EBOD Tracking Security & Risk Analysis
wordpress.org/plugins/ebod-trackingThe EBOD (Engage-Benefit-On-Demand) WordPress plugin allows you to seamlessly integrate EBOD's engagement-driven rewards system into your WordPre …
Is EBOD Tracking Safe to Use in 2026?
Generally Safe
Score 85/100EBOD Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "ebod-tracking" v1.2.0 plugin exhibits a generally strong security posture. The absence of any identified vulnerabilities in its history and the lack of critical or high-severity code signals during static analysis are positive indicators. Specifically, the complete absence of dangerous functions, SQL queries without prepared statements, and improperly escaped output suggests careful development practices in these common vulnerability areas. Furthermore, the plugin does not appear to use bundled libraries, mitigating risks associated with outdated dependencies.
However, several areas present potential concerns that warrant attention. The plugin has zero nonce checks and zero capability checks, which is a significant weakness, especially considering it makes external HTTP requests. While the current attack surface appears minimal (0 entry points without authentication), this could change with future updates. The absence of taint analysis results is also noteworthy; while it might indicate no complex data flows, it could also mean the analysis was not performed comprehensively enough to uncover potential issues with user-supplied data interacting with external requests. The external HTTP requests themselves, without clear authentication or sanitization mechanisms detailed in the analysis, represent a potential vector for the plugin to be influenced by malicious external sources or to leak sensitive information.
In conclusion, "ebod-tracking" v1.2.0 demonstrates good adherence to secure coding principles regarding SQL and output handling. Its clean vulnerability history is a significant strength. However, the complete lack of nonce and capability checks, combined with external HTTP requests, introduces notable security risks that should be addressed to further harden the plugin.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
- External HTTP requests made
- No taint analysis results available
EBOD Tracking Security Vulnerabilities
EBOD Tracking Release Timeline
EBOD Tracking Code Analysis
Output Escaping
EBOD Tracking Attack Surface
WordPress Hooks 8
Maintenance & Trust
EBOD Tracking Maintenance & Trust
Maintenance Signals
Community Trust
EBOD Tracking Alternatives
Kazooky Loyalty
kazooky-loyalty-rewards
Kazooky Social Rewards and Loyalty instantly adds loyalty and rewards to your Wordpress website.
The Loyalty Box – WooCommerce Rewards Program
the-loyalty-box-woocommerce-rewards-program
One store or many
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
mycred
myCred is a flexible WordPress loyalty points and gamification plugin for points, badges, ranks, referrals, and WooCommerce rewards.
Points and Rewards for WooCommerce
points-and-rewards-for-woocommerce
Points and Rewards for WooCommerce offer a reward for points to your customers for their activities & increase customer loyalty.
Loyalty Points Rewards and Referral for WooCommerce – WPLoyalty
wployalty
Create WooCommerce points and rewards program with WPLoyalty to increase customer loyalty and boost sales. Reward customers to drive repeat purchases.
EBOD Tracking Developer Profile
2 plugins · 0 total installs
How We Detect EBOD Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ebod-tracking/admin/css/ebod-admin.css/wp-content/plugins/ebod-tracking/admin/js/ebod-admin.js/wp-content/plugins/ebod-tracking/admin/js/ebod-admin.jsebod-tracking/admin/css/ebod-admin.css?ver=ebod-tracking/admin/js/ebod-admin.js?ver=HTML / DOM Fingerprints
name="ebod_settings[ebod_apitoken_field]"