
Customers Loyalty Program – Points and Rewards Security & Risk Analysis
wordpress.org/plugins/customers-loyalty-program-points-and-rewardsComplete solution for Customers Loyalty Program making.
Is Customers Loyalty Program – Points and Rewards Safe to Use in 2026?
Generally Safe
Score 85/100Customers Loyalty Program – Points and Rewards has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "customers-loyalty-program-points-and-rewards" v1.27.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with missing authorization checks indicates a well-constrained attack surface. The code signals also show positive signs, with dangerous functions and file operations not present, and all SQL queries utilizing prepared statements. This suggests a proactive approach to preventing common vulnerabilities like SQL injection.
However, a significant concern arises from the output escaping. With one total output and 0% properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data rendered on the frontend without proper sanitization could be exploited by attackers. The lack of nonce checks and capability checks on entry points (though the entry points themselves are limited) is also a potential weakness, as it doesn't enforce WordPress's built-in security mechanisms for certain operations.
The vulnerability history further reinforces the plugin's positive standing, with no known CVEs recorded. This suggests a history of responsible development and patching. In conclusion, while the plugin has a solid foundation and a clean vulnerability record, the unescaped output is a critical oversight that needs immediate attention to mitigate XSS risks.
Key Concerns
- Unescaped output detected
- Lack of nonce checks
- Lack of capability checks
Customers Loyalty Program – Points and Rewards Security Vulnerabilities
Customers Loyalty Program – Points and Rewards Code Analysis
SQL Query Safety
Output Escaping
Customers Loyalty Program – Points and Rewards Attack Surface
WordPress Hooks 4
Maintenance & Trust
Customers Loyalty Program – Points and Rewards Maintenance & Trust
Maintenance Signals
Community Trust
Customers Loyalty Program – Points and Rewards Alternatives
HostPlugin – WooCommerce Points & Rewards
hostplugin-woocommerce-points-and-rewards
Reward your loyal customers for purchases and other actions using points which can be redeemed for discounts on future purchase.
LoyaltyX – Points and Rewards for WooCommerce – Build Customer Loyalty Program and Reward Purchases
loyaltyx-points-and-rewards-for-woocommerce
Add a WooCommerce points and rewards program to your store. Customers earn points on every purchase and redeem them for discounts on cart & checkout.
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
mycred
A WordPress gamification plugin is also a points management system. Award ranks, loyalty points and rewards or WooCommerce rewards to your users.
Points and Rewards for WooCommerce – Create Loyalty Programs, Reward Customer Purchases, User Badges, Gamification
points-and-rewards-for-woocommerce
Points and Rewards for WooCommerce offer a reward for points to your customers for their activities & increase customer loyalty.
Easy Loyalty Points and Rewards for WooCommerce
easy-loyalty-points-and-rewards-for-woocommerce
A lightweight, easy to use customer loyalty system for WooCommerce.
Customers Loyalty Program – Points and Rewards Developer Profile
9 plugins · 130 total installs
How We Detect Customers Loyalty Program – Points and Rewards
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/customers-loyalty-program-points-and-rewards/css/style.css/wp-content/plugins/customers-loyalty-program-points-and-rewards/js/azm_clp.js/wp-content/plugins/customers-loyalty-program-points-and-rewards/js/azm_clp.jscustomers-loyalty-program-points-and-rewards/css/style.css?ver=customers-loyalty-program-points-and-rewards/js/azm_clp.js?ver=HTML / DOM Fingerprints
azm-clp-points-display<!-- AZEXO CLP SHORTCODE START --><!-- AZEXO CLP SHORTCODE END -->data-azm-clp-user-iddata-azm-clp-points-typedata-azm-clp-actionazm_clp_vars[azm_clp_points_display]