
ingenidev Buy One Get One Free (BOGO) for WooCommerce Security & Risk Analysis
wordpress.org/plugins/ingenidev-bogo-offers-for-woocommerceNEW Plugin! The ultimate WooCommerce plugin for creating powerful Buy One Get One Free (BOGO) deals, dynamic pricing rules, quantity discounts to boos …
Is ingenidev Buy One Get One Free (BOGO) for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100ingenidev Buy One Get One Free (BOGO) for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ingenidev-bogo-offers-for-woocommerce" plugin v1.0.0 demonstrates a generally good security posture based on the provided static analysis. There are no identified dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests. The plugin also includes nonce and capability checks, indicating an effort to implement basic access control. The limited attack surface, with zero identified entry points like AJAX handlers, REST API routes, or shortcodes, further contributes to its perceived security.
However, a notable concern is the output escaping, where only 67% of outputs are properly escaped. This leaves a significant portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not sufficiently sanitized before being displayed. The lack of any recorded vulnerability history is positive, suggesting the developers have either maintained good security practices or the plugin has not been extensively tested or targeted. Despite the absence of critical taint flows or dangerous code signals, the incomplete output escaping presents a clear risk that warrants attention.
In conclusion, while the plugin avoids many common security pitfalls and has a minimal attack surface, the insufficient output escaping is a tangible weakness. This deficiency could be exploited to inject malicious scripts, impacting user sessions or site integrity. The plugin's strengths lie in its controlled entry points and secure data handling for queries, but the output escaping needs improvement to achieve a robust security profile.
Key Concerns
- Insufficient output escaping
ingenidev Buy One Get One Free (BOGO) for WooCommerce Security Vulnerabilities
ingenidev Buy One Get One Free (BOGO) for WooCommerce Release Timeline
ingenidev Buy One Get One Free (BOGO) for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
ingenidev Buy One Get One Free (BOGO) for WooCommerce Attack Surface
WordPress Hooks 16
Maintenance & Trust
ingenidev Buy One Get One Free (BOGO) for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ingenidev Buy One Get One Free (BOGO) for WooCommerce Alternatives
Buy one Get one Free – BOGO discount rule maker for WooCommerce
buy-one-get-one-free
Create buy one get one free or buy X get Y Free, BOGO discount rule of product in WooCommerce
Kns Dynamic Discounts for WooCommerce
kns-dynamic-discounts-for-woocommerce
A flexible WooCommerce discount plugin with BOGO campaigns, tiered quantity pricing, customer segmentation, usage limits, and scheduling.
Discount Rules for WooCommerce
woo-discount-rules
The discount plugin for WooCommerce helps you create bulk discount, quantity discount, storewide sale, dynamic pricing discount offers easily.
Smart Coupons For WooCommerce Coupons
wt-smart-coupons-for-woocommerce
Best WooCommerce coupons plugin to create advanced coupons and discount codes with auto-apply, BOGO, free shipping, giveaways, and discount rules.
Advanced Dynamic Pricing and Discount Rules for WooCommerce
advanced-dynamic-pricing-for-woocommerce
The discount plugin for WooCommerce supports any dynamic pricing discount: bulk discount, role discount, storewide, bogo, gifts, cart discount
ingenidev Buy One Get One Free (BOGO) for WooCommerce Developer Profile
14 plugins · 1K total installs
How We Detect ingenidev Buy One Get One Free (BOGO) for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ingenidev-bogo-offers-for-woocommerce/assets/css/ing-bogo-admin.cssingenidev-bogo-offers-for-woocommerce/assets/css/ing-bogo-admin.css?ver=HTML / DOM Fingerprints
ingenidev-bogo-offers-for-woocommercedata-product-iddata-variation-id