Promotion for Woo – Promo manager with Widgets, Badges and Blocks Security & Risk Analysis

wordpress.org/plugins/tyresaddict-promo

Improve products promotion in your shop with badges, product pages blocks, easily styled Elementor widget. Manage it together to increase sales

0 active installs v1.2.3 PHP 7.4+ WP 6.3+ Updated Unknown
adspromotionshopstorewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Promotion for Woo – Promo manager with Widgets, Badges and Blocks Safe to Use in 2026?

Generally Safe

Score 100/100

Promotion for Woo – Promo manager with Widgets, Badges and Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "tyresaddict-promo" v1.2.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The single capability check, while present, might be a point of concern if it's the sole protection for any sensitive operations.

While the static analysis revealed no dangerous functions, unsanitized paths in taint flows, or external HTTP requests, the limited attack surface (zero identified entry points) means that complex vulnerabilities are less likely to be exploitable. The plugin's vulnerability history is completely clean, with no recorded CVEs, indicating a history of secure development or effective patching. However, the presence of file operations without clear context in the analysis could be a minor concern if not handled securely. The lack of nonce checks on any potential entry points, if any exist that were not identified as such, would also be a weakness.

Overall, the plugin appears to be developed with security in mind, with a strong emphasis on secure coding practices for database interactions and output handling. The absence of any historical vulnerabilities further reinforces this. The primary areas for potential improvement or scrutiny would be the exact implementation of the file operations and ensuring that any implicit entry points are adequately protected with capability checks and nonces.

Key Concerns

  • Zero nonce checks identified
  • File operations present without context
Vulnerabilities
None known

Promotion for Woo – Promo manager with Widgets, Badges and Blocks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Promotion for Woo – Promo manager with Widgets, Badges and Blocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
101 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped107 total outputs
Attack Surface

Promotion for Woo – Promo manager with Widgets, Badges and Blocks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
filterwoocommerce_cart_item_nameincludes\FeatureCart.php:19
filterrwmb_meta_boxesincludes\FeatureMetabox.php:22
actioninitincludes\FeaturePostType.php:22
actionwoocommerce_before_shop_loop_item_titleincludes\FeatureProductCard.php:19
actionwoocommerce_single_product_summaryincludes\FeatureProductPage.php:24
filterthe_contentincludes\FeaturePromoPost.php:20
actionelementor/widgets/registerincludes\FeatureWidgets.php:27
actionelementor/elements/categories_registeredincludes\FeatureWidgets.php:35
actionadmin_menuincludes\PageOptions.php:24
actionadmin_initincludes\PageOptions.php:25
actionadmin_enqueue_scriptsincludes\Plugin.php:102
actionadmin_enqueue_scriptsincludes\Plugin.php:103
actionwp_enqueue_scriptsincludes\Plugin.php:127
actionwp_enqueue_scriptsincludes\Plugin.php:128
actionwidgets_initincludes\WidgetPromos.php:57
actionadmin_noticesincludes\Woo.php:330
actionplugins_loadedtyresaddict-promo.php:73
Maintenance & Trust

Promotion for Woo – Promo manager with Widgets, Badges and Blocks Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads219

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Promotion for Woo – Promo manager with Widgets, Badges and Blocks Developer Profile

TyresAddict

5 plugins · 370 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Promotion for Woo – Promo manager with Widgets, Badges and Blocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tyresaddict-promo/assets/css/admin.css/wp-content/plugins/tyresaddict-promo/assets/css/backend.css/wp-content/plugins/tyresaddict-promo/assets/css/frontend.css/wp-content/plugins/tyresaddict-promo/assets/js/admin.js/wp-content/plugins/tyresaddict-promo/assets/js/backend.js/wp-content/plugins/tyresaddict-promo/assets/js/frontend.js
Version Parameters
tyresaddict-promo/assets/css/admin.css?ver=tyresaddict-promo/assets/css/backend.css?ver=tyresaddict-promo/assets/css/frontend.css?ver=tyresaddict-promo/assets/js/admin.js?ver=tyresaddict-promo/assets/js/backend.js?ver=tyresaddict-promo/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
elementor-tyresaddict-promos-storyp-sectionp-titlep-cardp-badgebc-caption
Data Attributes
data-elementor-iddata-elementor-type
JS Globals
window.tyresAddictPromo
FAQ

Frequently Asked Questions about Promotion for Woo – Promo manager with Widgets, Badges and Blocks