
DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce Security & Risk Analysis
wordpress.org/plugins/discountkitCreate flexible WooCommerce discount rules with percentage discounts, fixed discounts, and bulk pricing options.
Is DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "discountkit" v1.0.1 plugin exhibits a generally good security posture in several key areas. It demonstrates a strong commitment to secure coding practices by utilizing prepared statements for all its SQL queries and ensuring all output is properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a more secure foundation. The lack of any recorded historical vulnerabilities or CVEs is also a positive indicator, suggesting a well-maintained and potentially secure codebase.
However, the plugin does present some notable security concerns. The presence of 3 REST API routes without permission callbacks represents a significant attack surface that could potentially be exploited by unauthenticated users. Furthermore, the complete absence of nonce checks on any of its entry points is a critical oversight. Nonce checks are a fundamental WordPress security mechanism designed to prevent Cross-Site Request Forgery (CSRF) attacks. While no critical taint flows were detected, the potential for exploiting the unprotected REST API routes is real.
In conclusion, "discountkit" v1.0.1 has strengths in its data handling and output sanitization. Nonetheless, the lack of permission callbacks on REST API endpoints and the complete omission of nonce checks are significant weaknesses that expose the plugin to potential exploitation. Addressing these issues should be a high priority to improve the overall security of the plugin.
Key Concerns
- REST API routes without permission callbacks
- Missing nonce checks on all entry points
DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce Security Vulnerabilities
DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce Release Timeline
DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce Attack Surface
REST API Routes 8
WordPress Hooks 25
Maintenance & Trust
DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce Alternatives
Dynamic Pricing With Discount Rules for WooCommerce
aco-woo-dynamic-pricing
The Dynamic Pricing With Discount Rules plugin enables bulk discounts for WooCommerce products. Its simple design allows easy setup in minutes.
Conditional Discounts for WooCommerce – A simple yet complete woocommerce dynamic pricing plugin
woo-advanced-discounts
A powerful WooCommerce dynamic pricing plugin for bulk discounts, free gifts, BOGOs, customer role or groups based deals and much more.
Dynamic Pricing and Discount Rules
discount-and-dynamic-pricing
Dynamic Pricing Plugin lets you create special discounts for your customers based on product and cart details.
Offermative – WooCommerce Discount Rules, Upsells & BOGO Powered by AI
offermative-discount-pricing-related-products-upsell-funnels-for-woocommerce
Grow revenue and AOV with targeted and automated WooCommerce discount rules, upsells, cross-sells, order bumps, and dynamic pricing offers.
Dynamic Pricing & Discount Rules for WooCommerce
wpulse-pricing-rules-for-woocommerce
Create dynamic pricing and discount rules for WooCommerce — tiered bulk pricing, BOGO, role-based pricing, cart promotions, free shipping, and free gi …
DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce Developer Profile
6 plugins · 10 total installs
How We Detect DiscountKit – Discount Rules, Bulk Pricing & Dynamic Pricing for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/discountkit/assets/css/frontend.css/wp-content/plugins/discountkit/assets/css/admin-app.css/wp-content/plugins/discountkit/assets/js/admin-clean.jsdiscountkit/assets/css/frontend.css?ver=discountkit/assets/css/admin-app.css?ver=discountkit/assets/js/admin-clean.js?ver=HTML / DOM Fingerprints
DiscountKitObj/wp-json/discountkit/v1/rules/wp-json/discountkit/v1/rules/\d+/wp-json/discountkit/v1/products/wp-json/discountkit/v1/categories/wp-json/discountkit/v1/rules/\d+/duplicate/wp-json/discountkit/v1/customers/wp-json/discountkit/v1/settings/wp-json/discountkit/v1/settings/reset