
LoymaxWebApp Security & Risk Analysis
wordpress.org/plugins/loymaxappПлагин для установки и настройки Личного кабинета Участника программ лояльности Loymax.
Is LoymaxWebApp Safe to Use in 2026?
Generally Safe
Score 100/100LoymaxWebApp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The loymaxapp plugin v3.5.8 presents a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) recorded, and the plugin demonstrates good practices in its handling of SQL queries, with 93% using prepared statements. The absence of external HTTP requests and bundled libraries also contributes to a reduced attack surface in those specific areas.
However, significant concerns arise from the static and taint analysis. The presence of unsanitized paths in 13 out of 14 analyzed flows is a critical red flag, indicating a high potential for path traversal or file manipulation vulnerabilities, even though the taint analysis did not flag them as critical or high severity. Furthermore, only 25% of outputs are properly escaped, exposing the plugin to potential Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks on any entry points is also a serious oversight, leaving actions susceptible to CSRF attacks.
While the vulnerability history is clean, this does not negate the risks identified in the code analysis. The plugin's strengths in SQL handling and lack of external requests are overshadowed by the critical findings in taint analysis related to unsanitized paths and the significant risk of XSS due to insufficient output escaping, coupled with the absence of fundamental security checks like nonces. A balanced conclusion would be that the plugin has some good foundational security elements but harbors critical weaknesses that require immediate attention.
Key Concerns
- Unsanitized paths in taint flows
- Low percentage of properly escaped output
- Zero nonce checks on entry points
- Only one capability check present
LoymaxWebApp Security Vulnerabilities
LoymaxWebApp Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LoymaxWebApp Attack Surface
WordPress Hooks 27
Maintenance & Trust
LoymaxWebApp Maintenance & Trust
Maintenance Signals
Community Trust
LoymaxWebApp Alternatives
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
mycred
A WordPress gamification plugin is also a points management system. Award ranks, loyalty points and rewards or WooCommerce rewards to your users.
theMarketer – Email marketing, Newsletters, Automation & Loyalty for Woocommerce
themarketer
Collect subscribers. Send newsletters. Create 1:1 personalised emails using dynamic blocks. Activate one of almost 30 predefined workflows.
Diller Loyalty
diller-loyalty
Diller Loyalty platform integration plugin for seamless membership engagement. Manages points, coupons and benefits and integrates with WC orders.
HostPlugin – WooCommerce Points & Rewards
hostplugin-woocommerce-points-and-rewards
Reward your loyal customers for purchases and other actions using points which can be redeemed for discounts on future purchase.
Vite Rewards for Woocommerce
vite-rewards
ViteRewards is a powerful and flexible loyalty points plugin designed specifically for WooCommerce.
LoymaxWebApp Developer Profile
1 plugin · 40 total installs
How We Detect LoymaxWebApp
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/loymaxapp/admin/loymax-plugin-styles.css/wp-content/plugins/loymaxapp/admin/admin.js/wp-content/plugins/loymaxapp/admin/admin.jsloymax-style?ver=loymax-admin-js?ver=HTML / DOM Fingerprints
loymax-setuplmx-action