Simple Order Bump Security & Risk Analysis

wordpress.org/plugins/simple-order-bump

The \"Simple Order Bump\" plugin for WooCommerce allows merchants to offer additional products or \"order upgrade options\" on the …

10 active installs v1 PHP 7.0+ WP 5.6+ Updated Mar 24, 2023
order-bumporders-bumpupsellwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Order Bump Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Order Bump has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "simple-order-bump" v1 plugin exhibits a strong security posture based on the provided static analysis. The absence of SQL injection vulnerabilities, proper output escaping for the vast majority of outputs, and the presence of nonce and capability checks are positive indicators. The limited attack surface, particularly the lack of unprotected entry points, further contributes to its secure design. The plugin also has no recorded vulnerability history, suggesting a pattern of responsible development and maintenance. However, the analysis does not indicate any taint flows, which could mean either the plugin has no exploitable data flows or the taint analysis was not comprehensive enough to detect them. The use of a bundled library, Select2, while not inherently a risk, necessitates attention to its version and any potential known vulnerabilities it might carry.

Key Concerns

  • Bundled library (Select2)
Vulnerabilities
None known

Simple Order Bump Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Order Bump Release Timeline

v1.0
Code Analysis
Analyzed Mar 17, 2026

Simple Order Bump Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
60 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

97% escaped62 total outputs
Attack Surface

Simple Order Bump Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_add_product_to_cartclass.ajax-add-to-cart.php:7
noprivwp_ajax_add_product_to_cartclass.ajax-add-to-cart.php:8
WordPress Hooks 8
actionadmin_initclass.sob-settings.php:8
actionwoocommerce_after_checkout_billing_formclass.sob.php:9
actionwoocommerce_review_order_before_paymentclass.sob.php:11
actionwoocommerce_checkout_before_order_reviewclass.sob.php:13
actionadmin_menusimple-order-bump.php:43
actionwp_enqueue_scriptssimple-order-bump.php:53
actionadmin_enqueue_scriptssimple-order-bump.php:54
actionplugin_row_metasimple-order-bump.php:55
Maintenance & Trust

Simple Order Bump Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 24, 2023
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Simple Order Bump Developer Profile

marcomireles

3 plugins · 220 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Order Bump

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-order-bump/assets/css/frontend.css/wp-content/plugins/simple-order-bump/assets/css/backend.css/wp-content/plugins/simple-order-bump/vendor/css/select2.css/wp-content/plugins/simple-order-bump/vendor/js/frontend.js/wp-content/plugins/simple-order-bump/vendor/js/style.js/wp-content/plugins/simple-order-bump/vendor/js/select2.js
Version Parameters
simple-order-bump/assets/css/frontend.css?ver=simple-order-bump/assets/css/backend.css?ver=simple-order-bump/vendor/css/select2.css?ver=simple-order-bump/vendor/js/frontend.js?ver=simple-order-bump/vendor/js/style.js?ver=simple-order-bump/vendor/js/select2.js?ver=

HTML / DOM Fingerprints

CSS Classes
sob-order-bump-wrappersob-order-bump-titlesob-order-bump-descriptionsob-order-bump-pricesob-order-bump-add-to-cart-button
Data Attributes
data-product_iddata-quantitydata-variation_iddata-cart_iddata-bump_price
JS Globals
window.sob_add_to_cart_data
FAQ

Frequently Asked Questions about Simple Order Bump