Bulk Products Pricing Security & Risk Analysis

wordpress.org/plugins/bulk-products-pricing

Set different prices based on product quantities. Perfect for wholesale, bulk discounts, and tiered pricing strategies in WooCommerce.

0 active installs v1.0.1 PHP 7.4+ WP 6.2+ Updated Nov 19, 2025
bulk-pricingquantity-pricingtiered-pricingwholesalewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bulk Products Pricing Safe to Use in 2026?

Generally Safe

Score 100/100

Bulk Products Pricing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'bulk-products-pricing' plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The code demonstrates adherence to secure coding practices, with all identified SQL queries utilizing prepared statements and all output being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. The plugin also incorporates a good number of nonce checks, indicating a proactive approach to preventing CSRF attacks on its AJAX endpoints. The vulnerability history being clean, with no known CVEs, suggests a mature and well-maintained codebase.

While the static analysis reveals a lack of identified critical or high-severity taint flows and a protected attack surface with no unprotected entry points, the complete absence of capability checks on AJAX handlers is a notable concern. This means that any authenticated user, regardless of their role, could potentially interact with these AJAX endpoints, which might lead to unintended actions or information disclosure if the logic within these handlers isn't robust enough to handle all user types. The presence of a bundled library (Select2) also warrants attention, as its version is not specified, and outdated libraries can introduce vulnerabilities.

In conclusion, the plugin's core code appears to be written with security in mind, showing excellent practices in SQL sanitization and output escaping. However, the lack of capability checks on its AJAX handlers presents a significant potential risk that requires immediate attention. The bundled library also represents a minor, yet important, area for review. Overall, the plugin is in a good state but could be significantly improved by implementing role-based access control for its AJAX endpoints.

Key Concerns

  • AJAX handlers lack capability checks
  • Bundled library version not specified (potential outdated library)
Vulnerabilities
None known

Bulk Products Pricing Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Bulk Products Pricing Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
223 escaped
Nonce Checks
8
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

100% escaped223 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
aicoso_bulk_prod_price_choose_categories (admin\class-aicoso-bulk-prod-price-admin.php:39)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bulk Products Pricing Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_aicoso_bulk_prod_price_choose_categoriesadmin\class-aicoso-bulk-prod-price-admin.php:36
noprivwp_ajax_aicoso_bulk_prod_price_choose_categoriesadmin\class-aicoso-bulk-prod-price-admin.php:37
authwp_ajax_aicoso_bulk_prod_price_single_qtypublic\class-aicoso-bulk-prod-price-public.php:35
noprivwp_ajax_aicoso_bulk_prod_price_single_qtypublic\class-aicoso-bulk-prod-price-public.php:36
WordPress Hooks 18
actionwoocommerce_product_options_general_product_dataadmin\class-aicoso-bulk-prod-price-admin.php:29
actionsave_postadmin\class-aicoso-bulk-prod-price-admin.php:30
actionwoocommerce_variation_options_pricingadmin\class-aicoso-bulk-prod-price-admin.php:31
actionwoocommerce_save_product_variationadmin\class-aicoso-bulk-prod-price-admin.php:32
actionadmin_enqueue_scriptsadmin\class-aicoso-bulk-prod-price-admin.php:34
actionadmin_menuadmin\class-aicoso-bulk-prod-price-admin.php:35
actionbefore_woocommerce_initbulk-products-pricing.php:67
actionadmin_initbulk-products-pricing.php:107
actionadmin_noticesbulk-products-pricing.php:116
filterwoocommerce_get_price_htmlpublic\class-aicoso-bulk-prod-price-public.php:33
actionwp_enqueue_scriptspublic\class-aicoso-bulk-prod-price-public.php:34
actionwoocommerce_before_calculate_totalspublic\class-aicoso-bulk-prod-price-public.php:38
actionwoocommerce_after_cart_item_quantity_updatepublic\class-aicoso-bulk-prod-price-public.php:41
actionwoocommerce_single_product_summarypublic\class-aicoso-bulk-prod-price-public.php:42
filterwoocommerce_product_is_taxablepublic\class-aicoso-bulk-prod-price-public.php:43
filterwoocommerce_cart_item_pricepublic\class-aicoso-bulk-prod-price-public.php:46
filterwoocommerce_cart_item_subtotalpublic\class-aicoso-bulk-prod-price-public.php:47
actionwoocommerce_cart_loaded_from_sessionpublic\class-aicoso-bulk-prod-price-public.php:50
Maintenance & Trust

Bulk Products Pricing Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 19, 2025
PHP min version7.4
Downloads213

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Bulk Products Pricing Developer Profile

aicoso

3 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bulk Products Pricing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bulk-products-pricing/public/js/aicoso-bulk-prod-price-public.js/wp-content/plugins/bulk-products-pricing/admin/js/aicoso-bulk-prod-price-admin.js/wp-content/plugins/bulk-products-pricing/admin/css/aicoso-bulk-prod-price-admin.css
Script Paths
/wp-content/plugins/bulk-products-pricing/public/js/aicoso-bulk-prod-price-public.js/wp-content/plugins/bulk-products-pricing/admin/js/aicoso-bulk-prod-price-admin.js
Version Parameters
bulk-products-pricing/public/js/aicoso-bulk-prod-price-public.js?ver=bulk-products-pricing/admin/js/aicoso-bulk-prod-price-admin.js?ver=bulk-products-pricing/admin/css/aicoso-bulk-prod-price-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
aicoso-bulk-prod-price-admin-wrapper
Data Attributes
data-aicoso-bulk-prod-price-variation-iddata-aicoso-bulk-prod-price-product-id
JS Globals
aicoso_bulk_prod_price_admin_params
REST Endpoints
/wp-json/aicoso-bulk-prod-price/v1/get-price
FAQ

Frequently Asked Questions about Bulk Products Pricing