
HostPlugin – WooCommerce Points & Rewards Security & Risk Analysis
wordpress.org/plugins/hostplugin-woocommerce-points-and-rewardsReward your loyal customers for purchases and other actions using points which can be redeemed for discounts on future purchase.
Is HostPlugin – WooCommerce Points & Rewards Safe to Use in 2026?
Generally Safe
Score 85/100HostPlugin – WooCommerce Points & Rewards has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "hostplugin-woocommerce-points-and-rewards" v1.1.2 plugin presents a generally positive security posture. The complete absence of identified dangerous functions, raw SQL queries, and external HTTP requests is a strong indicator of secure coding practices. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of responsible development and maintenance. The attack surface appears minimal, with no exposed entry points like AJAX handlers, REST API routes, or shortcodes that are not protected by authentication or capability checks. The presence of capability checks on two identified code paths is also a good sign.
However, a significant concern arises from the low percentage of properly escaped output. With only 37% of 60 outputs being properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any unsanitized user-controlled input that is later displayed to other users could be exploited. The absence of taint analysis results could be due to the analysis tool's limitations or a genuine lack of complex data flows that trigger its analysis. While the current findings are positive, the output escaping issue requires immediate attention to mitigate potential security risks.
Key Concerns
- Low percentage of properly escaped output
HostPlugin – WooCommerce Points & Rewards Security Vulnerabilities
HostPlugin – WooCommerce Points & Rewards Release Timeline
HostPlugin – WooCommerce Points & Rewards Code Analysis
Output Escaping
HostPlugin – WooCommerce Points & Rewards Attack Surface
WordPress Hooks 38
Maintenance & Trust
HostPlugin – WooCommerce Points & Rewards Maintenance & Trust
Maintenance Signals
Community Trust
HostPlugin – WooCommerce Points & Rewards Alternatives
XT Points & Rewards for WooCommerce
xt-woo-points-rewards
Points and Rewards for WooCommerce that lets you reward your customers for purchases and other actions with points that can be redeemed for discounts.
Customers Loyalty Program – Points and Rewards
customers-loyalty-program-points-and-rewards
Complete solution for Customers Loyalty Program making.
Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program)
loyaltyx-points-and-rewards-for-woocommerce
A lightweight WooCommerce points and rewards plugin to run a loyalty program where customers earn points on purchases and redeem them for discounts.
Oliver POS – Points and Rewards for WooCommerce
oliver-pos-points-and-rewards
Oliver POS - Points and Rewards for WooCommerce is a points management system built on top of WooCommerce Points and Rewards.
Loyalty Points and Rewards for Square
loyalty-points-and-rewards-for-square
Add a Square loyalty program to WooCommerce store. Enable customers to earn and track reward points automatically with Square loyalty integration.
HostPlugin – WooCommerce Points & Rewards Developer Profile
1 plugin · 50 total installs
How We Detect HostPlugin – WooCommerce Points & Rewards
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hostplugin-woocommerce-points-and-rewards/assets/css/style.csshostplugin-woocommerce-points-and-rewards/assets/css/style.css?ver=hostplugin-woocommerce-points-rewards.php?ver=HTML / DOM Fingerprints
hp-woo-rewards-points