Black Friday and Cyber Monday Deals for WooCommerce Security & Risk Analysis

wordpress.org/plugins/pw-black-friday

All-in-one tool for Black Friday, Cyber Monday, and any other special sales event.

200 active installs v2.9 PHP 7.4+ WP 4.5+ Updated Mar 15, 2026
black-fridaybogoflash-salesaleswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Black Friday and Cyber Monday Deals for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Black Friday and Cyber Monday Deals for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 19d ago
Risk Assessment

The "pw-black-friday" plugin version 2.9 demonstrates a generally good security posture, with a notable absence of known vulnerabilities and a strong adherence to prepared statements for SQL queries. The analysis indicates a robust implementation of nonce checks for all identified AJAX handlers, which is a critical security measure. However, a significant concern arises from the static analysis, which reveals that a substantial percentage (43%) of output operations are not properly escaped. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if the data being output is user-controlled or derived from untrusted sources. The taint analysis also identified two flows with unsanitized paths, although these were not categorized as critical or high severity, they still represent potential weaknesses that warrant investigation.

The plugin's history of zero known CVEs, with no common vulnerability types recorded, is a positive indicator of its maintainers' efforts towards security. This suggests a proactive approach to patching and development. Despite the lack of critical vulnerabilities in the taint analysis and the strong history, the unescaped output and unsanitized paths present a moderate risk. Therefore, while the plugin is currently in a relatively secure state, addressing the output escaping and taint flow issues is crucial to further strengthen its security and prevent future potential exploits.

Key Concerns

  • High percentage of unescaped output
  • Unsanitized paths found in taint analysis
Vulnerabilities
None known

Black Friday and Cyber Monday Deals for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Black Friday and Cyber Monday Deals for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
67
88 escaped
Nonce Checks
6
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

57% escaped155 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<countdown> (templates\woocommerce\pw-black-friday\countdown.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Black Friday and Cyber Monday Deals for WooCommerce Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_pw-black-friday-save-eventpw-black-friday.php:118
authwp_ajax_pw-black-friday-save-countdownspw-black-friday.php:119
authwp_ajax_pw-black-friday-delete-eventpw-black-friday.php:120
authwp_ajax_pw-black-friday-save-dealpw-black-friday.php:121
authwp_ajax_pw-black-friday-delete-dealpw-black-friday.php:122
authwp_ajax_pw-black-friday-save-promopw-black-friday.php:123
WordPress Hooks 32
actionplugins_loadedpw-black-friday.php:76
actionwoocommerce_initpw-black-friday.php:77
actionbefore_woocommerce_initpw-black-friday.php:80
actioninitpw-black-friday.php:112
actionadmin_menupw-black-friday.php:116
actionadmin_enqueue_scriptspw-black-friday.php:117
filterwoocommerce_order_get_itemspw-black-friday.php:124
filterwoocommerce_product_is_on_salepw-black-friday.php:126
actionwoocommerce_shipping_free_shipping_is_availablepw-black-friday.php:127
filterwoocommerce_shipping_zone_shipping_methodspw-black-friday.php:128
filterwoocommerce_quantity_input_argspw-black-friday.php:129
filterwoocommerce_available_variationpw-black-friday.php:130
filterwoocommerce_add_to_cart_validationpw-black-friday.php:131
filterwoocommerce_update_cart_validationpw-black-friday.php:132
filterwoocommerce_variation_pricespw-black-friday.php:133
filterwoocommerce_get_price_htmlpw-black-friday.php:134
actionget_footerpw-black-friday.php:135
filterwoocommerce_shortcode_products_querypw-black-friday.php:136
filtershortcode_atts_productspw-black-friday.php:137
filterwoocommerce_get_shop_coupon_datapw-black-friday.php:140
actionwoocommerce_add_to_cartpw-black-friday.php:141
actionwoocommerce_check_cart_itemspw-black-friday.php:142
filterwoocommerce_coupon_messagepw-black-friday.php:143
filterwoocommerce_coupon_errorpw-black-friday.php:144
filterwoocommerce_coupon_is_validpw-black-friday.php:145
filterwoocommerce_cart_totals_coupon_labelpw-black-friday.php:146
filterwoocommerce_cart_totals_coupon_htmlpw-black-friday.php:147
actionwoocommerce_new_order_itempw-black-friday.php:150
actionwoocommerce_order_add_couponpw-black-friday.php:152
actionwoocommerce_cart_calculate_feespw-black-friday.php:156
actionwoocommerce_cart_contents_totalpw-black-friday.php:157
filterpwbf_to_default_currencypw-black-friday.php:175
Maintenance & Trust

Black Friday and Cyber Monday Deals for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version7.4
Downloads35K

Community Trust

Rating70/100
Number of ratings6
Active installs200
Developer Profile

Black Friday and Cyber Monday Deals for WooCommerce Developer Profile

pimwick

9 plugins · 43K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect Black Friday and Cyber Monday Deals for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pw-black-friday/pw-black-friday.css/wp-content/plugins/pw-black-friday/pw-black-friday.js/wp-content/plugins/pw-black-friday/assets/css/pw-black-friday.css/wp-content/plugins/pw-black-friday/assets/js/pw-black-friday.js/wp-content/plugins/pw-black-friday/assets/js/pw-black-friday-admin.js
Version Parameters
pw-black-friday/pw-black-friday.css?ver=pw-black-friday/pw-black-friday.js?ver=pw-black-friday/assets/css/pw-black-friday.css?ver=pw-black-friday/assets/js/pw-black-friday.js?ver=pw-black-friday/assets/js/pw-black-friday-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
pwbf-countdown-timerpwbf-deal-titlepwbf-deal-descriptionpwbf-promo-bannerpwbf-promo-titlepwbf-promo-content
Data Attributes
data-pwbf-countdowndata-pwbf-event-iddata-pwbf-deal-id
JS Globals
PWBF_Admin
FAQ

Frequently Asked Questions about Black Friday and Cyber Monday Deals for WooCommerce