PiWeb Products Frequently Bought Together for WooCommerce Security & Risk Analysis

wordpress.org/plugins/products-frequently-bought-together-for-woocommerce

Product frequently bought together plugin for WooCommerce helps you to increase your sales by showing frequently bought together products.

0 active installs v1.0.7 PHP 7.4+ WP 5.0+ Updated Mar 13, 2026
cross-sellfrequently-bought-togetherincrease-salesproduct-bundlesupsell
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PiWeb Products Frequently Bought Together for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

PiWeb Products Frequently Bought Together for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The plugin "products-frequently-bought-together-for-woocommerce" version 1.0.7 demonstrates several positive security practices, including the use of prepared statements for all SQL queries and proper output escaping for all outputs. The absence of any known vulnerabilities in its history is also a strong indicator of a well-maintained codebase. However, the static analysis reveals a significant concern regarding its attack surface. There are two AJAX handlers identified, and neither has authentication checks. This means any unauthenticated user could potentially interact with these handlers, posing a risk of unauthorized actions or information disclosure if these handlers are not intrinsically secured by other means not evident in the provided data.

The taint analysis did not reveal any flows with unsanitized paths, which is a positive sign that sensitive data is being handled securely within the analyzed code. The limited attack surface, while concerning due to the lack of authentication on AJAX handlers, is not excessively large. Despite the lack of direct evidence of exploitable vulnerabilities in the static analysis, the unprotected AJAX endpoints represent a clear security weakness. The plugin's strong adherence to other security best practices suggests a developer who understands secure coding, but the oversight on AJAX handler authentication is a notable area for improvement.

Key Concerns

  • 2 AJAX handlers without auth checks
Vulnerabilities
None known

PiWeb Products Frequently Bought Together for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PiWeb Products Frequently Bought Together for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
0
224 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared7 total queries

Output Escaping

100% escaped224 total outputs
Attack Surface
2 unprotected

PiWeb Products Frequently Bought Together for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_pisol_pfbt_block_related_productspublic\Cart.php:27
noprivwp_ajax_pisol_pfbt_block_related_productspublic\Cart.php:29
WordPress Hooks 19
actionpisol_custom_field_order_analysis_buttonadmin\Basic_Option.php:19
actionadmin_menuadmin\Menu.php:23
actionadmin_initadmin\Option.php:28
actionadmin_initadmin\Option.php:29
actionwoocommerce_order_status_changedadmin\Order_Processor.php:28
actionadmin_post_pisol_pfbt_start_order_analysisadmin\Order_Processor.php:30
actionadmin_post_pisol_pfbt_stop_order_analysisadmin\Order_Processor.php:32
actionpisol_pfbt_process_orders_batch_hookadmin\Order_Processor.php:34
filtercron_schedulesadmin\Order_Processor.php:36
actionadmin_noticesadmin\review.php:108
actionadmin_noticesproducts-frequently-bought-together-for-woocommerce.php:25
actionbefore_woocommerce_initproducts-frequently-bought-together-for-woocommerce.php:47
actionwp_enqueue_scriptspublic\Cart.php:21
actionwoocommerce_blocks_enqueue_cart_block_scripts_beforepublic\Cart.php:22
actionwc_ajax_pisol_pfbt_related_productspublic\Cart.php:23
actionwc_ajax_pisol_pfbt_block_related_productspublic\Cart.php:24
filterwoocommerce_cart_item_classpublic\Cart.php:31
actionwp_enqueue_scriptspublic\Checkout.php:19
actionwc_ajax_pisol_pfbt_checkout_related_productspublic\Checkout.php:20

Scheduled Events 2

pisol_pfbt_process_orders_batch_hook
pisol_pfbt_process_orders_batch_hook
Maintenance & Trust

PiWeb Products Frequently Bought Together for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.4
Downloads286

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PiWeb Products Frequently Bought Together for WooCommerce Developer Profile

PI Web Solution

30 plugins · 93K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
235 days
View full developer profile
Detection Fingerprints

How We Detect PiWeb Products Frequently Bought Together for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/products-frequently-bought-together-for-woocommerce/assets/css/frontend.css/wp-content/plugins/products-frequently-bought-together-for-woocommerce/assets/js/frontend.js
Script Paths
/wp-content/plugins/products-frequently-bought-together-for-woocommerce/assets/js/frontend.js
Version Parameters
products-frequently-bought-together-for-woocommerce/assets/css/frontend.css?ver=products-frequently-bought-together-for-woocommerce/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
pisol-pfbt-frontend-wrapperpisol-pfbt-product-wrapperpisol-pfbt-add-to-cart-button
HTML Comments
PIWeb Product Frequently Bought Together
Data Attributes
data-product-iddata-post-iddata-pfbt-product
JS Globals
pisol_pfbt_frontend_params
FAQ

Frequently Asked Questions about PiWeb Products Frequently Bought Together for WooCommerce