BundleCraft Security & Risk Analysis

wordpress.org/plugins/bundlecraft

Create unlimited product bundles or combo offers in WooCommerce with custom discounts, titles, and responsive layouts.

0 active installs v1.2.2 PHP 7.4+ WP 5.8+ Updated Mar 29, 2026
bundle-buildercombo-offersdiscountsproduct-bundleswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is BundleCraft Safe to Use in 2026?

Generally Safe

Score 100/100

BundleCraft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The bundlecraft plugin v1.2.2 demonstrates a generally strong security posture based on the provided static analysis. The absence of known CVEs and a history of no recorded vulnerabilities is a significant positive indicator of the plugin's maturity and security focus. All identified entry points, including AJAX handlers and shortcodes, appear to have authentication and permission checks, which is a crucial security best practice. Furthermore, the plugin utilizes prepared statements for all SQL queries and properly escapes all output, mitigating common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The use of nonces and capability checks on its entry points further strengthens its defenses.

However, the taint analysis does reveal a potential area of concern. The presence of two "flows with unsanitized paths" indicates that user-supplied input might be used in a way that could lead to path traversal or other file system-related vulnerabilities if not handled with extreme care. While no critical or high severity issues were flagged in this analysis, this finding warrants further investigation. The plugin's attack surface is relatively small, and the complete absence of unprotected entry points is commendable. The overall picture is of a well-developed plugin with a good security foundation, but with a specific, albeit potentially low-risk, taint issue that should be addressed for complete security.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

BundleCraft Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BundleCraft Release Timeline

v1.2.2Current
v1.2.1
v1.2.0
v1.1.9
v1.1.8
Code Analysis
Analyzed Apr 16, 2026

BundleCraft Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
413 escaped
Nonce Checks
8
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped415 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
handle_preview (includes/class-bundlecraft-shortcode.php:592)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BundleCraft Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 5

authwp_ajax_bundlecraft_check_cartincludes/class-bundlecraft-ajax.php:36
noprivwp_ajax_bundlecraft_check_cartincludes/class-bundlecraft-ajax.php:37
authwp_ajax_bundlecraft_checkoutincludes/class-bundlecraft-ajax.php:40
noprivwp_ajax_bundlecraft_checkoutincludes/class-bundlecraft-ajax.php:41
authwp_ajax_bundlecraft_admin_previewincludes/class-bundlecraft-ajax.php:44

Shortcodes 1

[Bundle_Craft] includes/class-bundlecraft-shortcode.php:35
WordPress Hooks 19
actionplugins_loadedbundlecraft.php:67
actionbefore_woocommerce_initbundlecraft.php:70
actionadmin_noticesbundlecraft.php:113
actionadmin_menuincludes/class-bundlecraft-admin.php:35
actionadd_meta_boxesincludes/class-bundlecraft-admin.php:36
actionsave_post_bundlecraftincludes/class-bundlecraft-admin.php:37
actionadmin_enqueue_scriptsincludes/class-bundlecraft-admin.php:38
filtermanage_bundlecraft_posts_columnsincludes/class-bundlecraft-admin.php:41
actionmanage_bundlecraft_posts_custom_columnincludes/class-bundlecraft-admin.php:42
filterpost_row_actionsincludes/class-bundlecraft-admin.php:45
actionadmin_initincludes/class-bundlecraft-admin.php:46
filterplugin_row_metaincludes/class-bundlecraft-admin.php:50
actionbefore_delete_postincludes/class-bundlecraft-admin.php:53
actionwp_trash_postincludes/class-bundlecraft-admin.php:54
actionuntrash_postincludes/class-bundlecraft-admin.php:55
actioninitincludes/class-bundlecraft-cpt.php:35
actionwoocommerce_cart_calculate_feesincludes/class-bundlecraft-discounts.php:37
actionsave_postincludes/class-bundlecraft-helpers.php:25
actiontemplate_redirectincludes/class-bundlecraft-shortcode.php:36
Maintenance & Trust

BundleCraft Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 29, 2026
PHP min version7.4
Downloads372

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

BundleCraft Developer Profile

Technical Himanshu

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BundleCraft

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bundlecraft/assets/css/bundlecraft-bundle-editor.css/wp-content/plugins/bundlecraft/assets/css/bundlecraft-bundle-frontend.css/wp-content/plugins/bundlecraft/assets/css/bundlecraft-frontend.css/wp-content/plugins/bundlecraft/assets/js/bundlecraft-admin.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-bundle-editor.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-frontend.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-helpers.js
Script Paths
/wp-content/plugins/bundlecraft/assets/js/bundlecraft-admin.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-bundle-editor.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-frontend.js/wp-content/plugins/bundlecraft/assets/js/bundlecraft-helpers.js
Version Parameters
bundlecraft/assets/css/bundlecraft-bundle-editor.css?ver=bundlecraft/assets/css/bundlecraft-bundle-frontend.css?ver=bundlecraft/assets/css/bundlecraft-frontend.css?ver=bundlecraft/assets/js/bundlecraft-admin.js?ver=bundlecraft/assets/js/bundlecraft-bundle-editor.js?ver=bundlecraft/assets/js/bundlecraft-frontend.js?ver=bundlecraft/assets/js/bundlecraft-helpers.js?ver=

HTML / DOM Fingerprints

CSS Classes
bundlecraft-bundle-editorbundlecraft-bundle-frontendbundlecraft-frontendbundlecraft-product-bundlebundlecraft-add-to-cartbundlecraft-bundle-wrap
HTML Comments
<!-- START BundleCraft product bundle wrapper --><!-- END BundleCraft product bundle wrapper --><!-- BundleCraft Product Bundle: Configuration Options --><!-- BundleCraft Product Bundle: Add to Cart Button -->+1 more
Data Attributes
data-bundlecraft-product-iddata-bundlecraft-bundle-iddata-bundlecraft-optionsdata-bundlecraft-price
JS Globals
BundleCraftFrontendbundlecraft_frontend_paramsBundleCraftAdminbundlecraft_admin_paramsBundleCraftBundleEditorbundlecraft_bundle_editor_params
Shortcode Output
[bundlecraft_product_bundle][bundlecraft_bundle_add_to_cart]
FAQ

Frequently Asked Questions about BundleCraft