
Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce Security & Risk Analysis
wordpress.org/plugins/flexible-couponsFlexible PDF Coupons - Gift Cards & Vouchers for WooCommerce - plugin to design and sell PDF gift cards, vouchers, or coupons in your store.
Is Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "flexible-coupons" plugin v1.14.2 presents a mixed security posture. While it exhibits some good practices such as a moderate number of nonce and capability checks, its static analysis reveals significant concerns. The presence of several dangerous functions like `proc_open`, `shell_exec`, and `passthru` is a major red flag, indicating potential for remote code execution if exploited. Furthermore, a substantial portion of its output (72%) is not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of prepared statements for all SQL queries also introduces the possibility of SQL injection attacks.
The taint analysis, while reporting no critical or high severity flows, does indicate four flows with unsanitized paths. This, combined with the unprotected AJAX handlers and the inherent risks of dangerous functions, suggests that attackers could potentially leverage these weaknesses to manipulate plugin behavior or execute arbitrary code. The plugin's vulnerability history, showing one medium severity CVE related to XSS, reinforces the concern about improper input neutralization and suggests a pattern of past security weaknesses that require careful monitoring.
Overall, the plugin has a notable attack surface with three unprotected AJAX handlers, which is a direct entry point for potential abuse. The combination of unescaped output, lack of SQL sanitization, dangerous function usage, and unprotected entry points significantly elevates the risk profile. While it's positive that there are no currently unpatched CVEs and the vulnerability history is not extensive, the static analysis findings warrant significant caution and a strong recommendation for patching and enhanced security measures.
Key Concerns
- Unprotected AJAX handlers
- Dangerous functions (proc_open, shell_exec, passthru, unserialize)
- SQL queries without prepared statements
- Low percentage of properly escaped output
- Flows with unsanitized paths
- Medium severity vulnerability in history
- Bundled library (TCPDF)
Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Flexible PDF Coupons <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce Attack Surface
AJAX Handlers 7
WordPress Hooks 66
Maintenance & Trust
Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce Alternatives
gurado WebConnect – Gift Card & Voucher Shop for WordPress
gurado-webconnect
Sell gift cards, vouchers, and event tickets directly on your own website – no commissions, instant delivery, direct payout, and full design control.
KORTA
korta
Connect you WordPress page with KORTA.app to sell gift vouchers
WPTrivo Gift Cards Lite
wptrivo-gift-cards-lite
A lightweight WooCommerce plugin that allows you to sell digital gift cards, send them to recipients on a chosen date, and let customers select from a …
PW WooCommerce Gift Cards
pw-woocommerce-gift-cards
Sell gift cards to your WooCommerce store, in just a few minutes!
YITH WooCommerce Gift Cards
yith-woocommerce-gift-cards
The essential tool for selling gift cards in your store, increasing your conversion rate and attracting new customers.
Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce Developer Profile
23 plugins · 127K total installs
How We Detect Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flexible-coupons/assets/css/marketing.css/wp-content/plugins/flexible-coupons/assets/css/modal.css/wp-content/plugins/flexible-coupons/assets/js/modal.js/wp-content/plugins/flexible-coupons/assets/js/modal.js/wp-content/plugins/flexible-coupons/assets/js/two-weeks-notice.jsflexible-coupons/assets/css/marketing.css?ver=flexible-coupons/assets/css/modal.css?ver=flexible-coupons/assets/js/modal.js?ver=flexible_coupons-rate-notice?ver=HTML / DOM Fingerprints
sm-close-tempdata-type="date"