Codecorun – Coupon Discount Rules Security & Risk Analysis

wordpress.org/plugins/codecorun-coupon-discount-rules

A coupon plugin that will allow you to set single or multiple rules with "AND" or "OR(Full Version)" conditional operator.

0 active installs v1.3.1 PHP 7.0+ WP 4.7+ Updated Jan 27, 2023
auto-discountscoupondiscount-rulesdiscountsrules
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Codecorun – Coupon Discount Rules Safe to Use in 2026?

Generally Safe

Score 85/100

Codecorun – Coupon Discount Rules has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "codecorun-coupon-discount-rules" plugin v1.3.1 exhibits a generally good security posture based on the provided static analysis. The plugin has no known vulnerabilities in its history and demonstrates several positive security practices. Notably, it utilizes prepared statements for all SQL queries, implements nonce checks on its AJAX handlers, and has a limited attack surface with all entry points seemingly protected by capability checks or nonces. There are no critical or high severity taint analysis findings, and dangerous functions are absent. However, a significant concern is the relatively low percentage (56%) of properly escaped output. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed to users. While the plugin currently has no reported CVEs, this output escaping issue is a common vector for such vulnerabilities and warrants attention.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

Codecorun – Coupon Discount Rules Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Codecorun – Coupon Discount Rules Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
18 escaped
Nonce Checks
4
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

56% escaped32 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
wcdr_save_settings (admin\includes\codecorun-cdr-admin-class.php:351)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Codecorun – Coupon Discount Rules Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_wcdr_product_list_optionsadmin\includes\codecorun-cdr-admin-class.php:30
authwp_ajax_wcdr_category_list_optionsadmin\includes\codecorun-cdr-admin-class.php:31
authwp_ajax_wcdr_role_list_optionsadmin\includes\codecorun-cdr-admin-class.php:32
authwp_ajax_wcdr_save_settingsadmin\includes\codecorun-cdr-admin-class.php:39

Shortcodes 1

[codecorun_wcdr_applied_codes] includes\codecorun-cdr-main-class.php:67
WordPress Hooks 12
filterwoocommerce_coupon_data_tabsadmin\includes\codecorun-cdr-admin-class.php:27
filterwoocommerce_coupon_data_panelsadmin\includes\codecorun-cdr-admin-class.php:28
actionadmin_enqueue_scriptsadmin\includes\codecorun-cdr-admin-class.php:29
actionsave_post_shop_couponadmin\includes\codecorun-cdr-admin-class.php:34
actionadmin_menuadmin\includes\codecorun-cdr-admin-class.php:36
actioninitcodecorun-cdr-plugin.php:24
actionplugins_loadedcodecorun-cdr-plugin.php:54
actiontemplate_redirectincludes\codecorun-cdr-main-class.php:61
actiontemplate_redirectincludes\codecorun-cdr-main-class.php:62
actionwp_footerincludes\codecorun-cdr-main-class.php:70
actionwp_enqueue_scriptsincludes\codecorun-cdr-main-class.php:714
actionwp_footerincludes\codecorun-cdr-main-class.php:720
Maintenance & Trust

Codecorun – Coupon Discount Rules Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJan 27, 2023
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Codecorun – Coupon Discount Rules Developer Profile

codelad

3 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Codecorun – Coupon Discount Rules

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/codecorun-coupon-discount-rules/admin/assets/codemirror.css/wp-content/plugins/codecorun-coupon-discount-rules/admin/assets/codemirror.js/wp-content/plugins/codecorun-coupon-discount-rules/admin/assets/settings.js/wp-content/plugins/codecorun-coupon-discount-rules/admin/assets/admin.css/wp-content/plugins/codecorun-coupon-discount-rules/admin/assets/admin.js
Script Paths
/wp-content/plugins/codecorun-coupon-discount-rules/admin/assets/codemirror.js/wp-content/plugins/codecorun-coupon-discount-rules/admin/assets/settings.js/wp-content/plugins/codecorun-coupon-discount-rules/admin/assets/admin.js
Version Parameters
codecorun-coupon-discount-rules/admin/assets/codemirror.css?ver=codecorun-coupon-discount-rules/admin/assets/codemirror.js?ver=codecorun-coupon-discount-rules/admin/assets/settings.js?ver=codecorun-coupon-discount-rules/admin/assets/admin.css?ver=codecorun-coupon-discount-rules/admin/assets/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wcdr_discount_rules
Data Attributes
data-nonce="wcdr-nonce-admin"
JS Globals
wcdrAjaxwcdr_label_factorycodecorun_is_upgraded
REST Endpoints
/wp-json/wp/v2/posts/wp-json/wc/v3/products/wp-json/wc/v3/products/categories
FAQ

Frequently Asked Questions about Codecorun – Coupon Discount Rules