The best WordPress giveaway plugin. Grow your email list, website traffic, and social media followers with viral contests, giveaways, and sweepstakes.
Category Scores
Audit Overview
Open findings
1,124
261 errors, 863 warnings
Main area
Security
666 grouped findings
Last scanned
8s runtime
Audit stack
Plugin Check 2.0.0
Model 2026.06-mvp-static-v2
Issues to Review
Prioritized issue groups from the latest Plugin Check scan
Security
666
10 issue groups
Maintainability
456
8 issue groups
Repo Compliance
2
2 issue groups
WARNINGMaintainabilityNon Prefixed Variable FoundGlobal variables defined by a theme/plugin should start with the theme/plugin prefix. Found: "$action_token_ajax_url".223
- Category
- Maintainability
- Occurrences
- 223
- Severity
- warning
Sample message
Global variables defined by a theme/plugin should start with the theme/plugin prefix. Found: "$action_token_ajax_url".
ERRORSecurityNot PreparedUse placeholders and $wpdb->prepare(); found $query165
- Category
- Security
- Occurrences
- 165
- Severity
- error
Sample message
Use placeholders and $wpdb->prepare(); found $query
WARNINGSecurityMissing Unslash$_COOKIE['rafflepress_hash_' . $giveaway_id] not unslashed before sanitization. Use wp_unslash() or similar118
- Category
- Security
- Occurrences
- 118
- Severity
- warning
Sample message
$_COOKIE['rafflepress_hash_' . $giveaway_id] not unslashed before sanitization. Use wp_unslash() or similar
WARNINGMaintainabilityDirect QueryUse of a direct database call is discouraged.116
- Category
- Maintainability
- Occurrences
- 116
- Severity
- warning
Sample message
Use of a direct database call is discouraged.
WARNINGMaintainabilityNo CachingDirect database call without caching detected. Consider using wp_cache_get() / wp_cache_set() or wp_cache_delete().111
- Category
- Maintainability
- Occurrences
- 111
- Severity
- warning
Sample message
Direct database call without caching detected. Consider using wp_cache_get() / wp_cache_set() or wp_cache_delete().
ERRORSecurityUnescaped DBParameterUnescaped parameter $safe_sql used in $wpdb->get_results()\n$safe_sql assigned unsafely at line 107.92
- Category
- Security
- Occurrences
- 92
- Severity
- error
Sample message
Unescaped parameter $safe_sql used in $wpdb->get_results()\n$safe_sql assigned unsafely at line 107.
WARNINGSecurityInput Not ValidatedDetected usage of a possibly undefined superglobal array index: $_COOKIE['rafflepress_hash_' . $giveaway_id]. Check that the array index exists before using it.85
- Category
- Security
- Occurrences
- 85
- Severity
- warning
Sample message
Detected usage of a possibly undefined superglobal array index: $_COOKIE['rafflepress_hash_' . $giveaway_id]. Check that the array index exists before using it.
WARNINGSecurityRecommendedProcessing form data without nonce verification.78
- Category
- Security
- Occurrences
- 78
- Severity
- warning
Sample message
Processing form data without nonce verification.
WARNINGSecurityInput Not SanitizedDetected usage of a non-sanitized input variable: $_COOKIE['rafflepress_hash_' . $giveaway_id]64
- Category
- Security
- Occurrences
- 64
- Severity
- warning
Sample message
Detected usage of a non-sanitized input variable: $_COOKIE['rafflepress_hash_' . $giveaway_id]
WARNINGSecurityMissingProcessing form data without nonce verification.51
- Category
- Security
- Occurrences
- 51
- Severity
- warning
Sample message
Processing form data without nonce verification.
Show 10 more issue groups
WARNINGSecurityInput Not Validated Not Sanitized5
- Category
- Security
- Occurrences
- 5
- Severity
- warning
Sample message
Detected usage of a non-sanitized, non-validated input variable _SERVER: "://$_SERVER[HTTP_HOST]$_SERVER[REQUEST_URI]"
WARNINGSecurityUnescaped DBParameter4
- Category
- Security
- Occurrences
- 4
- Severity
- warning
Sample message
Unescaped parameter $safe_sql used in $wpdb->get_results()\n$safe_sql assigned unsafely at line 170.
WARNINGSecuritywp redirect wp redirect4
- Category
- Security
- Occurrences
- 4
- Severity
- warning
Sample message
wp_redirect() found. Using wp_safe_redirect(), along with the "allowed_redirect_hosts" filter if needed, can help avoid any chances of malicious redirects within code. It is also important to remember to call exit() after a redirect so that no other unwanted code is executed.
ERRORMaintainabilityfive star reviews detected2
- Category
- Maintainability
- Occurrences
- 2
- Severity
- error
Sample message
Linking directly to 5 stars reviews is not allowed.
WARNINGMaintainabilityNon Prefixed Function Found1
- Category
- Maintainability
- Occurrences
- 1
- Severity
- warning
Sample message
Functions declared in the global namespace by a theme/plugin should start with the theme/plugin prefix. Found: "seedprod_pro_upgrade_link_class".
WARNINGMaintainabilityerror log var dump1
- Category
- Maintainability
- Occurrences
- 1
- Severity
- warning
Sample message
var_dump() found. Debug code should not normally be used in production.
WARNINGMaintainabilitymismatched plugin name1
- Category
- Maintainability
- Occurrences
- 1
- Severity
- warning
Sample message
Plugin name "Giveaways and Contests by RafflePress - Get More Website Traffic, Email Subscribers, and Social Followers" is different from the name declared in plugin header "RafflePress Lite".
ERRORRepo Compliancereadme mismatched header requires1
- Category
- Repo Compliance
- Occurrences
- 1
- Severity
- error
Sample message
Mismatched Requires at least: 4.8 != 6.3. "Requires at least" needs to be exactly the same with that in your main plugin file's header.
WARNINGRepo Compliancereadme parser warnings too many tags1
- Category
- Repo Compliance
- Occurrences
- 1
- Severity
- warning
Sample message
One or more tags were ignored. Please limit your plugin to 5 tags.
ERRORMaintainabilitystable tag mismatch1
- Category
- Maintainability
- Occurrences
- 1
- Severity
- error
Sample message
Mismatched Stable Tag: 1.12.22 != 1.12.23. Your Stable Tag is meant to be the stable version of your plugin and it needs to be exactly the same with the Version in your main plugin file's header. Any mismatch can prevent users from downloading the correct plugin files from WordPress.org.
Score History
First score snapshot
Scan records1
v1.12.23
34
Latest
- Findings
- 1,124
- Errors
- 261
- Warnings
- 863
- Plugin Check
- 2.0.0
- Model
- 2026.06-mvp-static-v2
| Scan | Score | Findings | Errors | Warnings | Plugin | Plugin Check | Model |
|---|---|---|---|---|---|---|---|
| Latest | 34 | 1,124 | 261 | 863 | v1.12.23 | 2.0.0 | 2026.06-mvp-static-v2 |