
Codup WooCommerce Dynamic Pricing Table View Security & Risk Analysis
wordpress.org/plugins/codup-woocommerce-dynamic-pricing-table-viewThis plugin extends WooCommerce Dynamic Pricing to display bulk pricing tables on WooCommerce product pages.
Is Codup WooCommerce Dynamic Pricing Table View Safe to Use in 2026?
Generally Safe
Score 85/100Codup WooCommerce Dynamic Pricing Table View has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "codup-woocommerce-dynamic-pricing-table-view" plugin version 1.2.1.5 exhibits a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and a high percentage of properly escaped output, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers without any authentication or capability checks, creating direct entry points for potential attackers. This lack of input validation on these AJAX endpoints is a major weakness.
The vulnerability history shows one known CVE, a medium severity Cross-site Scripting (XSS) vulnerability, which was last seen on April 27, 2022. Although this CVE is no longer unpatched, the presence of a past XSS vulnerability, coupled with the current lack of nonce checks and capability checks on its AJAX endpoints, suggests a recurring theme of insufficient input sanitization and authentication, especially concerning user-supplied data.
In conclusion, while the plugin avoids dangerous functions, raw SQL, and file operations, the unprotected AJAX handlers and the history of XSS vulnerabilities present a notable risk. The absence of nonces and capability checks on critical entry points is a significant security oversight that could be exploited if an attacker can trigger these AJAX actions. Robust authentication and input validation are crucial for mitigating these risks.
Key Concerns
- 2 unprotected AJAX handlers
- 0 Nonce checks
- 0 Capability checks
- 1 known medium severity CVE (past)
Codup WooCommerce Dynamic Pricing Table View Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Codup WooCommerce Dynamic Pricing Table View <= 1.2.1.4 - Stored Cross-Site Scripting
Codup WooCommerce Dynamic Pricing Table View Release Timeline
Codup WooCommerce Dynamic Pricing Table View Code Analysis
Output Escaping
Codup WooCommerce Dynamic Pricing Table View Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
Codup WooCommerce Dynamic Pricing Table View Maintenance & Trust
Maintenance Signals
Community Trust
Codup WooCommerce Dynamic Pricing Table View Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 120+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Codup WooCommerce Dynamic Pricing Table View Developer Profile
2 plugins · 120 total installs
How We Detect Codup WooCommerce Dynamic Pricing Table View
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codup-woocommerce-dynamic-pricing-table-view/assets/js/wc-pricing-table-admin-date-expiry-notification.jscodup-woocommerce-dynamic-pricing-table-view/assets/js/wc-pricing-table-admin-date-expiry-notification.js?ver=HTML / DOM Fingerprints
myAjax