Up-sell Trio for WooCommerce Security & Risk Analysis

wordpress.org/plugins/up-sell-trio-for-woocommerce

Minimalist and high-efficiency plugin under 1,000 lines of code packed with WooCommerce up-sell features: Frequently Bought Together, Out-of-stock Alt …

0 active installs v1.9.2 PHP 7.4+ WP 6.0+ Updated Sep 25, 2025
out-of-stockproductsrecommended-productsupsellwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Up-sell Trio for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Up-sell Trio for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The 'up-sell-trio-for-woocommerce' plugin v1.9.2 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and implementing a nonce check, which is a positive indicator of security awareness. The complete absence of known CVEs and historical vulnerabilities further reinforces this positive outlook, suggesting a stable and well-maintained codebase.

However, there are areas for improvement. A significant concern is the low percentage of properly escaped output (47%). This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if the remaining unescaped outputs handle user-supplied data or data from untrusted sources. While taint analysis found no issues, this could be due to the limited scope of the analysis or the specific nature of the data processed. The presence of a shortcode, while not inherently insecure, represents an entry point that requires careful handling of its parameters and output.

In conclusion, the plugin has a good foundation with secure database interactions and nonce protection. The primary weakness lies in the insufficient output escaping, which warrants attention to mitigate potential XSS risks. The lack of historical vulnerabilities is encouraging but should not lead to complacency, as unseen vulnerabilities can still exist.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Up-sell Trio for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Up-sell Trio for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
9
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared5 total queries

Output Escaping

47% escaped17 total outputs
Attack Surface

Up-sell Trio for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ccom_fbt] class.frequently-bought-together.php:25
WordPress Hooks 11
actionbefore_woocommerce_initccom-upsell-trio.php:15
filterplugin_action_links_ccom-upsell-trio/ccom-upsell-trio.phpccom-upsell-trio.php:24
actionadmin_noticesclass.action-schedules.php:6
actionccom_fbt_builderclass.action-schedules.php:48
actionadmin_menuclass.fbt-report.php:4
actionwoocommerce_after_single_product_summaryclass.frequently-bought-together.php:8
actionwoocommerce_cart_loaded_from_sessionclass.myaccount-orders.php:3
actionwoocommerce_cart_calculate_feesclass.myaccount-orders.php:29
actionwoocommerce_before_template_partclass.out-of-stock-upsells.php:7
actiontemplate_redirectclass.submissions.php:7
actionwoocommerce_cart_calculate_feesclass.submissions.php:57
Maintenance & Trust

Up-sell Trio for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 25, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Up-sell Trio for WooCommerce Developer Profile

Sean Conklin

3 plugins · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Up-sell Trio for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/up-sell-trio-for-woocommerce/frequently-bought-together.js
Script Paths
/wp-content/plugins/up-sell-trio-for-woocommerce/frequently-bought-together.js
Version Parameters
up-sell-trio-for-woocommerce/ccom-upsell-trio.php?ver=

HTML / DOM Fingerprints

CSS Classes
ccom_fbt_self_idwc-block-components-checkboxwc-block-components-checkbox__inputwc-block-components-checkbox__markwc-block-components-checkbox__label
Data Attributes
data-price
JS Globals
ccom_fbt
Shortcode Output
[ccom_fbt][ccom_fbt cross_sells="yes"]
FAQ

Frequently Asked Questions about Up-sell Trio for WooCommerce