
NFT Marketplace and Loyalty Rewards Security & Risk Analysis
wordpress.org/plugins/nft-marketplaceNFT Marketplace helps you mint and sell NFTs on your WordPress site and earn royalties out of them after reselling.
Is NFT Marketplace and Loyalty Rewards Safe to Use in 2026?
Generally Safe
Score 100/100NFT Marketplace and Loyalty Rewards has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nft-marketplace" v3.2.2 plugin exhibits a generally strong security posture with several good practices in place. Notably, 100% of its SQL queries utilize prepared statements, and all identified output operations are properly escaped, significantly mitigating common risks like SQL injection and cross-site scripting (XSS). The absence of any known CVEs or past vulnerabilities further suggests a well-maintained and secure codebase.
However, a significant concern arises from the attack surface analysis. The plugin exposes 19 AJAX handlers, and crucially, one of these lacks any authentication check. This presents a clear pathway for unauthenticated attackers to interact with the plugin's functionality, potentially leading to unintended actions or information disclosure depending on what that specific AJAX handler does. While taint analysis shows no critical or high severity unsanitized flows, the presence of two flows with unsanitized paths, even if deemed lower severity, warrants attention. The large number of external HTTP requests (19) also introduces a potential reliance on external services that could be compromised or unavailable, although this is not a direct security flaw in the plugin itself.
In conclusion, the plugin demonstrates commendable security engineering in its core data handling and output sanitization. The primary weakness lies in an exposed AJAX endpoint. Addressing this single unauthenticated entry point should be the immediate priority. The lack of historical vulnerabilities is a positive indicator, but it doesn't negate the identified risk in the current version's attack surface.
Key Concerns
- AJAX handler without auth check
- Flows with unsanitized paths (2)
NFT Marketplace and Loyalty Rewards Security Vulnerabilities
NFT Marketplace and Loyalty Rewards Code Analysis
Output Escaping
Data Flow Analysis
NFT Marketplace and Loyalty Rewards Attack Surface
AJAX Handlers 19
Shortcodes 3
WordPress Hooks 16
Maintenance & Trust
NFT Marketplace and Loyalty Rewards Maintenance & Trust
Maintenance Signals
Community Trust
NFT Marketplace and Loyalty Rewards Alternatives
Web3 – Crypto wallet Login & NFT token gating
web3-authentication
Users can sign up for your WordPress using their crypto wallets. Gate content based on NFTs owned. Web3 authentication plugin supports crypto wallets …
Web3 Access
web3-access
Accept cryptocurrency payments via MetaMask or web3 browser wallets. Restrict content to NFT owners or crypto wallets that make a payment.
thirdweb WP
thirdweb-wp
A community WordPress plugin for thirdweb. Turn your WordPress website into Web3 instantly and easily with thirdweb. 🚀💻🧩
Enefti NFT Marketplace Core lite
enefti-nft-marketplace-core-lite
Enefti NFT Marketplace Core lite is a starting point for NFT Marketplaces based on Wordpress. Creating NFTs was never so easy.
Opensea NFT Gallery
gallery-openseanft
In just few clicks you can display NFTs (from Opensea) on your Wordpress website.
NFT Marketplace and Loyalty Rewards Developer Profile
38 plugins · 83K total installs
How We Detect NFT Marketplace and Loyalty Rewards
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.