
QR-Code Bonus Card Security & Risk Analysis
wordpress.org/plugins/qr-code-bonus-cardgenerate QR-Code for Bonus Card. A simple and user-friendly digital bonus card system.
Is QR-Code Bonus Card Safe to Use in 2026?
Generally Safe
Score 85/100QR-Code Bonus Card has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'qr-code-bonus-card' plugin, version 1.2.2, exhibits a generally strong security posture, with excellent practices in SQL query handling and output escaping. The static analysis shows a commendable 100% of SQL queries utilize prepared statements, and 98% of outputs are properly escaped, significantly reducing risks of SQL injection and cross-site scripting (XSS) vulnerabilities respectively. The absence of file operations and external HTTP requests further limits potential attack vectors.
However, the taint analysis reveals a notable concern: 4 out of 7 analyzed flows have unsanitized paths, with 4 classified as high severity. This suggests potential pathways for malicious data to enter the application without proper validation or sanitization, which could lead to vulnerabilities if exploited. Additionally, while there are 6 AJAX entry points, the static analysis indicates 0 nonce checks. This is a significant oversight, as it leaves these AJAX handlers potentially vulnerable to Cross-Site Request Forgery (CSRF) attacks. The plugin's vulnerability history is clean, with no known CVEs, which is a positive sign and may indicate thorough development or recent security attention.
In conclusion, while the plugin demonstrates robust protection against common threats like SQL injection and XSS through diligent coding practices, the presence of high-severity unsanitized taint flows and the complete lack of nonce checks on AJAX handlers represent critical areas of concern that require immediate attention to bolster its overall security.
Key Concerns
- High severity unsanitized taint flows
- Missing nonce checks on AJAX handlers
QR-Code Bonus Card Security Vulnerabilities
QR-Code Bonus Card Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
QR-Code Bonus Card Attack Surface
AJAX Handlers 6
WordPress Hooks 9
Maintenance & Trust
QR-Code Bonus Card Maintenance & Trust
Maintenance Signals
Community Trust
QR-Code Bonus Card Alternatives
Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce
flexible-coupons
Flexible PDF Coupons - Gift Cards & Vouchers for WooCommerce - plugin to design and sell PDF gift cards, vouchers, or coupons in your store.
Smart Contact Card
smart-contact-card
Shareable contact cards with QR codes and vCard via shortcode, Gutenberg block, and Elementor widget.
gurado WebConnect – Gift Card & Voucher Shop for WordPress
gurado-webconnect
Sell gift cards, vouchers, and event tickets directly on your own website – no commissions, instant delivery, direct payout, and full design control.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
QR-Code Bonus Card Developer Profile
1 plugin · 0 total installs
How We Detect QR-Code Bonus Card
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qr-code-bonus-card/assets/admin.css/wp-content/plugins/qr-code-bonus-card/assets/admin.js/wp-content/plugins/qr-code-bonus-card/assets/admin.jsqr-code-bonus-card/assets/admin.css?ver=qr-code-bonus-card/assets/admin.js?ver=HTML / DOM Fingerprints
qr-search-formprint-blockpagination-tableonclickdata-iddata-bonus-id