
ACS Points Plugin Security & Risk Analysis
wordpress.org/plugins/acs-pointsACS Points Plugin
Is ACS Points Plugin Safe to Use in 2026?
Generally Safe
Score 100/100ACS Points Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'acs-points' plugin version 2.1.0 presents a generally strong security posture based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events, particularly those unprotected by authentication, significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices in its handling of SQL queries, with 100% of them utilizing prepared statements, which mitigates the risk of SQL injection vulnerabilities. The presence of a nonce check and file operations, while present, do not appear to be directly exploitable based on the provided data.
However, a notable concern is the output escaping, where only 60% of outputs are properly escaped. This leaves a significant portion of potentially user-controlled data at risk of cross-site scripting (XSS) vulnerabilities if not handled carefully by the theme or other plugins. While the taint analysis did not reveal any critical or high-severity unsanitized paths, the mixed output escaping quality warrants caution. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of secure development. Despite the limited attack surface and secure SQL handling, the unescaped output is the primary area of potential weakness, requiring developers to remain vigilant.
Key Concerns
- Insufficient output escaping (40%)
ACS Points Plugin Security Vulnerabilities
ACS Points Plugin Code Analysis
Output Escaping
Data Flow Analysis
ACS Points Plugin Attack Surface
WordPress Hooks 17
Maintenance & Trust
ACS Points Plugin Maintenance & Trust
Maintenance Signals
Community Trust
ACS Points Plugin Alternatives
AfterSalesPro Plugin
aftersalespro
One-Stop Solution for Automated label creation 🏷️, Smart shipment tracking 📍, branded tracking page 🖼️, automated survey 📝, order management 📦, cost c …
Smartpoints Lockers for ACS
smartpoints-lockers-acs
Smartpoints Lockers for ACS plugin extends WooCommerce shipping options, enabling customers to pick up orders at ACS Smartpoints Lockers.
Fr Multi Bank Transfer Payment Gateways for WooCommerce
fr-multi-bank-transfer-payment-gateways-for-woocommerce
Add multiple bank transfer payment gateways.
PAY by square pre WooCommerce
wc-bacs-paybysquare
Tento plugin pridáva QR kód PAY by square pre priamu platbu na bankový účet vo WooCommerce. Na použitie je potrebné mať účet na stránke https://app.
QR payment for WooCommerce
wc-qr-payment
Generate QR codes for bank transfers in WooCommerce checkout to simplify payments for your customers.
ACS Points Plugin Developer Profile
2 plugins · 700 total installs
How We Detect ACS Points Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acs-points/css/styles.css/wp-content/plugins/acs-points/js/acs-points-blocks.js/wp-content/plugins/acs-points/js/markerclusterer.js/wp-content/plugins/acs-points/js/script.jshttps://maps.googleapis.com/maps/api/js?key=plugins_url('js/markerclusterer.jsplugins_url('js/script.jsplugins_url('js/acs-points-blocks.jsplugins_url('css/styles.cssacs-points/css/styles.css?ver=acs-points/js/acs-points-blocks.js?ver=acs-points/js/markerclusterer.js?ver=acs-points/js/script.js?ver=HTML / DOM Fingerprints
<!-- ACS Points - WooCommerce Blocks Integration --><!-- 1. Register the ACS point ID as an official WooCommerce checkout field --><!-- 2. Validate: require a point only when ACS Points shipping is selected --><!-- 3. Save the full point data to order meta when order is placed -->+14 moredata-acs-points-mapdata-acs-points-triggerAcsPointsPlugin/wp-json/acs-points/v1/points