
WP Referral Code Security & Risk Analysis
wordpress.org/plugins/wp-referral-codeThis plugin brings referral marketing to your WordPress website. It's dead simple, fast, customizable, and it's all free!
Is WP Referral Code Safe to Use in 2026?
Generally Safe
Score 92/100WP Referral Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-referral-code' plugin v1.4.12 demonstrates a generally good security posture with a strong adherence to secure coding practices. The plugin utilizes prepared statements for all its SQL queries and exhibits a high rate of proper output escaping, minimizing risks of SQL injection and cross-site scripting vulnerabilities. Furthermore, the absence of known CVEs and common vulnerability types in its history suggests a mature and well-maintained codebase. The plugin also correctly implements nonce and capability checks for most of its entry points.
However, there are specific areas of concern that warrant attention. The static analysis reveals a notable attack surface with two AJAX handlers that lack authentication checks. This is a significant risk as it could allow unauthenticated users to trigger actions within the plugin. While the taint analysis found no critical or high severity issues, the presence of unprotected AJAX endpoints is a direct path for potential exploitation if an attacker can manipulate inputs to these handlers.
In conclusion, the plugin has a solid foundation regarding SQL and output security, and a clean vulnerability history. The primary weakness lies in the unprotected AJAX endpoints, which represent a direct and exploitable attack vector. Addressing these unprotected entry points should be the immediate priority to significantly improve the plugin's overall security.
Key Concerns
- AJAX handlers without authentication checks
WP Referral Code Security Vulnerabilities
WP Referral Code Release Timeline
WP Referral Code Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
WP Referral Code Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
WP Referral Code Maintenance & Trust
Maintenance Signals
Community Trust
WP Referral Code Alternatives
YBAI Affiliate
modoro-ybai-interaction
This plugin is made by Affiliate Marketing System, We provide this plugin to help our customer connect to YBAI system.
Affiliates
affiliates
The Affiliates system provides the most powerful growth-oriented tools to run a successful Affiliate Marketing Program.
Affiliates WooCommerce Light
affiliates-woocommerce-light
Grow your Business with your own Affiliate Network and let your partners earn commissions on referred sales. Integrates Affiliates and WooCommerce.
Affiliatly
affiliatly
Affiliatly Integration for WooCommerce.
Affiliates Contact Form 7 Integration
affiliates-contact-form-7
Affiliates plugin integration for Contact Form 7. Collect form data & track submissions. Lead tracking, sales, support ...
WP Referral Code Developer Profile
1 plugin · 700 total installs
How We Detect WP Referral Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-referral-code/admin/js/select2.full.min.js/wp-content/plugins/wp-referral-code/admin/css/select2.min.css/wp-content/plugins/wp-referral-code/admin/js/main.min.jswp-referral-code/admin/js/select2.full.min.js?ver=wp-referral-code/admin/css/select2.min.css?ver=wp-referral-code/admin/js/main.min.js?ver=HTML / DOM Fingerprints
wp-referral-code-user-search<!-- BEGIN WP Referral Code --><!-- END WP Referral Code --><!-- BEGIN WP Referral Code User Profile --><!-- END WP Referral Code User Profile -->data-noncedata-nonce-addWPReferralCode/wp-json/wp-referral-code/v1/get-users[wp_referral_code]