
Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program) Security & Risk Analysis
wordpress.org/plugins/loyaltyx-points-and-rewards-for-woocommerceA lightweight WooCommerce points and rewards plugin to run a loyalty program where customers earn points on purchases and redeem them for discounts.
Is Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program) Safe to Use in 2026?
Generally Safe
Score 100/100Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "loyaltyx-points-and-rewards-for-woocommerce" plugin version 1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for nearly all SQL queries and properly escaping a high percentage of output. The absence of known CVEs and a clean vulnerability history are strong indicators of responsible development and maintenance. However, a significant concern arises from the substantial attack surface presented by 16 AJAX handlers, of which 7 lack authentication checks. This leaves a considerable portion of the plugin's functionality potentially accessible to unauthenticated users, creating a notable risk.
Key Concerns
- 7 AJAX handlers without auth checks
- 9 unsanitized taint flows (high severity)
Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program) Security Vulnerabilities
Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program) Release Timeline
Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program) Attack Surface
AJAX Handlers 16
WordPress Hooks 44
Maintenance & Trust
Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program) Maintenance & Trust
Maintenance Signals
Community Trust
Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program) Alternatives
Simple Points and Rewards for WooCommerce – Create a Loyalty Program
simple-points-and-rewards
WooCommerce Points and Rewards plugin. Create a simple but powerful loyalty program. Reward purchases, referrals, and much more.
Loyalty Points and Rewards for Square
loyalty-points-and-rewards-for-square
Add a Square loyalty program to WooCommerce store. Enable customers to earn and track reward points automatically with Square loyalty integration.
Points and Rewards for WooCommerce
points-and-rewards-for-woocommerce
Points and Rewards for WooCommerce offer a reward for points to your customers for their activities & increase customer loyalty.
HostPlugin – WooCommerce Points & Rewards
hostplugin-woocommerce-points-and-rewards
Reward your loyal customers for purchases and other actions using points which can be redeemed for discounts on future purchase.
WupSales – Reward Points for WooCommerce
wupsales-reward-points-for-woocommerce
Reward points and loyalty program with WupSales points management system for WooCommerce. Reward your Customers for Purchase, Reviews, Sign up, etc
Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program) Developer Profile
2 plugins · 310 total installs
How We Detect Points and Rewards for WooCommerce – LoyaltyX (Referral, Gamification & Loyalty Program)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/loyaltyx-points-and-rewards-for-woocommerce/assets/css/backend/ddwcpr-admin-style.css/wp-content/plugins/loyaltyx-points-and-rewards-for-woocommerce/assets/js/backend/ddwcpr-admin-script.js/wp-content/plugins/loyaltyx-points-and-rewards-for-woocommerce/assets/css/frontend/ddwcpr-frontend-style.css/wp-content/plugins/loyaltyx-points-and-rewards-for-woocommerce/assets/js/frontend/ddwcpr-frontend-script.js/wp-content/plugins/loyaltyx-points-and-rewards-for-woocommerce/devdiggers-framework/assets/js/ddfw-app.js/wp-content/plugins/loyaltyx-points-and-rewards-for-woocommerce/devdiggers-framework/assets/js/ddfw-framework.jsloyaltyx-points-and-rewards-for-woocommerce/assets/css/backend/ddwcpr-admin-style.css?ver=loyaltyx-points-and-rewards-for-woocommerce/assets/js/backend/ddwcpr-admin-script.js?ver=loyaltyx-points-and-rewards-for-woocommerce/assets/css/frontend/ddwcpr-frontend-style.css?ver=loyaltyx-points-and-rewards-for-woocommerce/assets/js/frontend/ddwcpr-frontend-script.js?ver=loyaltyx-points-and-rewards-for-woocommerce/devdiggers-framework/assets/js/ddfw-app.js?ver=loyaltyx-points-and-rewards-for-woocommerce/devdiggers-framework/assets/js/ddfw-framework.js?ver=HTML / DOM Fingerprints
ddwcpr-admin-styleddwcpr-admin-scriptddwcpr-frontend-styleddwcpr-frontend-script<!-- ddwcpr: LoyaltyX - Points and Rewards for WooCommerce. -->data-plugin-name="LoyaltyX - Points and Rewards for WooCommerce"data-plugin-prefix="ddwcpr"data-review-url="https://wordpress.org/support/plugin/loyaltyx-points-and-rewards-for-woocommerce/reviews/#new-post"DDWCPR_ADMIN_SCRIPT_OBJECTDDWCPR_FRONTEND_SCRIPT_OBJECT