
Up-sell Trio for WooCommerce Security & Risk Analysis
wordpress.org/plugins/up-sell-trio-for-woocommerceMinimalist and high-efficiency plugin under 1,000 lines of code packed with WooCommerce up-sell features: Frequently Bought Together, Out-of-stock Alt …
Is Up-sell Trio for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Up-sell Trio for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'up-sell-trio-for-woocommerce' plugin v1.9.2 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and implementing a nonce check, which is a positive indicator of security awareness. The complete absence of known CVEs and historical vulnerabilities further reinforces this positive outlook, suggesting a stable and well-maintained codebase.
However, there are areas for improvement. A significant concern is the low percentage of properly escaped output (47%). This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if the remaining unescaped outputs handle user-supplied data or data from untrusted sources. While taint analysis found no issues, this could be due to the limited scope of the analysis or the specific nature of the data processed. The presence of a shortcode, while not inherently insecure, represents an entry point that requires careful handling of its parameters and output.
In conclusion, the plugin has a good foundation with secure database interactions and nonce protection. The primary weakness lies in the insufficient output escaping, which warrants attention to mitigate potential XSS risks. The lack of historical vulnerabilities is encouraging but should not lead to complacency, as unseen vulnerabilities can still exist.
Key Concerns
- Insufficient output escaping
Up-sell Trio for WooCommerce Security Vulnerabilities
Up-sell Trio for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Up-sell Trio for WooCommerce Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Up-sell Trio for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Up-sell Trio for WooCommerce Alternatives
UpsellWP – WooCommerce Upsell and Related Products Offers
checkout-upsell-and-order-bumps
Best WooCommerce Upsell plugin to create checkout upsells, cross-sells, order bumps and frequently bought together bundles to increase AOV.
Smart Related Products – AI-Inspired Recommendations for WooCommerce
ai-related-products
Show the right products to the right customers. A smart WooCommerce add-on for personalized product recommendations.
Leo Product Recommendations for WooCommerce
leo-product-recommendations
Boost WooCommerce sales with smart product recommendation popups on add to cart.
Easy Upsells, Related Products & Product Recommendations for WooCommerce
easy-upsells-for-woocommerce
Boost sales and increase average order value with WooCommerce upsells, related products, product recommendations, product addons, cross-sells.
Product Tagger
product-tagger
With this Plugin you can show all your wanted Products in the Sidebar with a Widget. To define the right Product use the Product-Tag like [woo_product …
Up-sell Trio for WooCommerce Developer Profile
3 plugins · 300 total installs
How We Detect Up-sell Trio for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/up-sell-trio-for-woocommerce/frequently-bought-together.js/wp-content/plugins/up-sell-trio-for-woocommerce/frequently-bought-together.jsup-sell-trio-for-woocommerce/ccom-upsell-trio.php?ver=HTML / DOM Fingerprints
ccom_fbt_self_idwc-block-components-checkboxwc-block-components-checkbox__inputwc-block-components-checkbox__markwc-block-components-checkbox__labeldata-priceccom_fbt[ccom_fbt][ccom_fbt cross_sells="yes"]