unescaped outputs.

Key Concerns

  • Raw SQL queries without prepared statements
  • Moderate output escaping (31% properly escaped)
Vulnerabilities
None known

WooNinjas Salesforce WP to Lead with AffiliateWP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WooNinjas Salesforce WP to Lead with AffiliateWP Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
22
10 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

31% escaped32 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_sawp_settings (includes\settings\options.php:190)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WooNinjas Salesforce WP to Lead with AffiliateWP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionwp_footerincludes\integration\class-salesforce-awp.php:47
actionwp_footerincludes\integration\class-salesforce-awp.php:50
filteraffwp_referral_reference_columnincludes\integration\class-salesforce-awp.php:53
filteraffwp_get_affiliate_rate_typeincludes\integration\class-salesforce-awp.php:56
filteraffwp_get_affiliate_rateincludes\integration\class-salesforce-awp.php:59
actionsalesforce_w2l_after_submitincludes\integration\class-salesforce-awp.php:69
actionadmin_enqueue_scriptsincludes\settings\init.php:32
actionplugins_loadedincludes\settings\init.php:45
actionadmin_noticesincludes\settings\init.php:55
actionplugins_loadedincludes\settings\init.php:144
actionadmin_menuincludes\settings\options.php:27
actionadmin_noticesincludes\settings\options.php:28
actionadmin_noticessalesforce-affiliate-wp-add-on.php:28
Maintenance & Trust

WooNinjas Salesforce WP to Lead with AffiliateWP Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WooNinjas Salesforce WP to Lead with AffiliateWP Developer Profile

Wooninjas

6 plugins · 370 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WooNinjas Salesforce WP to Lead with AffiliateWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wooninjas-salesforce-wp-to-lead-with-affiliate-wp/assets/css/salesforce-awp.css/wp-content/plugins/wooninjas-salesforce-wp-to-lead-with-affiliate-wp/assets/js/salesforce-awp.js
Script Paths
/wp-content/plugins/wooninjas-salesforce-wp-to-lead-with-affiliate-wp/assets/js/salesforce-awp.js
Version Parameters
/wp-content/plugins/wooninjas-salesforce-wp-to-lead-with-affiliate-wp/assets/css/salesforce-awp.css?ver=/wp-content/plugins/wooninjas-salesforce-wp-to-lead-with-affiliate-wp/assets/js/salesforce-awp.js?ver=

HTML / DOM Fingerprints

CSS Classes
notice-info
FAQ

Frequently Asked Questions about WooNinjas Salesforce WP to Lead with AffiliateWP