
Poket Loyalty Rewards For WooCommerce Security & Risk Analysis
wordpress.org/plugins/poket-rewards-for-woocommerceWelcome to Poket: Elevate Your Online Store with Proven Loyalty Solutions
Is Poket Loyalty Rewards For WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Poket Loyalty Rewards For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "poket-rewards-for-woocommerce" v2.0 plugin presents a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) and the attack surface appears to be well-controlled with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. The absence of file operations and external HTTP requests (which can sometimes be vectors for attack if not handled securely) is also a strength. However, significant concerns arise from the code analysis. The plugin exhibits poor SQL query sanitization, with only 6% of its 31 queries using prepared statements, indicating a high risk of SQL injection vulnerabilities. Furthermore, a complete lack of output escaping (0% properly escaped) is a critical flaw, opening the door to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks on any potential, albeit currently unexposed, entry points is also a notable weakness that could become a problem if the attack surface expands in future versions.
Key Concerns
- Raw SQL queries without prepared statements
- Zero percent of output properly escaped
- No nonce checks implemented
- No capability checks implemented
Poket Loyalty Rewards For WooCommerce Security Vulnerabilities
Poket Loyalty Rewards For WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Poket Loyalty Rewards For WooCommerce Attack Surface
WordPress Hooks 7
Maintenance & Trust
Poket Loyalty Rewards For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Poket Loyalty Rewards For WooCommerce Alternatives
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
mycred
A WordPress gamification plugin is also a points management system. Award ranks, loyalty points and rewards or WooCommerce rewards to your users.
EchoRewards — Refer-a-Friend & Referral Program for WooCommerce
echo-rewards
Create a WooCommerce refer-a-friend program. Generate coupons, reward customers, and run a customer referral program for your store.
HostPlugin – WooCommerce Points & Rewards
hostplugin-woocommerce-points-and-rewards
Reward your loyal customers for purchases and other actions using points which can be redeemed for discounts on future purchase.
Customers Loyalty Program – Points and Rewards
customers-loyalty-program-points-and-rewards
Complete solution for Customers Loyalty Program making.
Leat
leat-crm
Create and manage customer loyalty programs with points, rewards, and automated marketing - works both online and in-store.
Poket Loyalty Rewards For WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect Poket Loyalty Rewards For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.