Response Promo Redeemer Security & Risk Analysis

wordpress.org/plugins/response-promotion-redeemer

The Response Promotion Redemption plugin allows you to create partner promotions with list of your promotion codes and your partners.

10 active installs v1.1.0 PHP + WP 3.3.2+ Updated Aug 13, 2012
coupon-codespartner-promotionpromopromo-portalpromotion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Response Promo Redeemer Safe to Use in 2026?

Generally Safe

Score 85/100

Response Promo Redeemer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "response-promotion-redeemer" plugin v1.1.0 exhibits a mixed security posture. On the positive side, it has no known vulnerabilities in its history and a relatively small attack surface. The lack of AJAX handlers and REST API routes without authentication is a good practice. However, the code analysis reveals significant areas of concern. The low percentage of properly escaped output (22%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis indicates one high-severity flow with unsanitized data, which could lead to various exploits if not handled with extreme care. Furthermore, the absence of nonce checks and capability checks on any entry points is a critical oversight, leaving the plugin vulnerable to CSRF and unauthorized action execution.

The plugin's vulnerability history is clean, which is a positive indicator for past development. However, this does not mitigate the risks identified in the current static analysis. The combination of poor output escaping and the absence of essential security checks like nonces and capability checks, despite a limited attack surface, points to a plugin that, while not historically exploited, has foundational security weaknesses that could be exploited in its current version.

Key Concerns

  • High severity taint flow with unsanitized path
  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
  • SQL queries not always using prepared statements
Vulnerabilities
None known

Response Promo Redeemer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Response Promo Redeemer Release Timeline

v1.1.0Current
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Response Promo Redeemer Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
8 prepared
Unescaped Output
32
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared12 total queries

Output Escaping

22% escaped41 total outputs
Data Flows · Security
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
fn_rm_csv_export (includes\csv-export.php:11)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Response Promo Redeemer Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[promo-form] includes\form-shortcodes.php:69
WordPress Hooks 11
actionadmin_menuincludes\admin-page.php:61
actionadmin_initincludes\admin-page.php:67
actioninitincludes\csv-export.php:77
filterthe_contentincludes\display-functions.php:12
actioninitincludes\promo-ctype.php:4
filterpost_updated_messagesincludes\promo-ctype.php:40
actioninitincludes\promo-ctype.php:64
actionwp_enqueue_scriptsincludes\scripts.php:12
actionedit_postresponse-promo-redeemer.php:115
actionadmin_initresponse-promo-redeemer.php:119
actionsave_postresponse-promo-redeemer.php:120
Maintenance & Trust

Response Promo Redeemer Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedAug 13, 2012
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Response Promo Redeemer Developer Profile

bielefeldt

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Response Promo Redeemer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/response-promotion-redeemer/css/response-promo-redeemer.css/wp-content/plugins/response-promotion-redeemer/js/response-promo-redeemer.js
Script Paths
/wp-content/plugins/response-promotion-redeemer/js/response-promo-redeemer.js
Version Parameters
response-promotion-redeemer/css/response-promo-redeemer.css?ver=response-promotion-redeemer/js/response-promo-redeemer.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Include Admin Page --><!-- Include Scripts --><!-- Include Display Functions --><!-- Include CSV Export -->+48 more
Data Attributes
id="siteurl"name="siteurl"id="from"name="from"id="new_partner_type"name="new_partner_type"+73 more
JS Globals
window.rpr_adminwindow.rpr_admin.nonce
Shortcode Output
[promo_form][promo_form][promo_display][promo_display]
FAQ

Frequently Asked Questions about Response Promo Redeemer