
WP Keys Giveaway Security & Risk Analysis
wordpress.org/plugins/wp-keys-giveawayDo you have some keys for a software or videogame and want to give them to your users? This plugin is what you're looking for!
Is WP Keys Giveaway Safe to Use in 2026?
Generally Safe
Score 85/100WP Keys Giveaway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-keys-giveaway v1.0.1 plugin exhibits a generally positive security posture with some notable concerns. A significant strength is the complete absence of raw SQL queries, with all 23 queries utilizing prepared statements. This greatly mitigates the risk of SQL injection vulnerabilities. Furthermore, the plugin has no recorded history of vulnerabilities, indicating a potentially mature and well-maintained codebase. However, the presence of one unprotected AJAX handler significantly increases the attack surface. While the plugin employs nonce checks and capability checks, this single entry point lacks proper authentication, making it a prime target for unauthenticated attackers who could potentially trigger unintended actions within the plugin.
The static analysis reveals no critical or high severity issues in taint analysis, and dangerous functions are also absent. The main area of concern stems from the unprotected AJAX handler, which represents a direct avenue for exploitation. The output escaping is also not fully comprehensive, with 31% of outputs not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is involved in those outputs.
In conclusion, while the plugin demonstrates good practices in data handling (prepared statements) and has a clean vulnerability history, the single unprotected AJAX endpoint is a critical weakness that requires immediate attention. Addressing this missing authentication check is paramount to improving the plugin's overall security. The incomplete output escaping also warrants review to ensure user-provided data is handled safely.
Key Concerns
- AJAX handler without auth checks
- Outputs not properly escaped
WP Keys Giveaway Security Vulnerabilities
WP Keys Giveaway Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Keys Giveaway Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
WP Keys Giveaway Maintenance & Trust
Maintenance Signals
Community Trust
WP Keys Giveaway Alternatives
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
rafflepress
The best WordPress giveaway plugin. Grow your email list, website traffic, and social media followers with viral contests, giveaways, and sweepstakes.
Interact: Embed A Quiz On Your Site
interact-quiz-embed
Use this plugin to generate a shortcode to embed your Interact Quiz, Poll, or Giveaway into your WordPress site.
Woorise – Landing Pages, Forms & Surveys
woorise
Create landing pages, forms, surveys, quizzes and viral giveaways.
Woobox
woobox
Easily embed your Woobox promotions in WordPress using a simple shortcode.
Raffle Play Woocommerce
raffle-play-woo
Raffle Play Woo is generating raffle tickets for woocommerce products, based on the number defined by the admin. Adds raffle tickets to your woocommer …
WP Keys Giveaway Developer Profile
2 plugins · 30 total installs
How We Detect WP Keys Giveaway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-keys-giveaway/images/delete.pngHTML / DOM Fingerprints
sh9_deletekeyid="sh9_meta_box_iplock"name="sh9_meta_box_iplock"id="sh9_meta_box_loggedin"name="sh9_meta_box_loggedin"id="code"name="code"+6 more[keys id=