Vite Coupon Security & Risk Analysis

wordpress.org/plugins/vite-coupon

Easily manage coupons for your WooCommerce store with Vite Coupon. Streamline coupon creation, boost sales,and enjoy seamless integration with VitePOS

70 active installs v1.0.11 PHP 7.0+ WP 5.9+ Updated Dec 15, 2025
coupondiscountpromotionviteposwoocommerce
98
A · Safe
CVEs total1
Unpatched0
Last CVEApr 9, 2025
Safety Verdict

Is Vite Coupon Safe to Use in 2026?

Generally Safe

Score 98/100

Vite Coupon has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 9, 2025Updated 3mo ago
Risk Assessment

The "vite-coupon" plugin v1.0.11 exhibits a mixed security posture. On the positive side, static analysis reveals excellent practices in output escaping and a lack of dangerous functions, file operations, and external HTTP requests. The presence of nonce and capability checks, along with a seemingly small attack surface, are also encouraging signs. However, the presence of a single SQL query that is not using prepared statements is a notable concern, as it could be susceptible to SQL injection vulnerabilities if not handled with extreme care within the plugin's logic. Furthermore, the vulnerability history, specifically a past high-severity Cross-Site Request Forgery (CSRF) vulnerability, indicates a potential for recurring security weaknesses. While the current version shows no unpatched CVEs and the vulnerability was reported in the past, this history warrants ongoing vigilance. The lack of taint analysis results is either indicative of no complex data flows being analyzed or that the analyzed flows were deemed safe, but this aspect of the analysis could be more comprehensive.

Key Concerns

  • SQL queries not using prepared statements
  • History of high severity CSRF vulnerability
Vulnerabilities
1

Vite Coupon Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-32642high · 8.8Cross-Site Request Forgery (CSRF)

Vite Coupon <= 1.0.9 - Cross-Site Request Forgery to Remote Code Execution

Apr 9, 2025 Patched in 1.0.10 (104d)
Code Analysis
Analyzed Mar 16, 2026

Vite Coupon Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped10 total outputs
Attack Surface

Vite Coupon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionadmin_print_stylesvite_coupon_lite\core\class-vite-coupon-lite.php:51
actionadmin_enqueue_scriptsvite_coupon_lite\core\class-vite-coupon-lite.php:52
actionadmin_menuvite_coupon_lite\core\class-vite-coupon-lite.php:67
actionwoocommerce_after_register_post_typevite_coupon_lite\modules\class-vite-coupon-settings.php:37
actionadmin_menuvite_coupon_lite\modules\class-vite-coupon-settings.php:45
filterwoocommerce_coupon_is_validvite_coupon_lite\modules\class-vite-coupon-settings.php:47
filterwoocommerce_coupon_custom_discounts_arrayvite_coupon_lite\modules\class-vite-coupon-settings.php:48
filterwoocommerce_order_recalculate_coupons_coupon_objectvite_coupon_lite\modules\class-vite-coupon-settings.php:50
filterwoocommerce_coupon_errorvite_coupon_lite\modules\class-vite-coupon-settings.php:51
filterwoocommerce_coupon_messagevite_coupon_lite\modules\class-vite-coupon-settings.php:52
filterwoocommerce_coupon_discount_typesvite_coupon_lite\modules\class-vite-coupon-settings.php:53
filterwoocommerce_product_coupon_typesvite_coupon_lite\modules\class-vite-coupon-settings.php:54
filterappsbd/vite-coupon/filter/discount-typevite_coupon_lite\modules\class-vite-coupon-settings.php:56
filterappsbd/vite-coupon/filter/discount_price_typevite_coupon_lite\modules\class-vite-coupon-settings.php:57
filterappsbd/vite-coupon/filter/coupon-calculation/percent_uptovite_coupon_lite\modules\class-vite-coupon-settings.php:59
Maintenance & Trust

Vite Coupon Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 15, 2025
PHP min version7.0
Downloads3K

Community Trust

Rating90/100
Number of ratings2
Active installs70
Developer Profile

Vite Coupon Developer Profile

appsbd

7 plugins · 3K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
68 days
View full developer profile
Detection Fingerprints

How We Detect Vite Coupon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vite-coupon/assets/css/vite-coupon.css/wp-content/plugins/vite-coupon/assets/js/vite-coupon.js/wp-content/plugins/vite-coupon/assets/js/appsbd-admin-script.js
Script Paths
/wp-content/plugins/vite-coupon/assets/js/vite-coupon.js/wp-content/plugins/vite-coupon/assets/js/appsbd-admin-script.js
Version Parameters
vite-coupon/assets/css/vite-coupon.css?ver=vite-coupon/assets/js/vite-coupon.js?ver=vite-coupon/assets/js/appsbd-admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
vite-coupon-main-wrappervite-coupon-dashboardvite-coupon-coupon-form
HTML Comments
<!-- vite-coupon plugin starts --><!-- vite-coupon plugin ends -->
Data Attributes
data-vite-coupon-iddata-vite-coupon-code
JS Globals
window.viteCouponvar viteCoupon
REST Endpoints
/wp-json/vite-coupon/v1/coupons/wp-json/vite-coupon/v1/products/wp-json/vite-coupon/v1/categories
Shortcode Output
[vite_coupon_display]
FAQ

Frequently Asked Questions about Vite Coupon