
MyRewards Security & Risk Analysis
wordpress.org/plugins/woorewardsFree top-rated points and rewards program to retain your customers, grow your sales and get new customers.
Is MyRewards Safe to Use in 2026?
Generally Safe
Score 98/100MyRewards has a strong security track record. Known vulnerabilities have been patched promptly.
The "woorewards" plugin v5.7.3 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped output, there are significant concerns. The presence of the `unserialize` function, especially without explicitly mentioned nonce or capability checks on all potential usage points, raises a red flag for potential deserialization vulnerabilities. Furthermore, the taint analysis revealing 6 out of 7 flows with unsanitized paths, including 3 high-severity flows, indicates potential risks of data manipulation or code execution if these paths are exposed to user input without proper sanitization. The vulnerability history, showing two medium-severity CVEs in the past, both related to missing authorization, suggests a recurring pattern of authorization flaws. While there are currently no unpatched vulnerabilities, this history warrants caution, especially in conjunction with the code signals.
Key Concerns
- Dangerous function unserialize used
- High severity taint flow found
- Unsanitized paths in taint analysis
- No nonce checks detected
- Medium severity CVEs in history
MyRewards Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
MyRewards – Loyalty Points and Rewards for WooCommerce <= 5.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Loyalty Rule Modification
MyRewards <= 5.3.0 - Missing Authorization
MyRewards Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
MyRewards Attack Surface
WordPress Hooks 9
Maintenance & Trust
MyRewards Maintenance & Trust
Maintenance Signals
Community Trust
MyRewards Alternatives
Loyalty Points Rewards and Referral for WooCommerce – WPLoyalty
wployalty
Create WooCommerce points and rewards program with WPLoyalty to increase customer loyalty and boost sales. Reward customers to drive repeat purchases.
RewardsWP – Loyalty Points & Referral Program for WooCommerce
rewardswp
Turn customers into brand advocates with loyalty points and referral programs for WooCommerce and Easy Digital Downloads.
XT Points & Rewards for WooCommerce
xt-woo-points-rewards
Points and Rewards for WooCommerce that lets you reward your customers for purchases and other actions with points that can be redeemed for discounts.
Loyalty for WooCommerce – Points and Rewards / Loyalty Program
loyalty-for-woocommerce
Create a flexible loyalty and rewards program for WooCommerce—reward customers with points, increase retention, and grow repeat sales.
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
mycred
A WordPress gamification plugin is also a points management system. Award ranks, loyalty points and rewards or WooCommerce rewards to your users.
MyRewards Developer Profile
2 plugins · 3K total installs
How We Detect MyRewards
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woorewards/assets/css/bootstrap-grid.min.css/wp-content/plugins/woorewards/assets/css/bootstrap-reboot.min.css/wp-content/plugins/woorewards/assets/css/chart.min.css/wp-content/plugins/woorewards/assets/css/daterangepicker.css/wp-content/plugins/woorewards/assets/css/select2.min.css/wp-content/plugins/woorewards/assets/css/style.css/wp-content/plugins/woorewards/assets/css/tooltips.css/wp-content/plugins/woorewards/assets/js/bootstrap.bundle.min.js+5 more/wp-content/plugins/woorewards/assets/js/bootstrap.bundle.min.js/wp-content/plugins/woorewards/assets/js/chart.min.js/wp-content/plugins/woorewards/assets/js/daterangepicker.min.js/wp-content/plugins/woorewards/assets/js/moment.min.js/wp-content/plugins/woorewards/assets/js/select2.min.js/wp-content/plugins/woorewards/assets/js/script.jswoorewards/assets/css/bootstrap-grid.min.css?ver=woorewards/assets/css/bootstrap-reboot.min.css?ver=woorewards/assets/css/chart.min.css?ver=woorewards/assets/css/daterangepicker.css?ver=woorewards/assets/css/select2.min.css?ver=woorewards/assets/css/style.css?ver=woorewards/assets/css/tooltips.css?ver=woorewards/assets/js/bootstrap.bundle.min.js?ver=woorewards/assets/js/chart.min.js?ver=woorewards/assets/js/daterangepicker.min.js?ver=woorewards/assets/js/moment.min.js?ver=woorewards/assets/js/select2.min.js?ver=woorewards/assets/js/script.js?ver=HTML / DOM Fingerprints
lws-woorewards-admin-pagelws-woorewards-customers-pagelws-woorewards-loyalty-pagelws-woorewards-settings-pagelws-wr-tooltip<!-- WooCommerce Points & Rewards by Long Watch Studio --><!-- LWS WooRewards -->data-lws-wr-tooltipLWSWooRewardsLWS_WOOREWARDS_AJAX_URL