LocalLoyalty Security & Risk Analysis

wordpress.org/plugins/localloyalty

A simple, powerful WooCommerce loyalty points plugin. Customers earn points per purchase and redeem them at checkout for instant discounts.

0 active installs v1.0.1 PHP 7.2+ WP 5.6+ Updated Jan 11, 2026
couponslocalloyaltypointsrewards
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LocalLoyalty Safe to Use in 2026?

Generally Safe

Score 100/100

LocalLoyalty has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'localloyalty' v1.0.1 plugin demonstrates a strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, raw SQL queries, or unsanitized taint flows is a significant positive indicator. Furthermore, the plugin exhibits excellent coding practices with 100% properly escaped output and the use of prepared statements for all SQL queries. The presence of nonce and capability checks, even with a limited number of entry points, suggests a developer mindful of WordPress security best practices. The plugin's vulnerability history is also clean, with no recorded CVEs, which further reinforces its current security reliability.

Vulnerabilities
None known

LocalLoyalty Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LocalLoyalty Release Timeline

v1.0.2
v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

LocalLoyalty Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
87 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped87 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
localloyalty_render_admin_page (includes/free-core.php:103)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LocalLoyalty Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionwp_enqueue_scriptsincludes/free-core.php:59
actionadmin_menuincludes/free-core.php:89
actionwp_footerincludes/free-core.php:225
actionwoocommerce_before_cartincludes/free-core.php:252
actionwoocommerce_thankyouincludes/free-core.php:290
actionwoocommerce_order_status_completedincludes/free-core.php:319
actionwoocommerce_order_status_cancelledincludes/free-core.php:393
actionwoocommerce_order_status_failedincludes/free-core.php:394
actionwoocommerce_order_fully_refundedincludes/free-core.php:397
actionwoocommerce_review_order_before_paymentincludes/free-core.php:435
actionwoocommerce_cart_calculate_feesincludes/free-core.php:480
actionwoocommerce_checkout_create_orderincludes/free-core.php:535
actionwoocommerce_before_my_accountincludes/free-core.php:557
actionshow_user_profileincludes/free-core.php:642
actionedit_user_profileincludes/free-core.php:643
actionpersonal_options_updateincludes/free-core.php:663
actionedit_user_profile_updateincludes/free-core.php:664
Maintenance & Trust

LocalLoyalty Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 11, 2026
PHP min version7.2
Downloads344

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LocalLoyalty Developer Profile

Local Site Builder

4 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LocalLoyalty

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/localloyalty/assets/frontend.css/wp-content/plugins/localloyalty/assets/frontend.js
Version Parameters
localloyalty/assets/frontend.css?ver=localloyalty/assets/frontend.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-noncedata-localloyalty-points-label
JS Globals
localloyalty_ajax_object
FAQ

Frequently Asked Questions about LocalLoyalty