
Run Contests, Raffles, and Giveaways with ContestsWP Security & Risk Analysis
wordpress.org/plugins/contest-code-checkerAn easy to use WordPress plugin to do giveaways.
Is Run Contests, Raffles, and Giveaways with ContestsWP Safe to Use in 2026?
Mostly Safe
Score 74/100Run Contests, Raffles, and Giveaways with ContestsWP is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The "contest-code-checker" plugin version 2.1.1 exhibits a mixed security posture. While it demonstrates good practices such as a significant number of nonce checks and a majority of SQL queries using prepared statements, there are notable areas of concern. The presence of two AJAX handlers without authentication checks creates a significant attack surface that could be exploited by unauthenticated users. Furthermore, the taint analysis revealing three high-severity flows with unsanitized paths indicates a risk of sensitive data exposure or manipulation if these flows are triggered by malicious input. The plugin's vulnerability history is also a red flag, with three known CVEs, one of which remains unpatched. The common vulnerability types suggest a pattern of issues related to information exposure and cross-site scripting, indicating potential weaknesses in input validation and output sanitization that have persisted. The existence of an unpatched vulnerability is a critical issue that requires immediate attention. In conclusion, while the plugin has some strengths in its coding practices, the unprotected entry points, high-severity taint flows, and recurring vulnerability history, especially the unpatched CVE, pose significant risks that outweigh these positives.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Unpatched CVEs
- Bundled outdated library (Freemius v1.0)
- Vulnerability history indicates recurring issues
Run Contests, Raffles, and Giveaways with ContestsWP Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Run Contests, Raffles, and Giveaways with ContestsWP <= 2.0.7 - Unauthenticated Information Exposure
Run Contests, Raffles, and Giveaways with ContestsWP <= 2.0.6 - Reflected Cross-Site Scripting
Run Contests, Raffles, and Giveaways with ContestsWP <= 2.0.3 - Reflected Cross-Site Scripting
Run Contests, Raffles, and Giveaways with ContestsWP Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Run Contests, Raffles, and Giveaways with ContestsWP Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Run Contests, Raffles, and Giveaways with ContestsWP Maintenance & Trust
Maintenance Signals
Community Trust
Run Contests, Raffles, and Giveaways with ContestsWP Alternatives
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
rafflepress
The best WordPress giveaway plugin. Grow your email list, website traffic, and social media followers with viral contests, giveaways, and sweepstakes.
Woobox
woobox
Easily embed your Woobox promotions in WordPress using a simple shortcode.
Contests & Giveaways – WordPress Contest Plugin
giveaways-contests
Contest Cat Lets You Create Incredible Contests, Giveaways & Sweepstakes With Ease.
Contests by Rewards Fuel
contests-from-rewards-fuel
Contests by Rewards Fuel encourages your audience to take actions that build your business; it's a win-win for you and your customers!
Viral Loops WP Integration
viral-loops-wp-integration
The simplest way to install your Viral Loops campaign to your WordPress website.
Run Contests, Raffles, and Giveaways with ContestsWP Developer Profile
1 plugin · 100 total installs
How We Detect Run Contests, Raffles, and Giveaways with ContestsWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contest-code-checker/free/css/contest-code-checker-public.css/wp-content/plugins/contest-code-checker/free/css/contest-code-checker-admin.css/wp-content/plugins/contest-code-checker/free/js/contest-code-checker-public.js/wp-content/plugins/contest-code-checker/free/js/contest-code-checker-admin.js/wp-content/plugins/contest-code-checker/free/js/contest-code-checker-public.js/wp-content/plugins/contest-code-checker/free/js/contest-code-checker-admin.jscontest-code-checker/free/css/contest-code-checker-public.css?ver=contest-code-checker/free/css/contest-code-checker-admin.css?ver=contest-code-checker/free/js/contest-code-checker-public.js?ver=contest-code-checker/free/js/contest-code-checker-admin.js?ver=HTML / DOM Fingerprints
ccc-winners-displaydata-ccc-modal-idcontest_code_checker_params[contest-code-checker]