
800Website Loyalty Rewards for WooCommerce Security & Risk Analysis
wordpress.org/plugins/800website-loyalty-rewardsA complete loyalty rewards system with points earning, redemption, staff scanner, and customer app for WooCommerce.
Is 800Website Loyalty Rewards for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100800Website Loyalty Rewards for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "800website-loyalty-rewards" plugin v1.0.0 demonstrates a generally good security posture with several positive attributes. The code exclusively uses prepared statements for SQL queries, and all output is properly escaped, mitigating common web vulnerabilities. Furthermore, the absence of dangerous function calls, file operations, and external HTTP requests, alongside no recorded vulnerability history, suggests a diligent approach to secure coding.
However, there are significant concerns related to the attack surface. Four entry points into the plugin are identified as unprotected, specifically two AJAX handlers and two REST API routes lacking proper authorization checks. While the taint analysis only identified one flow with an unsanitized path (categorized as high severity), the combination of unprotected entry points and this single high-severity taint flow presents a tangible risk. The plugin's vulnerability history is clean, but this does not negate the immediate risks identified in the static analysis.
In conclusion, the plugin has a strong foundation in secure coding practices. Nevertheless, the presence of unprotected AJAX and REST API endpoints, coupled with a high-severity unsanitized path, requires immediate attention. Addressing these specific areas will significantly improve the plugin's security and reduce its attack surface.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- High severity unsanitized path flow
800Website Loyalty Rewards for WooCommerce Security Vulnerabilities
800Website Loyalty Rewards for WooCommerce Release Timeline
800Website Loyalty Rewards for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
800Website Loyalty Rewards for WooCommerce Attack Surface
AJAX Handlers 5
REST API Routes 15
Shortcodes 2
WordPress Hooks 20
Maintenance & Trust
800Website Loyalty Rewards for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
800Website Loyalty Rewards for WooCommerce Alternatives
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
mycred
A WordPress gamification plugin is also a points management system. Award ranks, loyalty points and rewards or WooCommerce rewards to your users.
HostPlugin – WooCommerce Points & Rewards
hostplugin-woocommerce-points-and-rewards
Reward your loyal customers for purchases and other actions using points which can be redeemed for discounts on future purchase.
Customers Loyalty Program – Points and Rewards
customers-loyalty-program-points-and-rewards
Complete solution for Customers Loyalty Program making.
Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program)
loyaltyx-points-and-rewards-for-woocommerce
A lightweight WooCommerce points and rewards plugin to run a loyalty program where customers earn points on purchases and redeem them for discounts.
Loyalty Points and Rewards for Square
loyalty-points-and-rewards-for-square
Add a Square loyalty program to WooCommerce store. Enable customers to earn and track reward points automatically with Square loyalty integration.
800Website Loyalty Rewards for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect 800Website Loyalty Rewards for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/800website-loyalty-rewards/assets/css/frontend.css/wp-content/plugins/800website-loyalty-rewards/assets/js/frontend.js/wp-content/plugins/800website-loyalty-rewards/assets/css/checkout.css/wp-content/plugins/800website-loyalty-rewards/assets/js/checkout.js/wp-content/plugins/800website-loyalty-rewards/assets/css/admin.css/wp-content/plugins/800website-loyalty-rewards/assets/js/admin.js/wp-content/plugins/800website-loyalty-rewards/assets/js/frontend.js/wp-content/plugins/800website-loyalty-rewards/assets/js/checkout.js/wp-content/plugins/800website-loyalty-rewards/assets/js/admin.js800website-loyalty-rewards/assets/css/frontend.css?ver=800website-loyalty-rewards/assets/js/frontend.js?ver=800website-loyalty-rewards/assets/css/checkout.css?ver=800website-loyalty-rewards/assets/js/checkout.js?ver=800website-loyalty-rewards/assets/css/admin.css?ver=800website-loyalty-rewards/assets/js/admin.js?ver=HTML / DOM Fingerprints
lrwc-loyalty-app-wrapperlrwc-loyalty-points-balancelrwc-checkout-points-redemption-formlrwc-rewards-badgelrwc-my-account-loyalty-title<!-- 800Website Loyalty Rewards for WooCommerce --><!-- End 800Website Loyalty Rewards for WooCommerce -->data-lrwc-customer-iddata-lrwc-points-balancedata-lrwc-redeemable-pointsdata-lrwc-max-redemption-amountlrwc_ajax_object/wp-json/lrwc/v1/redeem_points/wp-json/lrwc/v1/get_points_balance<div class='lrwc-loyalty-app-wrapper'><div class='lrwc-loyalty-staff-scanner-wrapper'>