FrequentlyBuy – Bought Together Upsells for WooCommerce Security & Risk Analysis

wordpress.org/plugins/frequentlybuy

Short Description: Add frequently bought together product bundles in WooCommerce to increase sales and order value.

0 active installs v1.0.1 PHP 7.4+ WP 6.5+ Updated Mar 26, 2026
bought-togetherfrequently-bought-togetherrelatedupsellswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FrequentlyBuy – Bought Together Upsells for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

FrequentlyBuy – Bought Together Upsells for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "frequentlybuy" plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history are positive indicators, suggesting the plugin has historically been developed with security in mind or has not yet been targeted. The code analysis reveals an exceptionally small attack surface with zero unprotected entry points, which is a significant strength. Furthermore, the plugin demonstrates good practices by using prepared statements for all SQL queries and properly escaping a very high percentage of its outputs. The presence of a nonce check and capability check indicates some awareness of authorization mechanisms.

However, the static analysis does reveal some potential areas for improvement. While the attack surface is small, the total absence of AJAX handlers, REST API routes, shortcodes, and cron events might be a consequence of the plugin's limited functionality. More importantly, the analysis shows 325 total outputs with only 98% properly escaped, leaving a small but present risk of cross-site scripting (XSS) vulnerabilities if these unescaped outputs are ever exposed to user-controlled data. The single nonce check and capability check are noted, but their placement and effectiveness are not detailed, leaving a minor concern about potential privilege escalation or unauthorized actions if not implemented correctly in all relevant contexts. The bundled Select2 library, while common, should be monitored for potential vulnerabilities in future audits.

In conclusion, "frequentlybuy" v1.0.1 appears to be a relatively secure plugin with a minimal attack surface and good coding practices for SQL and output handling. The lack of historical vulnerabilities is a strong point. The primary areas of concern are the small percentage of unescaped outputs and the potential implications of the limited number of security checks if they are not robustly implemented. Continued vigilance regarding the bundled library and any future expansion of the plugin's functionality is recommended.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

FrequentlyBuy – Bought Together Upsells for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

FrequentlyBuy – Bought Together Upsells for WooCommerce Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

FrequentlyBuy – Bought Together Upsells for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
319 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

98% escaped325 total outputs
Attack Surface

FrequentlyBuy – Bought Together Upsells for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuadmin/Admin.php:23
filterwp_enqueue_scriptsfrequentlybuy.php:66
actioninitinc/Hook.php:23
actionwp_enqueue_scriptsinc/Hook.php:24
filterfrequentlybuy_addons_listinc/Hook.php:25
actionadd_meta_boxesinc/Meta_Base.php:27
actionsave_postinc/Meta_Base.php:28
actionwoocommerce_before_add_to_cart_buttoninc/WooHook.php:22
actionwoocommerce_add_to_cartinc/WooHook.php:24
actionadmin_enqueue_scriptsmeta-fields/Fields_Maping.php:40
Maintenance & Trust

FrequentlyBuy – Bought Together Upsells for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 26, 2026
PHP min version7.4
Downloads193

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FrequentlyBuy – Bought Together Upsells for WooCommerce Developer Profile

themelooks

12 plugins · 2K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
20 days
View full developer profile
Detection Fingerprints

How We Detect FrequentlyBuy – Bought Together Upsells for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/frequentlybuy/assets/css/main.css/wp-content/plugins/frequentlybuy/meta-fields/assets/css/jquery-ui.css/wp-content/plugins/frequentlybuy/meta-fields/assets/css/select2.min.css/wp-content/plugins/frequentlybuy/meta-fields/assets/css/fields.css/wp-content/plugins/frequentlybuy/assets/js/main.js/wp-content/plugins/frequentlybuy/meta-fields/assets/js/wp-color-picker-alpha.js
Script Paths
/wp-content/plugins/frequentlybuy/assets/js/main.js
Version Parameters
frequentlybuy/assets/css/main.css?ver=frequentlybuy/meta-fields/assets/css/jquery-ui.css?ver=frequentlybuy/meta-fields/assets/css/select2.min.css?ver=frequentlybuy/meta-fields/assets/css/fields.css?ver=frequentlybuy/assets/js/main.js?ver=frequentlybuy/meta-fields/assets/js/wp-color-picker-alpha.js?ver=

HTML / DOM Fingerprints

JS Globals
frequentlybuyMainScript
FAQ

Frequently Asked Questions about FrequentlyBuy – Bought Together Upsells for WooCommerce