
Points loyalty system Security & Risk Analysis
wordpress.org/plugins/pointsPoints is a powerful solution, providing a loyalty system for your users, promoting participation in the website.
Is Points loyalty system Safe to Use in 2026?
Generally Safe
Score 85/100Points loyalty system has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'points' v1.1.4 plugin exhibits a very low-risk security profile based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, file operations, external HTTP requests, and a complete lack of known CVEs are significant strengths. Furthermore, all observed output is properly escaped, and the plugin appears to have no critical or high-severity taint flows. The minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, further contributes to its secure posture.
However, a notable concern arises from the presence of a single SQL query that does not utilize prepared statements. While this is the only identified SQL interaction and the overall attack surface is minimal, it still represents a potential avenue for SQL injection if the input to this query is not rigorously sanitized and validated elsewhere. The absence of any nonce or capability checks, while not directly exploitable given the lack of entry points, points to a potential oversight in future development should new entry points be added without these security measures. Overall, the plugin is currently very secure, but this single instance of raw SQL warrants attention.
Key Concerns
- SQL query without prepared statements
Points loyalty system Security Vulnerabilities
Points loyalty system Code Analysis
SQL Query Safety
Points loyalty system Attack Surface
WordPress Hooks 4
Maintenance & Trust
Points loyalty system Maintenance & Trust
Maintenance Signals
Community Trust
Points loyalty system Alternatives
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
mycred
A WordPress gamification plugin is also a points management system. Award ranks, loyalty points and rewards or WooCommerce rewards to your users.
Points and Rewards for WooCommerce – Create Loyalty Programs, Reward Customer Purchases, User Badges, Gamification
points-and-rewards-for-woocommerce
Points and Rewards for WooCommerce offer a reward for points to your customers for their activities & increase customer loyalty.
MyRewards
woorewards
Free top-rated points and rewards program to retain your customers, grow your sales and get new customers.
Loyalty Points Rewards and Referral for WooCommerce – WPLoyalty
wployalty
Create WooCommerce points and rewards program with WPLoyalty to increase customer loyalty and boost sales. Reward customers to drive repeat purchases.
Easy Loyalty Points and Rewards for WooCommerce
easy-loyalty-points-and-rewards-for-woocommerce
A lightweight, easy to use customer loyalty system for WooCommerce.
Points loyalty system Developer Profile
5 plugins · 100 total installs
How We Detect Points loyalty system
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/points/css/points-admin.css/wp-content/plugins/points/css/jquery.datetimepicker.css/wp-content/plugins/points/js/admin-scripts.js/wp-content/plugins/points/js/jquery.datetimepicker.full.min.js/wp-content/plugins/points/css/points.csspoints-admin-csspoints-csspoints-admin-scriptdatepicker