Replace Percentage Badges Insted of Sales Security & Risk Analysis

wordpress.org/plugins/replace-sale-text-with-percentage

Description: This plugin will Replace "Sale" On every sales product with percentage.

10 active installs v1.1.0 PHP + WP 3.5.0+ Updated Sep 12, 2023
change-sale-text-with-percentageproduct-sales-percentagesale-text
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Replace Percentage Badges Insted of Sales Safe to Use in 2026?

Generally Safe

Score 85/100

Replace Percentage Badges Insted of Sales has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin "replace-sale-text-with-percentage" v1.1.0 exhibits a strong security posture regarding its attack surface and SQL query handling. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events means there are virtually no direct entry points for attackers to exploit. Furthermore, all SQL queries, if any existed, are confirmed to use prepared statements, which is an excellent practice for preventing SQL injection vulnerabilities. The plugin also shows no history of known vulnerabilities, including critical or high severity ones, suggesting a well-maintained and secure codebase over time.

However, a significant concern arises from the output escaping. With one total output analyzed and 0% properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered on the front-end or admin area without proper escaping can be manipulated by attackers to inject malicious scripts. The lack of nonces and capability checks, while not immediately problematic due to the limited attack surface, could become a weakness if the plugin's functionality were to expand or if new entry points were introduced in future versions without corresponding security checks.

In conclusion, the plugin is strong in its minimal attack surface and secure database interaction. Its vulnerability history is a positive indicator. The primary weakness and critical area for improvement is the complete lack of output escaping, which presents a tangible risk of XSS. The absence of nonces and capability checks on the (currently non-existent) entry points is a potential future risk but not an immediate exploit.

Key Concerns

  • 0% output escaping on outputs
Vulnerabilities
None known

Replace Percentage Badges Insted of Sales Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Replace Percentage Badges Insted of Sales Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Replace Percentage Badges Insted of Sales Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwoocommerce_sale_flashreplace-percentage-badges-insted-of-sales-text.php:11
Maintenance & Trust

Replace Percentage Badges Insted of Sales Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedSep 12, 2023
PHP min version
Downloads823

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Replace Percentage Badges Insted of Sales Alternatives

No alternatives data available yet.

Developer Profile

Replace Percentage Badges Insted of Sales Developer Profile

Asif Ali

7 plugins · 220 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Replace Percentage Badges Insted of Sales

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
replace-sale-text-with-percentage/replace-percentage-badges-insted-of-sales-text.php?ver=

HTML / DOM Fingerprints

CSS Classes
onsale
FAQ

Frequently Asked Questions about Replace Percentage Badges Insted of Sales