Promotion Products in Cart for WooCommerce Security & Risk Analysis

wordpress.org/plugins/promotion-products-in-cart-for-woocommerce

This plugin will give the option to the store owner to promote there products on the Cart Page.

10 active installs v1.0.0 PHP + WP 3.3+ Updated Aug 18, 2020
cartproductproduct-promotionproduct-promotion-on-cartproduct-promotion-on-cart-for-woocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Promotion Products in Cart for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Promotion Products in Cart for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "promotion-products-in-cart-for-woocommerce" v1.0.0 demonstrates a generally positive security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with exposed entry points significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions used, all SQL queries are prepared, and a high percentage of outputs are properly escaped. There are no indications of file operations or external HTTP requests, which are often vectors for vulnerabilities.

However, there are notable areas for concern. The complete lack of nonce checks and capability checks across any potential entry points is a significant weakness. While the static analysis reported zero entry points, this could be an oversight, or if the plugin legitimately has no user-facing interactions, it still leaves potential for exploitation if the plugin's functionality were ever expanded or triggered unintentionally. The taint analysis showing zero flows is also positive but could be due to the limited scope or complexity of the plugin's code. The absence of any recorded vulnerability history is a strong positive, suggesting a history of secure development.

In conclusion, while the current version appears to be free from known vulnerabilities and follows good practices like prepared statements and output escaping, the complete absence of authentication and authorization checks (nonces and capabilities) is a critical oversight. This leaves the plugin susceptible to potential privilege escalation or unauthorized actions if any code execution paths were to be discovered or introduced in future versions. The strengths lie in its minimal attack surface and adherence to safe coding practices for SQL and output handling, but the weakness in authentication is a notable risk.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Potentially large attack surface without auth
Vulnerabilities
None known

Promotion Products in Cart for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Promotion Products in Cart for WooCommerce Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Promotion Products in Cart for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
44 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped50 total outputs
Attack Surface

Promotion Products in Cart for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedincludes/class-promotion-product-cart.php:142
actionadmin_enqueue_scriptsincludes/class-promotion-product-cart.php:157
actionadmin_initincludes/class-promotion-product-cart.php:158
actionadmin_menuincludes/class-promotion-product-cart.php:159
actionwoocommerce_after_cart_tableincludes/class-promotion-product-cart.php:172
Maintenance & Trust

Promotion Products in Cart for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 18, 2020
PHP min version
Downloads877

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Promotion Products in Cart for WooCommerce Developer Profile

Aslam Shekh

3 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Promotion Products in Cart for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/promotion-products-in-cart-for-woocommerce/admin/js/promotion-product-cart-admin.js
Version Parameters
promotion-product-cart-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Promotion Products in Cart for WooCommerce