Magic Order Bump for WooCommerce Security & Risk Analysis

wordpress.org/plugins/magic-order-bump-for-woocommerce

Adds a beautiful, interactive order bump to the WooCommerce block checkout. One click adds a real product to the order.

0 active installs v1.0.1 PHP 8.0+ WP 6.0+ Updated Mar 26, 2026
checkoutcross-sellorder-bumpupsellwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Magic Order Bump for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Magic Order Bump for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The magic-order-bump-for-woocommerce plugin, version 1.0.1, exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, all SQL queries are properly prepared, and all output is correctly escaped. Furthermore, the plugin implements both nonce and capability checks on its two identified AJAX entry points, effectively securing its attack surface. There are no file operations or external HTTP requests, further minimizing potential risks.

The vulnerability history is also clean, with no known CVEs reported for this plugin. This, combined with the absence of critical or high-severity taint flows, suggests a well-developed and secure codebase. The plugin does not bundle any external libraries that could potentially introduce vulnerabilities.

In conclusion, based on the provided data, magic-order-bump-for-woocommerce v1.0.1 appears to be a secure plugin. Its adherence to best practices in handling user input, database interactions, and access control contributes to its strong security profile. The lack of past vulnerabilities reinforces this assessment. While no security issues are identified, ongoing vigilance and regular updates for any potential future threats are always recommended for any software.

Vulnerabilities
None known

Magic Order Bump for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Magic Order Bump for WooCommerce Release Timeline

v1.0.1Current
Code Analysis
Analyzed Apr 16, 2026

Magic Order Bump for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
61 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped61 total outputs
Attack Surface

Magic Order Bump for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_mobump_toggleincludes/frontend.php:19
noprivwp_ajax_mobump_toggleincludes/frontend.php:20
WordPress Hooks 10
actionadmin_menuincludes/admin.php:12
actionadmin_enqueue_scriptsincludes/admin.php:13
actionwp_enqueue_scriptsincludes/frontend.php:17
actionwp_footerincludes/frontend.php:18
actionbefore_woocommerce_initincludes/helpers.php:14
actionplugins_loadedincludes/helpers.php:15
actionadmin_noticesincludes/helpers.php:40
filterwoocommerce_get_cart_item_from_sessionincludes/helpers.php:229
actionwoocommerce_checkout_create_order_line_itemincludes/helpers.php:245
actionwoocommerce_before_calculate_totalsincludes/helpers.php:259
Maintenance & Trust

Magic Order Bump for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 26, 2026
PHP min version8.0
Downloads91

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Magic Order Bump for WooCommerce Developer Profile

magicsoft

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Magic Order Bump for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/magic-order-bump-for-woocommerce/assets/css/admin.css/wp-content/plugins/magic-order-bump-for-woocommerce/assets/js/admin.js
Version Parameters
magic-order-bump-for-woocommerce/assets/css/admin.css?ver=magic-order-bump-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
mobump-order-bump-wrapper
HTML Comments
<!-- Order Bump -->
Data Attributes
data-mobump-product-id
JS Globals
mobump_vars
FAQ

Frequently Asked Questions about Magic Order Bump for WooCommerce