
Taxonomy/Term and Role based Discounts for WooCommerce Security & Risk Analysis
wordpress.org/plugins/taxonomy-discounts-woocommerceLet’s you configure discounts/pricing rules for products based on any product taxonomy terms and WordPress user roles
Is Taxonomy/Term and Role based Discounts for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Taxonomy/Term and Role based Discounts for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "taxonomy-discounts-woocommerce" plugin version 7.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong practices regarding database interactions, with 100% of its SQL queries utilizing prepared statements and an impressive 99% of its output being properly escaped. This significantly reduces the risk of common injection and XSS vulnerabilities related to data handling. The absence of file operations and external HTTP requests further contributes to a more secure codebase.
However, significant security concerns arise from the plugin's attack surface. All 5 identified AJAX handlers lack authentication checks, presenting a direct pathway for attackers to trigger plugin functionality without proper authorization. While the total number of flows analyzed in taint analysis is low (3), the presence of 2 flows with unsanitized paths, flagged as high severity, is a critical red flag. These could potentially lead to vulnerabilities if not addressed. The plugin also has a history of past vulnerabilities, including a medium severity one, indicating a pattern that warrants vigilance. While there are no currently unpatched CVEs, the presence of historical issues, coupled with the unprotected AJAX endpoints and high-severity taint flows, suggests a need for rigorous auditing and immediate attention to the identified vulnerabilities.
In conclusion, while the plugin excels in several secure coding practices like prepared statements and output escaping, the unprotected AJAX endpoints and high-severity unsanitized taint flows represent substantial security risks. The historical vulnerability data, though currently clear of unpatched issues, suggests a recurring need for security maintenance. Addressing the unprotected entry points and the identified taint flows should be the immediate priority to improve the plugin's overall security.
Key Concerns
- 5 AJAX handlers without auth checks
- 2 high severity unsanitized taint flows
- 1 medium CVE in vulnerability history
- 1 nonce check for 5 entry points
Taxonomy/Term and Role based Discounts for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Taxonomy/Term and Role based Discounts for WooCommerce <= 5.1 - Cross-Site Request Forgery to Settings Update
Taxonomy/Term and Role based Discounts for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Taxonomy/Term and Role based Discounts for WooCommerce Attack Surface
AJAX Handlers 5
WordPress Hooks 29
Maintenance & Trust
Taxonomy/Term and Role based Discounts for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Taxonomy/Term and Role based Discounts for WooCommerce Alternatives
Dynamic Pricing With Discount Rules for WooCommerce
aco-woo-dynamic-pricing
The Dynamic Pricing With Discount Rules plugin enables bulk discounts for WooCommerce products. Its simple design allows easy setup in minutes.
Account Engagement
pardot
Integrate Account Engagement with WordPress: easily track visitors, embed forms and dynamic content in pages and posts, or use the forms or dynamic co …
Bargain Bot for WooCommerce – Dynamic Pricing, Make your Offer
bargain
Shoppers Make Offer Now with a Bargaining bot for WooCommerce for Dynamic pricing. Increase Sales with woocommerce dynamic pricing
Multiple Sale Prices Scheduler
multiple-sale-prices-scheduler
Schedule multiple sale prices for WooCommerce products with different dates. Supports dynamic pricing for discounts and peak seasonal adjustments.
Scheduled Sales & Automatic Discounts for WooCommerce – Smart Cycle Discounts
smart-cycle-discounts
WooCommerce discount plugin for automated campaigns: dynamic pricing, BOGO, product bundles, tiered pricing, scheduled sales, and conflict safeguards.
Taxonomy/Term and Role based Discounts for WooCommerce Developer Profile
21 plugins · 27K total installs
How We Detect Taxonomy/Term and Role based Discounts for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/taxonomy-discounts-woocommerce/assets/css/backend.css/wp-content/plugins/taxonomy-discounts-woocommerce/assets/js/backend.js/wp-content/plugins/taxonomy-discounts-woocommerce/assets/js/frontend.js/wp-content/plugins/taxonomy-discounts-woocommerce/assets/css/backend.css?ver=/wp-content/plugins/taxonomy-discounts-woocommerce/assets/js/backend.js?ver=/wp-content/plugins/taxonomy-discounts-woocommerce/assets/js/frontend.js?ver=HTML / DOM Fingerprints
tdw-discount-rule-fieldtdw-rules-table<!-- HPOS Compatible -->/* If you're reading this you must know what you're doing ;-) Greetings from sunny Portugal! *//**
* Main class file for WooCommerce Taxonomy Discounts plugin
*
* Handles taxonomy and role-based discount functionality for WooCommerce products
*/data-tdw-rule-idWC_TDW_AJAX_URLtdw_discount_typestdw_enable_cache/wp-json/tdw/v1/rules