Sitewide Discount for WooCommerce: Apply Discount to All Products Security & Risk Analysis

wordpress.org/plugins/global-shop-discount-for-woocommerce

Add global shop discount to all WooCommerce products. Beautifully.

700 active installs v2.2.4 PHP + WP 4.4+ Updated Sep 12, 2025
discountecommerceglobal-shop-discountwoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 19, 2025
Safety Verdict

Is Sitewide Discount for WooCommerce: Apply Discount to All Products Safe to Use in 2026?

Generally Safe

Score 99/100

Sitewide Discount for WooCommerce: Apply Discount to All Products has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 19, 2025Updated 6mo ago
Risk Assessment

The plugin 'global-shop-discount-for-woocommerce' v2.2.4 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, properly escaped output, and the use of prepared statements for SQL queries are positive indicators. Furthermore, the lack of external HTTP requests and file operations reduces potential attack vectors. However, there are some areas of concern, particularly the complete absence of nonce checks and capability checks. This could leave the plugin vulnerable to CSRF attacks or privilege escalation if certain functionalities are exposed through its entry points without proper authorization verification.

The plugin's vulnerability history shows one known CVE, which is reportedly patched. The common vulnerability type, Cross-Site Scripting, in the past suggests that improper input sanitization could be a recurring issue if not diligently addressed. While the current static analysis did not reveal any taint flows, the historical pattern warrants caution, and thorough testing of all user-supplied inputs is recommended.

In conclusion, the plugin demonstrates good development practices in many areas. The lack of obvious critical flaws in the current code analysis is encouraging. Nevertheless, the absence of nonce and capability checks represents a significant weakness that needs attention. The historical XSS vulnerability also suggests a need for continued vigilance in input validation and output sanitization to ensure robust security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Past XSS vulnerability history
Vulnerabilities
1

Sitewide Discount for WooCommerce: Apply Discount to All Products Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48248medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Sitewide Discount for WooCommerce: Apply Discount to All Products <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 19, 2025 Patched in 2.2.2 (10d)
Code Analysis
Analyzed Mar 16, 2026

Sitewide Discount for WooCommerce: Apply Discount to All Products Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

Sitewide Discount for WooCommerce: Apply Discount to All Products Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[alg_wc_gsd_products] includes\class-alg-wc-global-shop-discount-shortcodes.php:24
WordPress Hooks 10
actionplugins_loadedglobal-shop-discount-for-woocommerce.php:58
actionalg_wc_global_shop_discount_settings_savedincludes\class-alg-wc-global-shop-discount-tools.php:24
actioninitincludes\class-alg-wc-global-shop-discount.php:78
actionbefore_woocommerce_initincludes\class-alg-wc-global-shop-discount.php:81
actioninitincludes\class-alg-wc-global-shop-discount.php:168
actioninitincludes\class-alg-wc-global-shop-discount.php:171
filterwoocommerce_get_settings_pagesincludes\class-alg-wc-global-shop-discount.php:174
actionadmin_initincludes\class-alg-wc-global-shop-discount.php:178
actionadmin_footerincludes\settings\class-alg-wc-global-shop-discount-settings-group.php:277
filterwoocommerce_get_sections_alg_wc_global_shop_discountincludes\settings\class-alg-wc-global-shop-discount-settings-section.php:40
Maintenance & Trust

Sitewide Discount for WooCommerce: Apply Discount to All Products Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 12, 2025
PHP min version
Downloads18K

Community Trust

Rating100/100
Number of ratings4
Active installs700
Developer Profile

Sitewide Discount for WooCommerce: Apply Discount to All Products Developer Profile

WPFactory

63 plugins · 136K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
98 days
View full developer profile
Detection Fingerprints

How We Detect Sitewide Discount for WooCommerce: Apply Discount to All Products

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/global-shop-discount-for-woocommerce/assets/css/frontend.min.css/wp-content/plugins/global-shop-discount-for-woocommerce/assets/js/frontend.min.js
Script Paths
/wp-content/plugins/global-shop-discount-for-woocommerce/assets/js/frontend.min.js
Version Parameters
global-shop-discount-for-woocommerce/assets/css/frontend.min.css?ver=global-shop-discount-for-woocommerce/assets/js/frontend.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
alg-wc-gsd-products-shortcode
Data Attributes
alg_wc_gsd_products
JS Globals
alg_wc_global_shop_discount_frontend_params
Shortcode Output
[alg_wc_gsd_products]
FAQ

Frequently Asked Questions about Sitewide Discount for WooCommerce: Apply Discount to All Products