
OfferStack Security & Risk Analysis
wordpress.org/plugins/clicksco-offerstackWe cover Vouchers, Deals, Offers and Click To Call campaigns.
Is OfferStack Safe to Use in 2026?
Generally Safe
Score 100/100OfferStack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The clicksco-offerstack plugin exhibits a generally strong security posture based on the provided static analysis. The absence of detected dangerous functions, the exclusive use of prepared statements for SQL queries, and the lack of file operations are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities, which suggests a history of secure development or diligent patching.
However, several areas raise concerns. The most significant is the complete lack of capability checks and nonce checks across all entry points. While the attack surface is small (only one shortcode), this oversight could allow unauthorized users to trigger the plugin's functionality if that shortcode performs sensitive actions. Additionally, a 33% rate of properly escaped output is a weakness; while not critical, unescaped output can lead to cross-site scripting (XSS) vulnerabilities, especially if the shortcode handles user-provided data.
The plugin's strengths lie in its clean code regarding SQL and dangerous functions, and its clean vulnerability history. Its weaknesses are primarily around authentication and output sanitization. The lack of any reported CVEs is a positive sign, but it cannot negate the fundamental security practices that are missing in the current codebase, particularly regarding authorization for its single entry point.
Key Concerns
- Missing capability checks on entry points
- Missing nonce checks on entry points
- Low proper output escaping percentage
OfferStack Security Vulnerabilities
OfferStack Code Analysis
Output Escaping
OfferStack Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
OfferStack Maintenance & Trust
Maintenance Signals
Community Trust
OfferStack Alternatives
Coupon API
couponapi
Automatically import Coupons & Deals from popular Affiliate Networks into your WordPress Coupon Website.
Deals
deals
It’s a MIT-licensed (can be used in premium themes), high quality, native and responsive WordPress plugin to create and view slider-based deals
Bogo Deals For WooCommerce
wc-bogo-deals
Special offers, such as 2×1 or 3×2 promotions, are an excellent way to encourage shoppers to fill their carts and return for more.
RedCase
webera-redcase
This plugin is used to show deals based on Sheerid RedCase platform
PW WooCommerce Gift Cards
pw-woocommerce-gift-cards
Sell gift cards to your WooCommerce store, in just a few minutes!
OfferStack Developer Profile
1 plugin · 0 total installs
How We Detect OfferStack
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clicksco-offerstack/public/css/theme-default/index.css/wp-content/plugins/clicksco-offerstack/public/js/theme-default/app.js/wp-content/plugins/clicksco-offerstack/public/js/theme-default/app.jsclicksco-offerstack/public/css/theme-default/index.css?ver=1.0.1clicksco-offerstack/public/js/theme-default/app.js?ver=1.0.1