
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more Security & Risk Analysis
wordpress.org/plugins/scratch-win-giveaways-for-website-facebookDisplay a Scratch Card on your website to offer visitors a chance to win prizes. A fun incentive to boost conversions!
Is Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more Safe to Use in 2026?
Generally Safe
Score 98/100Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more has a strong security track record. Known vulnerabilities have been patched promptly.
This plugin exhibits a mixed security posture. While it demonstrates strong practices in SQL query handling and output escaping, significant vulnerabilities lie in its attack surface and lack of authorization checks. The static analysis reveals a substantial number of unprotected AJAX handlers and REST API routes, presenting a broad avenue for potential exploits. The taint analysis further highlights a high-severity flow with unsanitized paths, indicating a direct risk of vulnerabilities like cross-site scripting or directory traversal if exploited. The plugin's history of known CVEs, particularly those involving missing authorization, CSRF, and XSS, strongly correlates with the current findings, suggesting recurring security weaknesses that have not been fully addressed.
Despite the strengths in secure coding for SQL and output, the sheer number of unprotected entry points and the identified taint flow are major concerns. The historical pattern of medium-severity vulnerabilities like Missing Authorization, CSRF, and XSS, even though currently unpatched, points to an ongoing struggle with securing user input and controlling access. This plugin should be treated with caution, and immediate attention should be paid to implementing proper authorization checks and sanitizing all user-supplied data, especially within the identified unprotected AJAX and REST API endpoints.
Key Concerns
- Unprotected AJAX handlers
- REST API routes without permission callbacks
- High severity taint flow with unsanitized paths
- Missing nonce checks on AJAX
- Vulnerability history (3 medium CVEs)
- Vulnerability history pattern (Missing Auth, CSRF, XSS)
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Scratch & Win – Giveaways and Contests <= 2.8.0 - Missing Authorization to Unauthenticated Coupon Creation
Scratch & Win – Giveaways and Contests <= 2.7.1 - Cross-Site Request Forgery via reset_installation Function
Scratch & Win – Giveaways and Contests <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more Attack Surface
AJAX Handlers 4
REST API Routes 11
Shortcodes 2
WordPress Hooks 8
Maintenance & Trust
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more Maintenance & Trust
Maintenance Signals
Community Trust
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more Alternatives
Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more
social-boost
Run viral giveaways, contests, competitions, sweepstakes, purchase for chance to win, instant wins, refer-a-friend, and boost subscribers, followers, …
Woobox
woobox
Easily embed your Woobox promotions in WordPress using a simple shortcode.
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program
gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce
Loyalty + Referral + Rewards + Birthdays and Anniversaries + Giveaways + Contests + Competitions + Sweepstakes. Selling on ETSY? Reward points for yo …
Gratisfaction- Contests Giveaways Referral Loyalty Rewards and Birthdays Program
gratisfaction-social-contests-referral-loyalty-rewards-program-by-appsmav
All-in-One Loyalty + Giveaways + Contests + Competitions + Referral + Birthdays + Anniversaries App. No Coding. Easy DIY Setup.
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
rafflepress
The best WordPress giveaway plugin. Grow your email list, website traffic, and social media followers with viral contests, giveaways, and sweepstakes.
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more Developer Profile
4 plugins · 1K total installs
How We Detect Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scratch-win-giveaways-for-website-facebook/assets/css/appsmav-scratchwin.css/wp-content/plugins/scratch-win-giveaways-for-website-facebook/assets/js/appsmav-scratchwin-admin.js/wp-content/plugins/scratch-win-giveaways-for-website-facebook/assets/js/appsmav-scratchwin-public.js//cdn.appsmav.com/win/assets/js/swin-widget-sdk.jshttps://appsmav.com/script.jsscratch-win-giveaways-for-website-facebook/assets/css/appsmav-scratchwin.css?ver=scratch-win-giveaways-for-website-facebook/assets/js/appsmav-scratchwin-admin.js?ver=scratch-win-giveaways-for-website-facebook/assets/js/appsmav-scratchwin-public.js?ver=HTML / DOM Fingerprints
swin-widgetdata-appsmav-scratchwin-idAMSWINConfigappsmav_scratchwin_admin_ajax_object/wp-json/appsmav_scratchwin/v1/save_settings/wp-json/appsmav_scratchwin/v1/register_account/wp-json/appsmav_scratchwin/v1/check_login/wp-json/appsmav_scratchwin/v1/check_autologin/wp-json/appsmav_scratchwin/v1/check_settings<a class="swin-widget" href="