
DeftCoders – Discount & Fee Rules for WooCommerce Security & Risk Analysis
wordpress.org/plugins/deftcoders-dynamic-pricing-conditional-feesAutomatically add fees and apply discounts in WooCommerce based on cart, payment method, user role, date, time, and location. No coupon codes needed.
Is DeftCoders – Discount & Fee Rules for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100DeftCoders – Discount & Fee Rules for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "deftcoders-dynamic-pricing-conditional-fees" plugin v1.0.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query preparation and output escaping, with 88% of SQL queries using prepared statements and 97% of outputs properly escaped. The absence of known CVEs and a clean vulnerability history are also positive indicators. However, a significant concern lies within its attack surface. With 11 AJAX handlers, 9 of which lack authentication checks, there is a substantial risk of unauthorized actions being performed. The taint analysis reveals 2 flows with unsanitized paths, although these are not categorized as critical or high severity, they still warrant attention as potential vectors for unexpected behavior or information disclosure.
The plugin's strengths are its adherence to secure coding practices for common web vulnerabilities like SQL injection and cross-site scripting (XSS) through prepared statements and output escaping. The lack of historical vulnerabilities suggests a generally stable codebase. Conversely, the primary weakness is the exposed AJAX endpoints, creating a broad attack surface that could be exploited if not properly secured at the application level by developers or end-users. The identified unsanitized paths, while not currently rated as high risk, indicate potential areas for further code review to ensure robustness against future vulnerabilities.
In conclusion, while the plugin is built on a foundation of secure coding principles for critical areas like database interaction and output handling, the significant number of unprotected AJAX endpoints presents a clear and present risk. The taint analysis, though not critical, highlights areas that could be improved. The absence of past vulnerabilities is encouraging, but the current attack surface requires immediate attention and mitigation strategies to ensure the security of WordPress sites using this plugin.
Key Concerns
- 9 unprotected AJAX handlers
- 2 flows with unsanitized paths
DeftCoders – Discount & Fee Rules for WooCommerce Security Vulnerabilities
DeftCoders – Discount & Fee Rules for WooCommerce Release Timeline
DeftCoders – Discount & Fee Rules for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
DeftCoders – Discount & Fee Rules for WooCommerce Attack Surface
AJAX Handlers 11
WordPress Hooks 21
Maintenance & Trust
DeftCoders – Discount & Fee Rules for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
DeftCoders – Discount & Fee Rules for WooCommerce Alternatives
Discount Rules for WooCommerce
woo-discount-rules
The discount plugin for WooCommerce helps you create bulk discount, quantity discount, storewide sale, dynamic pricing discount offers easily.
Advanced Dynamic Pricing and Discount Rules for WooCommerce
advanced-dynamic-pricing-for-woocommerce
The discount plugin for WooCommerce supports any dynamic pricing discount: bulk discount, role discount, storewide, bogo, gifts, cart discount
Conditional Discounts for WooCommerce – A simple yet complete woocommerce dynamic pricing plugin
woo-advanced-discounts
A powerful WooCommerce dynamic pricing plugin for bulk discounts, free gifts, BOGOs, customer role or groups based deals and much more.
Dynamic Pricing With Discount Rules for WooCommerce
aco-woo-dynamic-pricing
The Dynamic Pricing With Discount Rules plugin enables bulk discounts for WooCommerce products. Its simple design allows easy setup in minutes.
Dynamic Pricing and Discount Rules
discount-and-dynamic-pricing
Dynamic Pricing Plugin lets you create special discounts for your customers based on product and cart details.
DeftCoders – Discount & Fee Rules for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect DeftCoders – Discount & Fee Rules for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/deftcoders-dynamic-pricing-conditional-fees/assets/css/admin-style.css/wp-content/plugins/deftcoders-dynamic-pricing-conditional-fees/assets/js/admin-script.js/wp-content/plugins/deftcoders-dynamic-pricing-conditional-fees/assets/js/admin-script.jsdeftcoders-dynamic-pricing-conditional-fees/assets/css/admin-style.css?ver=deftcoders-dynamic-pricing-conditional-fees/assets/js/admin-script.js?ver=HTML / DOM Fingerprints
wcdpdr-admin-pagewcdpdr-rule-field<!-- WCDPDR START FIX: Single ABSPATH guard --><!-- FIX: Activation error notice lives in a persistent hook, not inside activate() --><!-- FIX: Show activation error notices via persistent transients (fires on next admin request) --><!-- Main plugin class -->+15 moredata-rule-iddata-field-namewcdpdr_admin_params