
Buy One Get One Free for WooCommerce Security & Risk Analysis
wordpress.org/plugins/buy-one-get-one-free-for-woocommerceCompletely free and simple plugin to add buy one get one free offers to WooCommerce. No ads, no upsells.
Is Buy One Get One Free for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Buy One Get One Free for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'buy-one-get-one-free-for-woocommerce' plugin v1.0.0 reveals a very small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code does not appear to utilize dangerous functions, make external HTTP requests, or perform file operations. All SQL queries are using prepared statements, which is a strong security practice. However, a significant concern is that 0% of output is properly escaped. This means that any dynamic data displayed to users could potentially be vulnerable to Cross-Site Scripting (XSS) attacks if not handled carefully at the point of display.
The plugin's vulnerability history is clean, with no known CVEs recorded. This, combined with the absence of critical or high-severity issues in the static and taint analysis, suggests a generally well-written codebase in terms of common vulnerability classes. The lack of recorded vulnerabilities could indicate a history of secure development or a relatively new/untested plugin. The primary weakness identified is the lack of output escaping, which presents a potential XSS risk, though the absence of other common vulnerabilities is a positive sign.
Key Concerns
- 0% of output properly escaped
Buy One Get One Free for WooCommerce Security Vulnerabilities
Buy One Get One Free for WooCommerce Code Analysis
Output Escaping
Buy One Get One Free for WooCommerce Attack Surface
WordPress Hooks 15
Maintenance & Trust
Buy One Get One Free for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Buy One Get One Free for WooCommerce Alternatives
WooCommerce
woocommerce
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
CT Commerce Lite 🛒 | Fast & Flexible WordPress eCommerce Plugin
ctc-lite
CT Commerce Lite** is an ultra-lightweight, block-based eCommerce plugin for WordPress
Secudeal Payments for Ecommerce
secudeal-payments-for-ecommerce
Official WooCommerce Payment gateway for the SECUDEAL payment solution dedicated to marketplaces.
UNIVERSAM
universam-demo
Платформа для сайта и бизнеса «УНИВЕРСАМ» c CRM. Множество цен, любые программы лояльности. 1С, парсинг, SEO, рассылка, конструктор рассылок.
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Buy One Get One Free for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect Buy One Get One Free for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buy-one-get-one-free-for-woocommerce/assets/js/scripts.js/wp-content/plugins/buy-one-get-one-free-for-woocommerce/assets/css/styles.css/wp-content/plugins/buy-one-get-one-free-for-woocommerce/assets/js/frontend.js/wp-content/plugins/buy-one-get-one-free-for-woocommerce/assets/js/scripts.js/wp-content/plugins/buy-one-get-one-free-for-woocommerce/assets/js/frontend.jsHTML / DOM Fingerprints
svbogo-noticeSVBOGO_PLUGIN_SLUG