Coupons by country for WooCommerce Security & Risk Analysis

wordpress.org/plugins/coupons-by-country-for-woocommerce

Coupons by Country for WooCommerce lets admins restrict coupon use by country seamlessly integrating with WooCommerce for targeted promotions.

30 active installs v1.4 PHP 5.6+ WP 5.2+ Updated Feb 25, 2026
country-based-couponscoupon-plugin-for-woocommercecoupon-restrictions-by-countrycouponswoocommerce-coupons
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Coupons by country for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Coupons by country for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "coupons-by-country-for-woocommerce" plugin version 1.4 exhibits a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators. Furthermore, the plugin successfully utilizes prepared statements for its SQL queries, which is a critical security practice. The presence of a nonce check and a reasonably high percentage of properly escaped output suggest a developer mindful of common web vulnerabilities.

However, there are areas that warrant attention. The complete lack of capability checks, despite having an entry point with a nonce check, is a concern. While the static analysis reports no AJAX handlers or REST API routes, this could be an artifact of the analysis scope or a simplification. If there are any hidden entry points or if functionality is exposed without proper authorization checks beyond the single nonce, it presents a significant risk. The vulnerability history being completely clean is a positive sign, suggesting a well-maintained plugin or a lack of prior targeting, but it does not negate the potential risks identified in the code analysis.

In conclusion, the plugin demonstrates good development practices in many areas, particularly concerning SQL injection and general output sanitation. The primary weakness lies in the potential for authorization bypass if any functionality is exposed without robust capability checks, which is a critical aspect of WordPress security. The current analysis does not highlight any specific vulnerabilities, but the absence of capability checks across all entry points is a notable area for improvement and vigilance.

Key Concerns

  • No capability checks found
  • High percentage of unescaped output (25%)
Vulnerabilities
None known

Coupons by country for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Coupons by country for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
3 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped4 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<coupons-by-country-for-woocommerce> (coupons-by-country-for-woocommerce.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Coupons by country for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterwoocommerce_coupon_data_tabscoupons-by-country-for-woocommerce.php:29
actionwoocommerce_coupon_options_savecoupons-by-country-for-woocommerce.php:40
actionwoocommerce_coupon_data_panelscoupons-by-country-for-woocommerce.php:65
actionwoocommerce_before_checkout_formcoupons-by-country-for-woocommerce.php:72
filterwoocommerce_coupons_enabledcoupons-by-country-for-woocommerce.php:81
filterwoocommerce_coupon_is_validcoupons-by-country-for-woocommerce.php:95
Maintenance & Trust

Coupons by country for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 25, 2026
PHP min version5.6
Downloads2K

Community Trust

Rating60/100
Number of ratings2
Active installs30
Developer Profile

Coupons by country for WooCommerce Developer Profile

Dhrumil Kumbhani

5 plugins · 350 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Coupons by country for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
show_if_coupon
Data Attributes
id="coupon_country_data"name="coupon_country"id="coupon_country"nonce="coupon_country_nonce"
Shortcode Output
<div id="coupon_country_data" class="panel woocommerce_options_panel"><div class="options_group"><p class="form-field"><label for="coupon_country">Coupon Country</label>
FAQ

Frequently Asked Questions about Coupons by country for WooCommerce