
Promotion for Woo – Promo manager with Widgets, Badges and Blocks Security & Risk Analysis
wordpress.org/plugins/tyresaddict-promoImprove products promotion in your shop with badges, product pages blocks, easily styled Elementor widget. Manage it together to increase sales
Is Promotion for Woo – Promo manager with Widgets, Badges and Blocks Safe to Use in 2026?
Generally Safe
Score 100/100Promotion for Woo – Promo manager with Widgets, Badges and Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tyresaddict-promo" v1.2.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The single capability check, while present, might be a point of concern if it's the sole protection for any sensitive operations.
While the static analysis revealed no dangerous functions, unsanitized paths in taint flows, or external HTTP requests, the limited attack surface (zero identified entry points) means that complex vulnerabilities are less likely to be exploitable. The plugin's vulnerability history is completely clean, with no recorded CVEs, indicating a history of secure development or effective patching. However, the presence of file operations without clear context in the analysis could be a minor concern if not handled securely. The lack of nonce checks on any potential entry points, if any exist that were not identified as such, would also be a weakness.
Overall, the plugin appears to be developed with security in mind, with a strong emphasis on secure coding practices for database interactions and output handling. The absence of any historical vulnerabilities further reinforces this. The primary areas for potential improvement or scrutiny would be the exact implementation of the file operations and ensuring that any implicit entry points are adequately protected with capability checks and nonces.
Key Concerns
- Zero nonce checks identified
- File operations present without context
Promotion for Woo – Promo manager with Widgets, Badges and Blocks Security Vulnerabilities
Promotion for Woo – Promo manager with Widgets, Badges and Blocks Code Analysis
Output Escaping
Promotion for Woo – Promo manager with Widgets, Badges and Blocks Attack Surface
WordPress Hooks 17
Maintenance & Trust
Promotion for Woo – Promo manager with Widgets, Badges and Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Promotion for Woo – Promo manager with Widgets, Badges and Blocks Alternatives
External Product New Tab for WooCommerce
wc-external-product-new-tab
This plugin sets all external / affiliate product buy now links on a WooCommerce site to open in a new web browser tab.
Invoice Payment Gateway for WooCommerce
wc-invoice-gateway
The Invoice Payment Gateway for WooCommerce plugin adds an Invoice Payment Gateway feature to the WooCommerce plugin for B2B transactions when instant …
Premium Packages – Sell Digital Products Securely
wpdm-premium-packages
Premium Packages is a free, full-featured WordPress eCommerce plugin to sell digital products easily and securely.
Recently Viewed Product for WooCommerce
recently-viewed-products-for-woocommerce
Recently Viewed Products for WooCommerce Listing page, you can easily add recently viewed product section by activate the plugin.
Cargus
cargus
Use Cargus delivery methods to ship and deliver your orders.
Promotion for Woo – Promo manager with Widgets, Badges and Blocks Developer Profile
5 plugins · 370 total installs
How We Detect Promotion for Woo – Promo manager with Widgets, Badges and Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tyresaddict-promo/assets/css/admin.css/wp-content/plugins/tyresaddict-promo/assets/css/backend.css/wp-content/plugins/tyresaddict-promo/assets/css/frontend.css/wp-content/plugins/tyresaddict-promo/assets/js/admin.js/wp-content/plugins/tyresaddict-promo/assets/js/backend.js/wp-content/plugins/tyresaddict-promo/assets/js/frontend.jstyresaddict-promo/assets/css/admin.css?ver=tyresaddict-promo/assets/css/backend.css?ver=tyresaddict-promo/assets/css/frontend.css?ver=tyresaddict-promo/assets/js/admin.js?ver=tyresaddict-promo/assets/js/backend.js?ver=tyresaddict-promo/assets/js/frontend.js?ver=HTML / DOM Fingerprints
elementor-tyresaddict-promos-storyp-sectionp-titlep-cardp-badgebc-captiondata-elementor-iddata-elementor-typewindow.tyresAddictPromo