
BundleCraft Security & Risk Analysis
wordpress.org/plugins/bundlecraftCreate unlimited product bundles or combo offers in WooCommerce with custom discounts, titles, and responsive layouts.
Is BundleCraft Safe to Use in 2026?
Generally Safe
Score 100/100BundleCraft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bundlecraft plugin v1.2.2 demonstrates a generally strong security posture based on the provided static analysis. The absence of known CVEs and a history of no recorded vulnerabilities is a significant positive indicator of the plugin's maturity and security focus. All identified entry points, including AJAX handlers and shortcodes, appear to have authentication and permission checks, which is a crucial security best practice. Furthermore, the plugin utilizes prepared statements for all SQL queries and properly escapes all output, mitigating common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The use of nonces and capability checks on its entry points further strengthens its defenses.
However, the taint analysis does reveal a potential area of concern. The presence of two "flows with unsanitized paths" indicates that user-supplied input might be used in a way that could lead to path traversal or other file system-related vulnerabilities if not handled with extreme care. While no critical or high severity issues were flagged in this analysis, this finding warrants further investigation. The plugin's attack surface is relatively small, and the complete absence of unprotected entry points is commendable. The overall picture is of a well-developed plugin with a good security foundation, but with a specific, albeit potentially low-risk, taint issue that should be addressed for complete security.
Key Concerns
- Flows with unsanitized paths
BundleCraft Security Vulnerabilities
BundleCraft Release Timeline
BundleCraft Code Analysis
Output Escaping
Data Flow Analysis
BundleCraft Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
BundleCraft Maintenance & Trust
Maintenance Signals
Community Trust
BundleCraft Alternatives
BundlePress – Grouped Product Bundle Builder for WooCommerce
bundlepress
Professional WooCommerce bundle builder. Create and manage custom WooCommerce bundle products with flexible pricing and display options.
QuickBundles – WooCommerce Product Bundles
quickbundles
Easily create compelling product bundles in WooCommerce to boost your sales and average order value. Intuitive builder, flexible pricing & urgency …
Discount Rules for WooCommerce
woo-discount-rules
The discount plugin for WooCommerce helps you create bulk discount, quantity discount, storewide sale, dynamic pricing discount offers easily.
Smart Coupons For WooCommerce Coupons
wt-smart-coupons-for-woocommerce
Best WooCommerce coupons plugin to create advanced coupons and discount codes with auto-apply, BOGO, free shipping, giveaways, and discount rules.
Advanced Dynamic Pricing and Discount Rules for WooCommerce
advanced-dynamic-pricing-for-woocommerce
The discount plugin for WooCommerce supports any dynamic pricing discount: bulk discount, role discount, storewide, bogo, gifts, cart discount
BundleCraft Developer Profile
2 plugins · 0 total installs
How We Detect BundleCraft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bundlecraft/assets/css/bundlecraft-bundle-editor.css/wp-content/plugins/bundlecraft/assets/css/bundlecraft-bundle-frontend.css/wp-content/plugins/bundlecraft/assets/css/bundlecraft-frontend.css/wp-content/plugins/bundlecraft/assets/js/bundlecraft-admin.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-bundle-editor.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-frontend.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-helpers.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-admin.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-bundle-editor.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-frontend.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-helpers.jsbundlecraft/assets/css/bundlecraft-bundle-editor.css?ver=bundlecraft/assets/css/bundlecraft-bundle-frontend.css?ver=bundlecraft/assets/css/bundlecraft-frontend.css?ver=bundlecraft/assets/js/bundlecraft-admin.js?ver=bundlecraft/assets/js/bundlecraft-bundle-editor.js?ver=bundlecraft/assets/js/bundlecraft-frontend.js?ver=bundlecraft/assets/js/bundlecraft-helpers.js?ver=HTML / DOM Fingerprints
bundlecraft-bundle-editorbundlecraft-bundle-frontendbundlecraft-frontendbundlecraft-product-bundlebundlecraft-add-to-cartbundlecraft-bundle-wrap<!-- START BundleCraft product bundle wrapper --><!-- END BundleCraft product bundle wrapper --><!-- BundleCraft Product Bundle: Configuration Options --><!-- BundleCraft Product Bundle: Add to Cart Button -->+1 moredata-bundlecraft-product-iddata-bundlecraft-bundle-iddata-bundlecraft-optionsdata-bundlecraft-priceBundleCraftFrontendbundlecraft_frontend_paramsBundleCraftAdminbundlecraft_admin_paramsBundleCraftBundleEditorbundlecraft_bundle_editor_params[bundlecraft_product_bundle][bundlecraft_bundle_add_to_cart]