C4D WooCommerce Product Bundles Security & Risk Analysis

wordpress.org/plugins/c4d-woo-bundle

C4D Woocommerce Product Bundle enables the efficient creation of a variety of product promotion bundles, powerful and ease-of-use to increase conversi …

60 active installs v1.1.2 PHP + WP 4.0.0+ Updated Aug 20, 2019
bundlebundlesproductproduct-bundlewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is C4D WooCommerce Product Bundles Safe to Use in 2026?

Generally Safe

Score 85/100

C4D WooCommerce Product Bundles has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The c4d-woo-bundle plugin version 1.1.2 exhibits a mixed security posture. While it demonstrates good practices by not utilizing dangerous functions, having no file operations, and using prepared statements for all SQL queries, it suffers from significant weaknesses in its attack surface management. The presence of two AJAX handlers without authentication checks is a major concern, opening potential avenues for unauthorized actions if these handlers are accessible and exploitable. The lack of nonce checks on these AJAX endpoints further exacerbates this risk, as it bypasses a crucial layer of defense against Cross-Site Request Forgery (CSRF) attacks.

The code analysis also reveals a substantial percentage of improperly escaped output, with only 44% of the 81 outputs being properly escaped. This indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the website through user-manipulated input displayed on the frontend. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting a history of relative security. However, this historical absence does not negate the current, evident risks identified in the static analysis. The plugin's strengths lie in its database interaction and lack of harmful functions, but the unprotected entry points and output escaping issues present immediate threats that require attention.

Key Concerns

  • AJAX handlers without auth checks
  • Output escaping: 44% proper
  • Nonce checks: 0
Vulnerabilities
None known

C4D WooCommerce Product Bundles Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

C4D WooCommerce Product Bundles Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
36 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

44% escaped81 total outputs
Attack Surface
2 unprotected

C4D WooCommerce Product Bundles Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_c4d_woo_bundle_add_to_cartincludes\frontend.php:8
noprivwp_ajax_c4d_woo_bundle_add_to_cartincludes\frontend.php:9

Shortcodes 1

[c4d_woo_bundle] includes\frontend.php:28
WordPress Hooks 26
actionadmin_initincludes\datas.php:2
actionadmin_enqueue_scriptsincludes\default.php:2
actionwp_enqueue_scriptsincludes\default.php:3
actionadmin_enqueue_scriptsincludes\default.php:4
actionc4d-plugin-manager-sectionincludes\default.php:5
filterplugin_row_metaincludes\default.php:6
actionplugins_loadedincludes\default.php:7
actionwoocommerce_before_shop_loop_item_titleincludes\frontend.php:3
filterwoocommerce_loop_add_to_cart_linkincludes\frontend.php:4
actionwoocommerce_single_product_summaryincludes\frontend.php:7
actionwoocommerce_before_calculate_totalsincludes\frontend.php:10
filterwoocommerce_widget_cart_item_quantityincludes\frontend.php:11
filterwoocommerce_widget_cart_item_quantityincludes\frontend.php:12
actionwoocommerce_after_cart_item_nameincludes\frontend.php:13
filterwoocommerce_cart_item_nameincludes\frontend.php:16
filterwoocommerce_checkout_cart_item_quantityincludes\frontend.php:17
filterwoocommerce_order_item_nameincludes\frontend.php:20
filterwoocommerce_order_item_quantity_htmlincludes\frontend.php:21
actionwoocommerce_add_order_item_metaincludes\frontend.php:22
actionwoocommerce_order_item_meta_endincludes\frontend.php:23
actionwoocommerce_after_order_itemmetaincludes\frontend.php:24
actionwoocommerce_single_product_summaryincludes\frontend.php:49
actionmanage_product_posts_custom_columnincludes\products.php:2
actionwoocommerce_product_write_panel_tabsincludes\tab.php:3
actionwoocommerce_product_data_panelsincludes\tab.php:4
actionwoocommerce_admin_process_product_objectincludes\tab.php:5
Maintenance & Trust

C4D WooCommerce Product Bundles Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedAug 20, 2019
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings5
Active installs60
Developer Profile

C4D WooCommerce Product Bundles Developer Profile

coffee4dev

18 plugins · 400 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect C4D WooCommerce Product Bundles

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/c4d-woo-bundle/assets/default.min.js/wp-content/plugins/c4d-woo-bundle/assets/default.js/wp-content/plugins/c4d-woo-bundle/assets/default.css/wp-content/plugins/c4d-woo-bundle/assets/admin.min.js/wp-content/plugins/c4d-woo-bundle/assets/admin.js/wp-content/plugins/c4d-woo-bundle/assets/admin.css
Script Paths
/wp-content/plugins/c4d-woo-bundle/assets/default.min.js/wp-content/plugins/c4d-woo-bundle/assets/default.js/wp-content/plugins/c4d-woo-bundle/assets/admin.min.js/wp-content/plugins/c4d-woo-bundle/assets/admin.js

HTML / DOM Fingerprints

CSS Classes
c4d-woo-bundle-load-more-activec4d-woo-bundle-load-more-c4d-woo-bundle-columns-c4d-woo-bundle-titlec4d-woo-bundle-description
Data Attributes
c4d-woo-bundle-prefix-classc4d-woo-bundle-load-morec4d-woo-bundle-columnsc4d-woo-bundle-discount-user-role-guestc4d-woo-bundle-discount-user-role-c4d-woo-bundle-discount+5 more
JS Globals
c4d_plugin_manager
FAQ

Frequently Asked Questions about C4D WooCommerce Product Bundles