
HostPlugin – WooCommerce Points & Rewards Security & Risk Analysis
wordpress.org/plugins/hostplugin-woocommerce-points-and-rewardsReward your loyal customers for purchases and other actions using points which can be redeemed for discounts on future purchase.
Is HostPlugin – WooCommerce Points & Rewards Safe to Use in 2026?
Generally Safe
Score 85/100HostPlugin – WooCommerce Points & Rewards has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "hostplugin-woocommerce-points-and-rewards" v1.1.2 plugin presents a generally positive security posture. The complete absence of identified dangerous functions, raw SQL queries, and external HTTP requests is a strong indicator of secure coding practices. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of responsible development and maintenance. The attack surface appears minimal, with no exposed entry points like AJAX handlers, REST API routes, or shortcodes that are not protected by authentication or capability checks. The presence of capability checks on two identified code paths is also a good sign.
However, a significant concern arises from the low percentage of properly escaped output. With only 37% of 60 outputs being properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any unsanitized user-controlled input that is later displayed to other users could be exploited. The absence of taint analysis results could be due to the analysis tool's limitations or a genuine lack of complex data flows that trigger its analysis. While the current findings are positive, the output escaping issue requires immediate attention to mitigate potential security risks.
Key Concerns
- Low percentage of properly escaped output
HostPlugin – WooCommerce Points & Rewards Security Vulnerabilities
HostPlugin – WooCommerce Points & Rewards Code Analysis
Output Escaping
HostPlugin – WooCommerce Points & Rewards Attack Surface
WordPress Hooks 38
Maintenance & Trust
HostPlugin – WooCommerce Points & Rewards Maintenance & Trust
Maintenance Signals
Community Trust
HostPlugin – WooCommerce Points & Rewards Alternatives
Customers Loyalty Program – Points and Rewards
customers-loyalty-program-points-and-rewards
Complete solution for Customers Loyalty Program making.
LoyaltyX – Points and Rewards for WooCommerce – Build Customer Loyalty Program and Reward Purchases
loyaltyx-points-and-rewards-for-woocommerce
Add a WooCommerce points and rewards program to your store. Customers earn points on every purchase and redeem them for discounts on cart & checkout.
Oliver POS – Points and Rewards for WooCommerce
oliver-pos-points-and-rewards
Oliver POS - Points and Rewards for WooCommerce is a points management system built on top of WooCommerce Points and Rewards.
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
mycred
A WordPress gamification plugin is also a points management system. Award ranks, loyalty points and rewards or WooCommerce rewards to your users.
Points and Rewards for WooCommerce – Create Loyalty Programs, Reward Customer Purchases, User Badges, Gamification
points-and-rewards-for-woocommerce
Points and Rewards for WooCommerce offer a reward for points to your customers for their activities & increase customer loyalty.
HostPlugin – WooCommerce Points & Rewards Developer Profile
1 plugin · 50 total installs
How We Detect HostPlugin – WooCommerce Points & Rewards
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hostplugin-woocommerce-points-and-rewards/assets/css/style.csshostplugin-woocommerce-points-and-rewards/assets/css/style.css?ver=hostplugin-woocommerce-points-rewards.php?ver=HTML / DOM Fingerprints
hp-woo-rewards-points