Oliver POS – Points and Rewards for WooCommerce Security & Risk Analysis

wordpress.org/plugins/oliver-pos-points-and-rewards

Oliver POS - Points and Rewards for WooCommerce is a points management system built on top of WooCommerce Points and Rewards.

10 active installs v2.1.0 PHP 7.4+ WP 5.9+ Updated Nov 20, 2023
oliver-points-and-rewardspr-pluginpoints-and-rewardsposwoocommerce-points-and-rewards
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Oliver POS – Points and Rewards for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Oliver POS – Points and Rewards for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "oliver-pos-points-and-rewards" v2.1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all its SQL queries and avoiding file operations and bundled libraries. The absence of known CVEs and vulnerabilities in its history suggests a generally well-maintained codebase. However, significant concerns arise from the static analysis. The presence of two taint flows with unsanitized paths, classified as high severity, indicates potential injection vulnerabilities despite the low number of total flows analyzed. Furthermore, the complete lack of nonce checks and capability checks across all entry points (even though the attack surface is reported as zero) is a major red flag. This absence of authorization and input validation mechanisms leaves the plugin exposed to potential exploitation if any entry points were to become accessible or if the reported zero attack surface is an incomplete assessment.

Key Concerns

  • High severity taint flow (unsanitized path)
  • High severity taint flow (unsanitized path)
  • No nonce checks on any entry points
  • No capability checks on any entry points
  • External HTTP requests present
  • Unescaped output present
Vulnerabilities
None known

Oliver POS – Points and Rewards for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Oliver POS – Points and Rewards for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

80% escaped5 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
opr_extension_render_html (includes\core\templates\class-op-points-rewards-extension-page.php:248)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Oliver POS – Points and Rewards for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionrest_api_initincludes\api\class-op-points-rewards-api.php:50
actionoliver_points_and_rewards_activate_pluginoliver-pos-points-and-rewards.php:67
actionoliver_points_and_rewards_deactivate_pluginoliver-pos-points-and-rewards.php:68
actionwp_enqueue_scriptsoliver-pos-points-and-rewards.php:69
Maintenance & Trust

Oliver POS – Points and Rewards for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedNov 20, 2023
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Oliver POS – Points and Rewards for WooCommerce Developer Profile

Oliver POS

2 plugins · 1K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
106 days
View full developer profile
Detection Fingerprints

How We Detect Oliver POS – Points and Rewards for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/oliver-pos-points-and-rewards/assets/css/style.css
Version Parameters
oliver-pos-points-and-rewards/assets/css/style.css?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/oliver-pos-points-and-rewards
FAQ

Frequently Asked Questions about Oliver POS – Points and Rewards for WooCommerce