
Reward Points for wc-marketplace Security & Risk Analysis
wordpress.org/plugins/reward-points-for-wc-marketplaceReward points for wc-marketplace is used to add reward point system to your woocommerce store in which your store has multiple vendors.
Is Reward Points for wc-marketplace Safe to Use in 2026?
Generally Safe
Score 85/100Reward Points for wc-marketplace has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "reward-points-for-wc-marketplace" v1.0 plugin exhibits a concerning security posture, primarily due to a significant number of unprotected AJAX endpoints and a high proportion of unsanitized data flows. While the plugin's vulnerability history is clean, suggesting a lack of publicly known exploits, the static analysis reveals critical weaknesses that could be easily leveraged by attackers. The presence of 8 unprotected AJAX handlers represents a substantial attack surface where malicious input could be processed without proper authorization or validation.
Furthermore, the taint analysis highlights 3 flows with unsanitized paths, all flagged as high severity. This indicates that data entering the plugin is not being properly cleaned before being used, potentially leading to vulnerabilities like cross-site scripting (XSS) or even remote code execution (RCE) depending on how this data is handled later in the codebase. The low percentage of properly escaped output (29%) exacerbates this risk, as user-supplied data might be displayed directly to other users without sanitization, leading to XSS attacks.
Despite the absence of known CVEs, the critical findings in the static analysis, particularly the unprotected entry points and tainted data flows, strongly suggest that the plugin is vulnerable. The plugin's strengths lie in the relatively low number of file operations and external HTTP requests, and the use of prepared statements for a majority of its SQL queries. However, these positive aspects are overshadowed by the readily exploitable weaknesses, making a proactive security approach essential.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Low percentage of properly escaped output
- Missing capability checks on AJAX handlers
- Bundled outdated library (DataTables v1.10.16)
Reward Points for wc-marketplace Security Vulnerabilities
Reward Points for wc-marketplace Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Reward Points for wc-marketplace Attack Surface
AJAX Handlers 8
WordPress Hooks 27
Maintenance & Trust
Reward Points for wc-marketplace Maintenance & Trust
Maintenance Signals
Community Trust
Reward Points for wc-marketplace Alternatives
Migrate to WooCommerce Multivendor Marketplace
wc-multivendor-marketplace-migration
Migrate your WC Markerplace or WC Vendors Marketplace or Dokan Multivendor or WC Product Vendors store to WooCommerce Multivendor Marketplace (WCFM Ma …
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
dokan-lite
Transform your WooCommerce site into a multivendor marketplace with Dokan – an AI powered & advanced WooCommerce marketplace solution
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
wc-frontend-manager
Vendor frontend store/shop manager for WC Marketplace, WC Vendors, WC Product Vendors & Dokan with Bookings, Listings & Subscriptions compatib …
WCFM Marketplace – Multivendor Marketplace for WooCommerce
wc-multivendor-marketplace
The most featured and powerful multi vendor plugin for WordPress, setup fantastic woocommerce marketplace store in minutes.
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace
wc-multivendor-membership
A simple woocommerce memberships plugin for offering free and premium subscription for your multi-vendor marketplace - WCFM Marketplace, WC Vendors &a …
Reward Points for wc-marketplace Developer Profile
4 plugins · 60 total installs
How We Detect Reward Points for wc-marketplace
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reward-points-for-wc-marketplace/js/custom.js/wp-content/plugins/reward-points-for-wc-marketplace/js/modernizr.min.js/wp-content/plugins/reward-points-for-wc-marketplace/lib/jquery.dataTables.min.js/wp-content/plugins/reward-points-for-wc-marketplace/js/custom.js/wp-content/plugins/reward-points-for-wc-marketplace/js/modernizr.min.js/wp-content/plugins/reward-points-for-wc-marketplace/lib/jquery.dataTables.min.jsreward-points-for-wc-marketplace/js/custom.js?ver=reward-points-for-wc-marketplace/js/modernizr.min.js?ver=reward-points-for-wc-marketplace/lib/jquery.dataTables.min.js?ver=HTML / DOM Fingerprints
ajax_objectcart_ajax