Loyalty Reward Points for HubSpot Security & Risk Analysis

wordpress.org/plugins/loyalty-reward-points-for-hubspot

Free WooCommerce Loyalty Reward Points for HubSpot connector to reward customers and grow sales.

0 active installs v1.0.1 PHP + WP 5.8.0+ Updated Dec 28, 2022
connectorloyaltypointsrewardswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Loyalty Reward Points for HubSpot Safe to Use in 2026?

Generally Safe

Score 85/100

Loyalty Reward Points for HubSpot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'loyalty-reward-points-for-hubspot' v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of known vulnerabilities in its history and no critical or high-severity taint flows are also encouraging indicators. However, a significant concern arises from the single AJAX handler that lacks authentication checks, creating an unprotected entry point into the application. While the static analysis didn't reveal specific dangerous functions or unsanitized paths, this unprotected AJAX handler represents a tangible risk that could be exploited by attackers.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Loyalty Reward Points for HubSpot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Loyalty Reward Points for HubSpot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
3
19 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

86% escaped22 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
mwb_app_connector_ajax (includes\class-loyalty-reward-points-for-hubspot-ajax-callbacks.php:26)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Loyalty Reward Points for HubSpot Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_mwb_app_connector_ajaxincludes\class-loyalty-reward-points-for-hubspot.php:235
WordPress Hooks 17
actionplugins_loadedincludes\class-loyalty-reward-points-for-hubspot.php:134
actionadmin_enqueue_scriptsincludes\class-loyalty-reward-points-for-hubspot.php:148
actionadmin_enqueue_scriptsincludes\class-loyalty-reward-points-for-hubspot.php:149
actionadmin_menuincludes\class-loyalty-reward-points-for-hubspot.php:150
filterwoocommerce_valid_webhook_resourcesincludes\class-loyalty-reward-points-for-hubspot.php:151
filterwoocommerce_valid_webhook_eventsincludes\class-loyalty-reward-points-for-hubspot.php:152
filterwoocommerce_webhook_payloadincludes\class-loyalty-reward-points-for-hubspot.php:155
filtermwb_app_tabsincludes\class-loyalty-reward-points-for-hubspot.php:159
actionmwb_app_connect_render_tabincludes\class-loyalty-reward-points-for-hubspot.php:161
actionmwb_app_connect_render_tabcontentincludes\class-loyalty-reward-points-for-hubspot.php:162
actionwp_enqueue_scriptsincludes\class-loyalty-reward-points-for-hubspot.php:177
actionwp_loadedincludes\class-loyalty-reward-points-for-hubspot.php:178
actionuser_registerincludes\class-loyalty-reward-points-for-hubspot.php:179
actionwp_footerincludes\class-loyalty-reward-points-for-hubspot.php:180
filterplugin_row_metaloyalty-reward-points-for-hubspot.php:170
actionadmin_initloyalty-reward-points-for-hubspot.php:193
actionadmin_noticesloyalty-reward-points-for-hubspot.php:212
Maintenance & Trust

Loyalty Reward Points for HubSpot Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 28, 2022
PHP min version
Downloads791

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Loyalty Reward Points for HubSpot Developer Profile

MakeWebBetter

4 plugins · 7K total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
2 days
View full developer profile
Detection Fingerprints

How We Detect Loyalty Reward Points for HubSpot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/loyalty-reward-points-for-hubspot/css/admin.css/wp-content/plugins/loyalty-reward-points-for-hubspot/js/admin.js/wp-content/plugins/loyalty-reward-points-for-hubspot/css/public.css/wp-content/plugins/loyalty-reward-points-for-hubspot/js/public.js
Script Paths
/wp-content/plugins/loyalty-reward-points-for-hubspot/js/admin.js/wp-content/plugins/loyalty-reward-points-for-hubspot/js/public.js
Version Parameters
loyalty-reward-points-for-hubspot/css/admin.css?ver=loyalty-reward-points-for-hubspot/js/admin.js?ver=loyalty-reward-points-for-hubspot/css/public.css?ver=loyalty-reward-points-for-hubspot/js/public.js?ver=

HTML / DOM Fingerprints

CSS Classes
mwb-notice
JS Globals
mwb_app_connector_name
FAQ

Frequently Asked Questions about Loyalty Reward Points for HubSpot