Points loyalty system Security & Risk Analysis

wordpress.org/plugins/points

Points is a powerful solution, providing a loyalty system for your users, promoting participation in the website.

10 active installs v1.1.4 PHP + WP 4.6+ Updated Jun 20, 2020
leaderboardpointpointsrewardsscore
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Points loyalty system Safe to Use in 2026?

Generally Safe

Score 85/100

Points loyalty system has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'points' v1.1.4 plugin exhibits a very low-risk security profile based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, file operations, external HTTP requests, and a complete lack of known CVEs are significant strengths. Furthermore, all observed output is properly escaped, and the plugin appears to have no critical or high-severity taint flows. The minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, further contributes to its secure posture.

However, a notable concern arises from the presence of a single SQL query that does not utilize prepared statements. While this is the only identified SQL interaction and the overall attack surface is minimal, it still represents a potential avenue for SQL injection if the input to this query is not rigorously sanitized and validated elsewhere. The absence of any nonce or capability checks, while not directly exploitable given the lack of entry points, points to a potential oversight in future development should new entry points be added without these security measures. Overall, the plugin is currently very secure, but this single instance of raw SQL warrants attention.

Key Concerns

  • SQL query without prepared statements
Vulnerabilities
None known

Points loyalty system Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Points loyalty system Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries
Attack Surface

Points loyalty system Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitpoints.php:77
actionwidgets_initpoints.php:78
actionwp_enqueue_scriptspoints.php:84
actionadmin_enqueue_scriptspoints.php:85
Maintenance & Trust

Points loyalty system Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 20, 2020
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Points loyalty system Developer Profile

ablancodev

5 plugins · 100 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Points loyalty system

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/points/css/points-admin.css/wp-content/plugins/points/css/jquery.datetimepicker.css/wp-content/plugins/points/js/admin-scripts.js/wp-content/plugins/points/js/jquery.datetimepicker.full.min.js/wp-content/plugins/points/css/points.css
Version Parameters
points-admin-csspoints-csspoints-admin-scriptdatepicker

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Points loyalty system