ELEX WooCommerce Discount Per Payment Method Security & Risk Analysis

wordpress.org/plugins/elex-discount-per-payment-method

It will be a pleasant little surprise for customers if you offer a discount based on the payment method they have chosen on the Checkout page.

1K active installs v1.3.1 PHP + WP 3.0.1+ Updated Feb 3, 2026
discountpaymentpayment-methodwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ELEX WooCommerce Discount Per Payment Method Safe to Use in 2026?

Generally Safe

Score 100/100

ELEX WooCommerce Discount Per Payment Method has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The elex-discount-per-payment-method v1.3.1 plugin exhibits a very strong security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface, and what little exists appears to be protected. The code signals also indicate good security practices, with no dangerous functions, all SQL queries using prepared statements, and a very high percentage of output escaping. The presence of nonce checks further reinforces secure handling of user interactions.

Further strengthening its security, there are no recorded vulnerabilities (CVEs) for this plugin. The taint analysis shows no flows with unsanitized paths, indicating a lack of common injection vulnerabilities like Cross-Site Scripting (XSS) or SQL Injection. This is further supported by the absence of raw SQL queries and file operations. The plugin also does not make external HTTP requests, mitigating risks associated with compromised external services.

Overall, this plugin appears to be well-developed and securely coded, with a clean history and a minimal attack surface. The lack of identified vulnerabilities and the robust internal security practices suggest a low risk of exploitation. The strengths lie in its limited attack vectors and meticulous code quality, while the lack of any identified weaknesses in the provided data makes it difficult to highlight specific areas for improvement. Its secure design is its primary strength.

Vulnerabilities
None known

ELEX WooCommerce Discount Per Payment Method Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ELEX WooCommerce Discount Per Payment Method Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
59 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped60 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
Elex_Woo_Discount_Per_Payment_Method_Save (elex-discount-per-payment-method.php:250)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ELEX WooCommerce Discount Per Payment Method Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_noticeselex-discount-per-payment-method.php:32
filterwoocommerce_settings_tabs_arrayelex-discount-per-payment-method.php:74
actionwoocommerce_before_calculate_totalselex-discount-per-payment-method.php:81
filterwoocommerce_checkout_cart_item_quantityelex-discount-per-payment-method.php:83
actionbefore_woocommerce_initelex-discount-per-payment-method.php:86
actionplugins_loadedelex-discount-per-payment-method.php:344
actionwp_enqueue_scriptsincludes\scripts.php:8
actionadmin_enqueue_scriptsincludes\scripts.php:9
actionadmin_noticesreview_and_troubleshoot_notify\review-and-troubleshoot-notify-class.php:20
actionadmin_initreview_and_troubleshoot_notify\review-and-troubleshoot-notify-class.php:21
Maintenance & Trust

ELEX WooCommerce Discount Per Payment Method Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 3, 2026
PHP min version
Downloads14K

Community Trust

Rating86/100
Number of ratings6
Active installs1K
Developer Profile

ELEX WooCommerce Discount Per Payment Method Developer Profile

ELEXtensions

22 plugins · 28K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
53 days
View full developer profile
Detection Fingerprints

How We Detect ELEX WooCommerce Discount Per Payment Method

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elex-discount-per-payment-method/review_and_troubleshoot_notify/review-and-troubleshoot-notify-class.php

HTML / DOM Fingerprints

CSS Classes
custom-product-text
JS Globals
Elex_Review_Components
FAQ

Frequently Asked Questions about ELEX WooCommerce Discount Per Payment Method