Lightning Deal for WooCommerce Security & Risk Analysis

wordpress.org/plugins/lightning-deal-for-woo

Lightning Deal for WooCommerce is an extension of WooCommerce that allows site admin to create time-bound discount offers for the customers.

0 active installs v1.3.0 PHP 7.0+ WP 5.0+ Updated Feb 9, 2025
discountlightning-dealtime-bound-dealswoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lightning Deal for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Lightning Deal for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "lightning-deal-for-woo" v1.3.0 exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices by implementing 100% of SQL queries with prepared statements and ensuring all output is properly escaped. The absence of file operations and external HTTP requests further reduces its attack surface. Furthermore, the lack of known vulnerabilities, including critical and high-severity ones, suggests a mature and well-maintained codebase.

Despite these strengths, there are a few areas that warrant attention. The complete absence of capability checks on the identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) presents a potential concern. While the current analysis indicates zero unprotected entry points, this could change if new functionalities are added without proper authorization checks. The presence of a single nonce check is also a positive sign, but its effectiveness is tied to the lack of identified vulnerabilities, which could be a coincidence.

In conclusion, the plugin appears to be secure for its current version and feature set, with robust handling of data and a clean vulnerability history. However, the reliance on an absence of unprotected entry points rather than explicit capability checks on all potential interaction points is a minor weakness that could be addressed proactively to further strengthen its security.

Key Concerns

  • No capability checks found on entry points
Vulnerabilities
None known

Lightning Deal for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Lightning Deal for WooCommerce Release Timeline

v1.3.0Current
v1.2.1
v1.2.0
v1.1.1
v1.1.0
Code Analysis
Analyzed Apr 16, 2026

Lightning Deal for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
0
84 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

Select2Freemius1.0

SQL Query Safety

100% prepared7 total queries

Output Escaping

100% escaped84 total outputs
Attack Surface

Lightning Deal for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 32
actioninitadmin/class-woold-post-type.php:47
actionadd_meta_boxesadmin/class-woold-post-type.php:48
actionsave_post_woold_dealadmin/class-woold-post-type.php:49
actionadmin_menuadmin/class-woold-settings.php:41
filterwpsf_register_settings_wooldadmin/settings.php:12
filterwoocommerce_add_to_cart_validationincludes/class-woold-order.php:23
filterwoocommerce_update_cart_validationincludes/class-woold-order.php:24
filterwoocommerce_before_checkout_processincludes/class-woold-order.php:25
filterwoocommerce_add_cart_item_dataincludes/class-woold-order.php:27
filterwoocommerce_store_api_validate_add_to_cartincludes/class-woold-order.php:29
filterwoocommerce_store_api_add_to_cart_dataincludes/class-woold-order.php:30
actionwoocommerce_checkout_create_order_line_itemincludes/class-woold-order.php:35
actionwoocommerce_before_calculate_totalsincludes/class-woold-order.php:37
actionwoocommerce_before_calculate_totalsincludes/class-woold-order.php:39
actiontrashed_postincludes/class-woold-order.php:40
actionwoocommerce_cart_totals_after_order_totalincludes/class-woold-order.php:42
actionwoocommerce_checkout_cart_item_quantityincludes/class-woold-order.php:43
actionwoocommerce_checkout_order_processedincludes/class-woold-order.php:45
actionwoocommerce_after_checkout_validationincludes/class-woold-order.php:47
actionwoocommerce_store_api_cart_errorsincludes/class-woold-order.php:48
actionwoocommerce_store_api_checkout_order_processedincludes/class-woold-order.php:50
actionwoocommerce_store_api_validate_cart_itemincludes/class-woold-order.php:51
actioninitincludes/class-woold-product.php:28
filterwoocommerce_get_price_htmlincludes/class-woold-product.php:50
filterwoocommerce_available_variationincludes/class-woold-product.php:51
actionwoocommerce_single_product_summaryincludes/class-woold-product.php:52
actionplugins_loadedincludes/class-woold.php:146
actionadmin_enqueue_scriptsincludes/class-woold.php:159
actionadmin_enqueue_scriptsincludes/class-woold.php:160
actionwp_enqueue_scriptsincludes/class-woold.php:173
actionwp_enqueue_scriptsincludes/class-woold.php:174
filterplugin_iconincludes/class-woold.php:201
Maintenance & Trust

Lightning Deal for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 9, 2025
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Lightning Deal for WooCommerce Developer Profile

IdeaWP

3 plugins · 20 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lightning Deal for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lightning-deal-for-woo/admin/css/woold-admin.css/wp-content/plugins/lightning-deal-for-woo/admin/css/select2.min.css/wp-content/plugins/lightning-deal-for-woo/public/vendor/jquery-datetimepicker/jquery.datetimepicker.min.css/wp-content/plugins/lightning-deal-for-woo/admin/js/woold-admin.js/wp-content/plugins/lightning-deal-for-woo/public/vendor/jquery-datetimepicker/jquery.datetimepicker.full.min.js/wp-content/plugins/lightning-deal-for-woo/admin/js/select2.min.js
Script Paths
/wp-content/plugins/lightning-deal-for-woo/admin/js/woold-admin.js/wp-content/plugins/lightning-deal-for-woo/public/vendor/jquery-datetimepicker/jquery.datetimepicker.full.min.js/wp-content/plugins/lightning-deal-for-woo/admin/js/select2.min.js
Version Parameters
lightning-deal-for-woo/admin/css/woold-admin.css?ver=lightning-deal-for-woo/admin/css/select2.min.css?ver=lightning-deal-for-woo/public/vendor/jquery-datetimepicker/jquery.datetimepicker.min.css?ver=lightning-deal-for-woo/admin/js/woold-admin.js?ver=lightning-deal-for-woo/public/vendor/jquery-datetimepicker/jquery.datetimepicker.full.min.js?ver=lightning-deal-for-woo/admin/js/select2.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
woold-pro-btnwoold-pro-btn__icon
Data Attributes
data-nonce="search-products"
JS Globals
venus_woold
FAQ

Frequently Asked Questions about Lightning Deal for WooCommerce