Customers Loyalty Program – Points and Rewards Security & Risk Analysis

wordpress.org/plugins/customers-loyalty-program-points-and-rewards

Complete solution for Customers Loyalty Program making.

10 active installs v1.27.1 PHP + WP 4.4+ Updated Apr 27, 2018
customers-loyalty-programloyaltyloyalty-programpointspoints-and-rewards
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Customers Loyalty Program – Points and Rewards Safe to Use in 2026?

Generally Safe

Score 85/100

Customers Loyalty Program – Points and Rewards has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin "customers-loyalty-program-points-and-rewards" v1.27.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with missing authorization checks indicates a well-constrained attack surface. The code signals also show positive signs, with dangerous functions and file operations not present, and all SQL queries utilizing prepared statements. This suggests a proactive approach to preventing common vulnerabilities like SQL injection.

However, a significant concern arises from the output escaping. With one total output and 0% properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data rendered on the frontend without proper sanitization could be exploited by attackers. The lack of nonce checks and capability checks on entry points (though the entry points themselves are limited) is also a potential weakness, as it doesn't enforce WordPress's built-in security mechanisms for certain operations.

The vulnerability history further reinforces the plugin's positive standing, with no known CVEs recorded. This suggests a history of responsible development and patching. In conclusion, while the plugin has a solid foundation and a clean vulnerability record, the unescaped output is a critical oversight that needs immediate attention to mitigate XSS risks.

Key Concerns

  • Unescaped output detected
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

Customers Loyalty Program – Points and Rewards Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Customers Loyalty Program – Points and Rewards Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

0% escaped1 total outputs
Attack Surface

Customers Loyalty Program – Points and Rewards Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedazh_loyalty.php:12
actionadmin_noticesazh_loyalty.php:18
filterazr_settingsazh_loyalty.php:27
filterazr_process_actionazh_loyalty.php:130
Maintenance & Trust

Customers Loyalty Program – Points and Rewards Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 27, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Customers Loyalty Program – Points and Rewards Developer Profile

azexo

9 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Customers Loyalty Program – Points and Rewards

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/customers-loyalty-program-points-and-rewards/css/style.css/wp-content/plugins/customers-loyalty-program-points-and-rewards/js/azm_clp.js
Script Paths
/wp-content/plugins/customers-loyalty-program-points-and-rewards/js/azm_clp.js
Version Parameters
customers-loyalty-program-points-and-rewards/css/style.css?ver=customers-loyalty-program-points-and-rewards/js/azm_clp.js?ver=

HTML / DOM Fingerprints

CSS Classes
azm-clp-points-display
HTML Comments
<!-- AZEXO CLP SHORTCODE START --><!-- AZEXO CLP SHORTCODE END -->
Data Attributes
data-azm-clp-user-iddata-azm-clp-points-typedata-azm-clp-action
JS Globals
azm_clp_vars
Shortcode Output
[azm_clp_points_display]
FAQ

Frequently Asked Questions about Customers Loyalty Program – Points and Rewards