Global Coupons for WooCommerce Security & Risk Analysis

wordpress.org/plugins/global-coupons-for-woocommerce

Create smart, personalized WooCommerce coupons that appear automatically in each customer’s My Account page.

10 active installs v1.4.0 PHP + WP 5.0+ Updated Dec 8, 2025
coupon-rulescouponsdynamic-couponspersonalized-couponswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Global Coupons for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Global Coupons for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'global-coupons-for-woocommerce' plugin v1.4.0 exhibits a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities in its history is a positive indicator. The code demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks on its entry points.

However, a concern arises from the taint analysis, which identified one flow with unsanitized paths. While this flow was not categorized as critical or high severity, it represents a potential area where an attacker might be able to inject or manipulate data. Additionally, the output escaping is not entirely comprehensive, with 21% of outputs not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output without proper sanitization.

Overall, the plugin is well-maintained and appears to follow many security best practices. The limited attack surface and lack of historical vulnerabilities are strengths. The primary areas for improvement lie in thoroughly sanitizing the identified unsanitized path and ensuring all output is properly escaped to mitigate potential XSS risks.

Key Concerns

  • Flow with unsanitized path detected
  • Incomplete output escaping (21% not escaped)
Vulnerabilities
None known

Global Coupons for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Global Coupons for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
81 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

79% escaped102 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
global_coupons_admin_mainmenu (core\global-coupon-admin.php:67)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Global Coupons for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[my-account-global-coupons] core\global-coupon-my-account.php:148
WordPress Hooks 14
actionadmin_menucore\global-coupon-admin.php:3
actionadmin_initcore\global-coupon-admin.php:484
actioninitcore\global-coupon-my-account.php:155
filterquery_varscore\global-coupon-my-account.php:163
filterwoocommerce_account_menu_itemscore\global-coupon-my-account.php:171
actionwp_loadedcore\global-coupon-my-account.php:183
actionwoocommerce_account_my-global-coupons_endpointcore\global-coupon-my-account.php:185
filterwoocommerce_account_menu_itemscore\global-coupon-my-account.php:202
actionbefore_woocommerce_initglobal-coupons.php:24
actionadmin_noticesglobal-coupons.php:39
actionadmin_initglobal-coupons.php:47
actionadmin_initglobal-coupons.php:49
actionwp_enqueue_scriptsglobal-coupons.php:53
actionplugins_loadedglobal-coupons.php:86
Maintenance & Trust

Global Coupons for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Global Coupons for WooCommerce Developer Profile

Eyup Gulsen

2 plugins · 1K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
454 days
View full developer profile
Detection Fingerprints

How We Detect Global Coupons for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/global-coupons-for-woocommerce/css/global-coupons.css
Version Parameters
global-coupons-for-woocommerce/css/global-coupons.css?ver=

HTML / DOM Fingerprints

CSS Classes
customers
FAQ

Frequently Asked Questions about Global Coupons for WooCommerce