SweepWidget – Contests, Giveaways, Sweepstakes & Photo Contests Security & Risk Analysis

wordpress.org/plugins/sweepwidget

The best free WordPress contest tool to run giveaways, sweepstakes, photo contests, voting contests, raffles, and instant coupons.

100 active installs v2.0.8 PHP 7.0+ WP 3.0.1+ Updated Feb 12, 2026
contestgiveawayrafflesweepstakesvoting
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 6, 2025
Safety Verdict

Is SweepWidget – Contests, Giveaways, Sweepstakes & Photo Contests Safe to Use in 2026?

Generally Safe

Score 99/100

SweepWidget – Contests, Giveaways, Sweepstakes & Photo Contests has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 6, 2025Updated 1mo ago
Risk Assessment

The sweepwidget plugin v2.0.8 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are significant strengths. The plugin also demonstrates good practices by having a limited attack surface with only one entry point (a shortcode) and no identified cron events or file operations that could be easily exploited. Taint analysis showing zero unsanitized flows further reinforces this positive outlook.

Key Concerns

  • One medium severity CVE in history
  • External HTTP requests present
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
1

SweepWidget – Contests, Giveaways, Sweepstakes & Photo Contests Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11756medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SweepWidget Contests, Giveaways, Photo Contests, Competitions <= 2.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 6, 2025 Patched in 2.0.7 (402d)
Code Analysis
Analyzed Mar 16, 2026

SweepWidget – Contests, Giveaways, Sweepstakes & Photo Contests Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
66 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped66 total outputs
Attack Surface

SweepWidget – Contests, Giveaways, Sweepstakes & Photo Contests Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[sweepwidget] sweepwidget.php:530
WordPress Hooks 3
actionadmin_menusweepwidget.php:33
actionadmin_initsweepwidget.php:36
actionadmin_enqueue_scriptssweepwidget.php:510
Maintenance & Trust

SweepWidget – Contests, Giveaways, Sweepstakes & Photo Contests Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 12, 2026
PHP min version7.0
Downloads10K

Community Trust

Rating86/100
Number of ratings14
Active installs100
Developer Profile

SweepWidget – Contests, Giveaways, Sweepstakes & Photo Contests Developer Profile

SweepWidget

1 plugin · 100 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
402 days
View full developer profile
Detection Fingerprints

How We Detect SweepWidget – Contests, Giveaways, Sweepstakes & Photo Contests

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sweepwidget/sweepwidget.css/wp-content/plugins/sweepwidget/sweepwidget.js
Script Paths
/wp-content/plugins/sweepwidget/sweepwidget.js
Version Parameters
sweepwidget/sweepwidget.css?ver=sweepwidget/sweepwidget.js?ver=

HTML / DOM Fingerprints

CSS Classes
sweepwidget-wrappersweepwidget-embed
Data Attributes
data-sweepwidget-iddata-sweepwidget-widget-id
JS Globals
SWEEPWidget
Shortcode Output
[sweepwidget]
FAQ

Frequently Asked Questions about SweepWidget – Contests, Giveaways, Sweepstakes & Photo Contests