
Taxonomy/Term and Role-based Discounts for WooCommerce Security & Risk Analysis
wordpress.org/plugins/taxonomy-discounts-woocommerceAutomatically apply WooCommerce discounts/pricing rules based on product category, tag, attribute, custom taxonomy, and user role — no coupons needed
Is Taxonomy/Term and Role-based Discounts for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Taxonomy/Term and Role-based Discounts for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "taxonomy-discounts-woocommerce" plugin version 7.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong practices regarding database interactions, with 100% of its SQL queries utilizing prepared statements and an impressive 99% of its output being properly escaped. This significantly reduces the risk of common injection and XSS vulnerabilities related to data handling. The absence of file operations and external HTTP requests further contributes to a more secure codebase.
However, significant security concerns arise from the plugin's attack surface. All 5 identified AJAX handlers lack authentication checks, presenting a direct pathway for attackers to trigger plugin functionality without proper authorization. While the total number of flows analyzed in taint analysis is low (3), the presence of 2 flows with unsanitized paths, flagged as high severity, is a critical red flag. These could potentially lead to vulnerabilities if not addressed. The plugin also has a history of past vulnerabilities, including a medium severity one, indicating a pattern that warrants vigilance. While there are no currently unpatched CVEs, the presence of historical issues, coupled with the unprotected AJAX endpoints and high-severity taint flows, suggests a need for rigorous auditing and immediate attention to the identified vulnerabilities.
In conclusion, while the plugin excels in several secure coding practices like prepared statements and output escaping, the unprotected AJAX endpoints and high-severity unsanitized taint flows represent substantial security risks. The historical vulnerability data, though currently clear of unpatched issues, suggests a recurring need for security maintenance. Addressing the unprotected entry points and the identified taint flows should be the immediate priority to improve the plugin's overall security.
Key Concerns
- 5 AJAX handlers without auth checks
- 2 high severity unsanitized taint flows
- 1 medium CVE in vulnerability history
- 1 nonce check for 5 entry points
Taxonomy/Term and Role-based Discounts for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Taxonomy/Term and Role based Discounts for WooCommerce <= 5.1 - Cross-Site Request Forgery to Settings Update
Taxonomy/Term and Role-based Discounts for WooCommerce Release Timeline
Taxonomy/Term and Role-based Discounts for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Taxonomy/Term and Role-based Discounts for WooCommerce Attack Surface
AJAX Handlers 5
WordPress Hooks 29
Maintenance & Trust
Taxonomy/Term and Role-based Discounts for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Taxonomy/Term and Role-based Discounts for WooCommerce Alternatives
Conditional Discounts for WooCommerce – A simple yet complete woocommerce dynamic pricing plugin
woo-advanced-discounts
A powerful WooCommerce dynamic pricing plugin for bulk discounts, free gifts, BOGOs, customer role or groups based deals and much more.
Simple Discount Rules for Woocommerce
woo-product-category-discount
Simple Discount Rules for Woocommerce allows administrator to add and remove discount to products based on Category.
Dynamic Pricing and Discount Rules for WooCommerce
woo-conditional-discount-rules-for-checkout
Conditional Discount Rules For WooCommerce Checkout Plugin will help you to create and manage complex discount rules based on your requirement.
PiWeb Conditional Discount / Bulk discounts for WooCommerce
conditional-discount-rule-for-woocommerce
Discount woocommerce plugin / Bulk discounts for woocommerce / dynamic pricing rule like product discount, product category discounts etc..
Discount Rules and Dynamic Pricing for WooCommerce
easy-woocommerce-discounts
WooCommerce discount plugin, pricing and discounts, category discount, smart coupon, quantity discount, bulk discount, shipping method, storewide.
Taxonomy/Term and Role-based Discounts for WooCommerce Developer Profile
9 plugins · 12K total installs
How We Detect Taxonomy/Term and Role-based Discounts for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/taxonomy-discounts-woocommerce/assets/css/backend.css/wp-content/plugins/taxonomy-discounts-woocommerce/assets/js/backend.js/wp-content/plugins/taxonomy-discounts-woocommerce/assets/js/frontend.js/wp-content/plugins/taxonomy-discounts-woocommerce/assets/css/backend.css?ver=/wp-content/plugins/taxonomy-discounts-woocommerce/assets/js/backend.js?ver=/wp-content/plugins/taxonomy-discounts-woocommerce/assets/js/frontend.js?ver=HTML / DOM Fingerprints
tdw-discount-rule-fieldtdw-rules-table<!-- HPOS Compatible -->/* If you're reading this you must know what you're doing ;-) Greetings from sunny Portugal! *//**
* Main class file for WooCommerce Taxonomy Discounts plugin
*
* Handles taxonomy and role-based discount functionality for WooCommerce products
*/data-tdw-rule-idWC_TDW_AJAX_URLtdw_discount_typestdw_enable_cache/wp-json/tdw/v1/rules