
Contests by Rewards Fuel Security & Risk Analysis
wordpress.org/plugins/contests-from-rewards-fuelContests by Rewards Fuel encourages your audience to take actions that build your business; it's a win-win for you and your customers!
Is Contests by Rewards Fuel Safe to Use in 2026?
Generally Safe
Score 90/100Contests by Rewards Fuel has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'contests-from-rewards-fuel' plugin v2.0.66 exhibits a mixed security posture. On the positive side, the static analysis indicates a strong adherence to secure coding practices in several areas. There are no observed SQL injection vulnerabilities due to the consistent use of prepared statements, and the taint analysis found no critical or high severity issues with unsanitized paths. Additionally, the plugin implements capability checks and nonce checks, which are crucial for securing administrative functionalities. However, a significant concern arises from the output escaping. A very low percentage (24%) of outputs are properly escaped, leaving a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of XSS CVEs. The plugin also has a history of three medium severity CVEs, primarily related to CSRF and XSS, even though none are currently unpatched. This history, coupled with the poor output escaping, suggests a recurring vulnerability pattern that attackers might exploit.
Key Concerns
- Low output escaping percentage (24%)
- History of 3 medium severity CVEs
- History of XSS and CSRF vulnerabilities
Contests by Rewards Fuel Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Contests by Rewards Fuel <= 2.0.65 - Authenticated (Contributor+) Stored Cross-Site Scripting
Contests by Rewards Fuel <= 2.0.62 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Contests by Rewards Fuel <= 2.0.64 - Authenticated (Contributor+) Stored Cross-Site Scripting via update_rewards_fuel_api_key
Contests by Rewards Fuel Release Timeline
Contests by Rewards Fuel Code Analysis
Output Escaping
Data Flow Analysis
Contests by Rewards Fuel Attack Surface
Shortcodes 2
WordPress Hooks 10
Maintenance & Trust
Contests by Rewards Fuel Maintenance & Trust
Maintenance Signals
Community Trust
Contests by Rewards Fuel Alternatives
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
rafflepress
The best WordPress giveaway plugin. Grow your email list, website traffic, and social media followers with viral contests, giveaways, and sweepstakes.
Woobox
woobox
Easily embed your Woobox promotions in WordPress using a simple shortcode.
Run Contests, Raffles, and Giveaways with ContestsWP
contest-code-checker
An easy to use WordPress plugin to do giveaways.
Contests & Giveaways – WordPress Contest Plugin
giveaways-contests
Contest Cat Lets You Create Incredible Contests, Giveaways & Sweepstakes With Ease.
Sweepstakes app
sweepstakes-app
> This plugin was replaced by our better and more recent [Social Contests](http://wordpress.org/plugins/wishpond-social-campaigns/ "Run social …
Contests by Rewards Fuel Developer Profile
1 plugin · 60 total installs
How We Detect Contests by Rewards Fuel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contests-from-rewards-fuel/admin/css/contests-from-rewards-fuel-admin.css/wp-content/plugins/contests-from-rewards-fuel/admin/css/dependencies.css/wp-content/plugins/contests-from-rewards-fuel/admin/js/dependencies.js/wp-content/plugins/contests-from-rewards-fuel/admin/js/contests-from-rewards-fuel-admin.jshttps://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.jscontests-from-rewards-fuel/admin/css/contests-from-rewards-fuel-admin.css?ver=contests-from-rewards-fuel/admin/css/dependencies.css?ver=contests-from-rewards-fuel/admin/js/dependencies.js?ver=contests-from-rewards-fuel/admin/js/contests-from-rewards-fuel-admin.js?ver=https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js?ver=HTML / DOM Fingerprints
rewards-fuel-plugin-menurf_ajax_nonceCONTESTS_FROM_REWARDS_FUEL_VERSIONCONTESTS_FROM_REWARDS_FUEL_BASE_URLCONTESTS_FROM_REWARDS_FUEL_FILE_ROOT/wp-json/rewards-fuel/v1/get_contests