
Buy one Get one Free – BOGO discount rule maker for WooCommerce Security & Risk Analysis
wordpress.org/plugins/buy-one-get-one-freeCreate buy one get one free or buy X get Y Free, BOGO discount rule of product in WooCommerce
Is Buy one Get one Free – BOGO discount rule maker for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Buy one Get one Free – BOGO discount rule maker for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'buy-one-get-one-free' plugin v1.11.10 exhibits a generally good security posture, with strong adherence to several WordPress security best practices. The plugin has no recorded vulnerabilities (CVEs), which is a significant positive indicator of its past security. Static analysis reveals a limited attack surface with all identified entry points (AJAX handlers) protected by nonce and capability checks. Furthermore, SQL queries are exclusively prepared, and there are no file operations or external HTTP requests that could pose immediate risks.
However, there are some areas for improvement. A notable concern is the presence of one unsanitized path in the taint analysis, which, although not flagged as critical or high severity, represents a potential risk for injection attacks if that path can be manipulated by an attacker. Additionally, while the majority of output is properly escaped (79%), the 21% that is not could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved. The plugin also makes an external HTTP request, which, while not inherently dangerous, should be carefully scrutinized to ensure it doesn't expose sensitive information or introduce supply chain risks.
In conclusion, the plugin demonstrates good foundational security practices, particularly in its handling of AJAX requests and SQL queries. The lack of historical vulnerabilities is reassuring. The primary areas to focus on for hardening are the identified unsanitized path and improving output escaping to reach closer to 100% for all output, thereby mitigating potential XSS risks. The single external HTTP request should also be reviewed for security implications.
Key Concerns
- Flow with unsanitized path
- 21% of outputs not properly escaped
- External HTTP request present
Buy one Get one Free – BOGO discount rule maker for WooCommerce Security Vulnerabilities
Buy one Get one Free – BOGO discount rule maker for WooCommerce Release Timeline
Buy one Get one Free – BOGO discount rule maker for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Buy one Get one Free – BOGO discount rule maker for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 37
Maintenance & Trust
Buy one Get one Free – BOGO discount rule maker for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Buy one Get one Free – BOGO discount rule maker for WooCommerce Alternatives
ingenidev Buy One Get One Free (BOGO) for WooCommerce
ingenidev-bogo-offers-for-woocommerce
NEW Plugin! The ultimate WooCommerce plugin for creating powerful Buy One Get One Free (BOGO) deals, dynamic pricing rules, quantity discounts to boos …
DC BOGO Coupons
dc-bogo-coupons
The minimal, elegant, and powerful solution for creating advanced Buy One, Get One offers in WooCommerce.
Quick Buy One Get One Free
quick-buy-one-get-one-free
Create BOGO offers to boost your WooCommerce stores conversion rate.
BOGO Same Product (Buy One Get One Free)
virtualcode-bogo-same-product
Run Buy One Get One Free promotions in WooCommerce with automatic cart handling.
Smart Coupons For WooCommerce Coupons
wt-smart-coupons-for-woocommerce
Best WooCommerce coupons plugin to create advanced coupons and discount codes with auto-apply, BOGO, free shipping, giveaways, and discount rules.
Buy one Get one Free – BOGO discount rule maker for WooCommerce Developer Profile
33 plugins · 93K total installs
How We Detect Buy one Get one Free – BOGO discount rule maker for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
buy-one-get-one-free-woocommerce/admin/css/bootstrap.cssbuy-one-get-one-free-woocommerce/admin/js/buy-one-get-one-free-woocommerce-admin.jsbuy-one-get-one-free-woocommerce/admin/js/pisol-quick-save.jsbuy-one-get-one-free-woocommerce/admin/css/bootstrap.css?ver=buy-one-get-one-free-woocommerce/admin/js/buy-one-get-one-free-woocommerce-admin.js?ver=buy-one-get-one-free-woocommerce/admin/js/pisol-quick-save.js?ver=HTML / DOM Fingerprints
pisol-containerpisol-rowbg-darkid="pisolpisol_bogo_params/wp-json/pisol_bogo/v1/products