Auto Import Coupons from vcommission Security & Risk Analysis

wordpress.org/plugins/auto-import-coupons-from-vcommission

WordPress Coupon plugin to auto-import affiliate coupon and deals to your WordPress site from vCommission partners account.

10 active installs v1.0 PHP 7.0+ WP 4.6+ Updated Mar 14, 2021
affiliatecouponsdealdealsvcommission-coupon
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Auto Import Coupons from vcommission Safe to Use in 2026?

Generally Safe

Score 85/100

Auto Import Coupons from vcommission has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "auto-import-coupons-from-vcommission" v1.0 exhibits a generally good security posture based on the provided static analysis. The absence of any recorded vulnerabilities (CVEs) and the clean taint analysis, with no identified flows of unsanitized data, are significant strengths. The code also demonstrates good output escaping practices, ensuring that data displayed to users is handled safely. However, there are areas for improvement. The presence of two SQL queries that do not use prepared statements is a concern, as it opens the door to potential SQL injection vulnerabilities, especially if the input used in these queries is not rigorously validated and sanitized on the server-side. Furthermore, the lack of nonce checks, while not directly tied to an attack surface in this analysis (as there are no AJAX handlers), represents a missed opportunity for robust security against common WordPress attacks like Cross-Site Request Forgery (CSRF) if entry points were to be introduced in the future. The single cron event and single capability check suggest a limited scope of functionality, which is positive from a security perspective as it reduces the potential for complex vulnerabilities. Overall, while the plugin is currently free of known issues and follows some good practices, the unescaped SQL queries warrant attention to prevent future vulnerabilities.

Key Concerns

  • SQL queries without prepared statements
  • Missing nonce checks
Vulnerabilities
None known

Auto Import Coupons from vcommission Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Auto Import Coupons from vcommission Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

100% escaped4 total outputs
Attack Surface

Auto Import Coupons from vcommission Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitincludes\wp_vc-function.php:24
actioninitincludes\wp_vc-function.php:45
actionadmin_menuincludes\wp_vc-settings.php:12
actionadmin_initincludes\wp_vc-settings.php:13
actionwpvc_coupon_hookwp-vcommission-coupons.php:27

Scheduled Events 1

wpvc_coupon_hook
Maintenance & Trust

Auto Import Coupons from vcommission Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 14, 2021
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Auto Import Coupons from vcommission Developer Profile

Sanoj Sharma

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto Import Coupons from vcommission

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Auto Import Coupons from vcommission