
Rewardix – Mystery Scratch Coupon for WooCommerce Security & Risk Analysis
wordpress.org/plugins/mystery-scratch-coupon-for-woocommerceProfessional gamified discount system with analytics, tiered rewards, email campaigns, and advanced targeting.
Is Rewardix – Mystery Scratch Coupon for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Rewardix – Mystery Scratch Coupon for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mystery-scratch-coupon-for-woocommerce" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and ensuring almost all output is properly escaped. The absence of dangerous functions, file operations, and external HTTP requests is also encouraging. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of relatively secure development.
However, significant concerns arise from the attack surface and taint analysis. Four out of six AJAX handlers lack authentication checks, creating a substantial entry point for unauthorized actions. The taint analysis reveals two flows with unsanitized paths, indicating potential for vulnerabilities that could be exploited through these paths, despite the absence of critical or high severity findings in the taint analysis itself. The presence of nonce checks on all AJAX handlers would significantly mitigate the risks associated with the unprotected AJAX endpoints.
In conclusion, while the plugin shows strengths in its handling of SQL and output, the unprotected AJAX endpoints and unsanitized paths represent notable weaknesses. Addressing the unprotected AJAX handlers and further investigating the identified unsanitized taint flows are crucial steps for improving its security.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
Rewardix – Mystery Scratch Coupon for WooCommerce Security Vulnerabilities
Rewardix – Mystery Scratch Coupon for WooCommerce Release Timeline
Rewardix – Mystery Scratch Coupon for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Rewardix – Mystery Scratch Coupon for WooCommerce Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
Rewardix – Mystery Scratch Coupon for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Rewardix – Mystery Scratch Coupon for WooCommerce Alternatives
Discount Rules for WooCommerce
woo-discount-rules
The discount plugin for WooCommerce helps you create bulk discount, quantity discount, storewide sale, dynamic pricing discount offers easily.
Smart Coupons For WooCommerce Coupons
wt-smart-coupons-for-woocommerce
Best WooCommerce coupons plugin to create advanced coupons and discount codes with auto-apply, BOGO, free shipping, giveaways, and discount rules.
Advanced Dynamic Pricing and Discount Rules for WooCommerce
advanced-dynamic-pricing-for-woocommerce
The discount plugin for WooCommerce supports any dynamic pricing discount: bulk discount, role discount, storewide, bogo, gifts, cart discount
Power Coupons for WooCommerce
power-coupons
WordPress coupon plugin for WooCommerce that auto-applies discounts with flexible rules and dynamic cart incentives—no codes required.
Extended Coupon Features for WooCommerce FREE
woocommerce-auto-added-coupons
Additional functionality for WooCommerce Coupons: Allow discounts to be automatically applied, applying coupons via url, etc...
Rewardix – Mystery Scratch Coupon for WooCommerce Developer Profile
17 plugins · 12K total installs
How We Detect Rewardix – Mystery Scratch Coupon for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mystery-scratch-coupon-for-woocommerce/assets/mscw-style.css/wp-content/plugins/mystery-scratch-coupon-for-woocommerce/assets/mscw-script.js/wp-content/plugins/mystery-scratch-coupon-for-woocommerce/assets/admin/mscw-admin.css/wp-content/plugins/mystery-scratch-coupon-for-woocommerce/assets/admin/chart.min.js/wp-content/plugins/mystery-scratch-coupon-for-woocommerce/assets/admin/mscw-admin.jswp-content/plugins/mystery-scratch-coupon-for-woocommerce/assets/mscw-script.jswp-content/plugins/mystery-scratch-coupon-for-woocommerce/assets/admin/mscw-admin.jsmystery-scratch-coupon-for-woocommerce/assets/mscw-style.css?ver=mystery-scratch-coupon-for-woocommerce/assets/mscw-script.js?ver=mystery-scratch-coupon-for-woocommerce/assets/admin/mscw-admin.css?ver=mystery-scratch-coupon-for-woocommerce/assets/admin/chart.min.js?ver=mystery-scratch-coupon-for-woocommerce/assets/admin/mscw-admin.js?ver=HTML / DOM Fingerprints
mscw-scratch-coupondata-mscw-promo-idmscw_ajaxmscw_admin_ajaxmscwCopyCoupon[mystery_scratch_coupon]