
Cashback Security & Risk Analysis
wordpress.org/plugins/cashbackMembers of 24/7 Discount receive cashback at over 2,500 shops. Aside from famous brands such as Zalando, Bol.com and Wehkamp many small retailers are …
Is Cashback Safe to Use in 2026?
Generally Safe
Score 85/100Cashback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cashback" plugin v1.1.0 exhibits a concerning security posture due to a significant number of unprotected entry points. All five identified AJAX handlers lack authentication checks, creating a substantial attack surface that could be exploited by unauthenticated users. The taint analysis reveals one high-severity flow with unsanitized paths, indicating a potential for code injection or other malicious operations if this flow is triggered with user-controlled input. While the plugin employs prepared statements for all SQL queries and has no recorded vulnerability history, these strengths are overshadowed by the critical flaw of unprotected AJAX endpoints.
The presence of dangerous functions like `set_time_limit` warrants careful review, as these can be misused. The low percentage of properly escaped output (24%) is another significant weakness, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is not correctly sanitized before being displayed. Despite the absence of known CVEs, the identified code signals and taint analysis present clear and immediate risks that require remediation.
Key Concerns
- All AJAX handlers lack authentication checks
- High severity unsanitized path in taint analysis
- Only 24% of outputs are properly escaped
- Presence of dangerous function set_time_limit
- No nonce checks on AJAX handlers
Cashback Security Vulnerabilities
Cashback Release Timeline
Cashback Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Cashback Attack Surface
AJAX Handlers 5
WordPress Hooks 13
Scheduled Events 2
Maintenance & Trust
Cashback Maintenance & Trust
Maintenance Signals
Community Trust
Cashback Alternatives
All-in-one Widget
all-in-one-widget
Add fundamental functionality to your WordPress sidebars with a set of proper widgets.
FS Revenue Maximizer
fs-revenue-mazimizer
Adds your Adsense or any other ads inside your content ( after the first or second paragraph ), enabling you to increase your revenue 10 times.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Cashback Developer Profile
1 plugin · 0 total installs
How We Detect Cashback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cashback/assets/css/c247.css/wp-content/plugins/cashback/assets/js/c247.js/wp-content/plugins/cashback/assets/js/c247.jscashback/assets/css/c247.css?ver=cashback/assets/js/c247.js?ver=HTML / DOM Fingerprints
c247-cssc247-disabledc247_keywordsc247_keywords_statusc247_total_postsc247_replace_existing_linksc247_disable_offers+1 morec247_keywords_statusc247_total_posts/wp-json/cashback/v1/offers/wp-json/cashback/v1/settings/wp-json/cashback/v1/profile