
Discontinued Products Security & Risk Analysis
wordpress.org/plugins/discontinued-productsEnables WooCommerce Discontinued Products.
Is Discontinued Products Safe to Use in 2026?
Generally Safe
Score 100/100Discontinued Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "discontinued-products" v2.0.8 plugin exhibits a generally good security posture based on the provided static analysis. The plugin has a very small attack surface, with only one shortcode, and crucially, no unprotected entry points like AJAX handlers or REST API routes. The code also shows a strong tendency towards proper output escaping, with 90% of outputs being sanitized. The presence of a nonce check, while only one, indicates some consideration for preventing CSRF attacks. The absence of file operations and external HTTP requests further reduces potential attack vectors.
However, there are areas of concern. The most significant is the use of raw SQL queries. With two SQL queries identified and 0% using prepared statements, this poses a substantial risk of SQL injection vulnerabilities. While taint analysis did not reveal any immediate unsanitized flows, the lack of prepared statements means that any user-supplied input that is incorporated into these queries without proper sanitization could be exploited. The lack of capability checks on the shortcode is also a weakness, as it implies that any authenticated user, regardless of their role, can potentially execute the shortcode's functionality.
Historically, the plugin has no recorded vulnerabilities, which is a very positive sign. This suggests either a well-written codebase or diligent maintenance. However, the lack of historical vulnerability data does not negate the risks identified in the current static analysis, particularly the raw SQL queries and the absence of capability checks.
Key Concerns
- SQL queries without prepared statements
- Missing capability checks on shortcode
Discontinued Products Security Vulnerabilities
Discontinued Products Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Discontinued Products Attack Surface
Shortcodes 1
WordPress Hooks 36
Maintenance & Trust
Discontinued Products Maintenance & Trust
Maintenance Signals
Community Trust
Discontinued Products Alternatives
Discontinued Products for WooCommerce
discontinued-product-for-woocommerce
Adds the ability to flag a product as discontinued to WooCommerce
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Mollie Payments for WooCommerce
mollie-payments-for-woocommerce
Accept all major payment methods in WooCommerce today. Credit cards, iDEAL and more! Fast, safe and intuitive.
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
Mercado Pago payments for WooCommerce
woocommerce-mercadopago
Offer to your clients the best experience in e-Commerce by using Mercado Pago as your payment method.
Discontinued Products Developer Profile
3 plugins · 500 total installs
How We Detect Discontinued Products
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/discontinued-products/assets/css/discontinued_product.cssdiscontinued_product.css?ver=2.0.8HTML / DOM Fingerprints
discontinued_product_tabdata-placeholder="Search for a product…"data-action="woocommerce_json_search_products_and_variations"[discontinued_products]