
Checkout Upsell Order Bump for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-upsell-and-order-bumpBoost sales with Checkout Upsell Order Bump for WooCommerce! Offer product suggestions and enticing discounts directly on the checkout page.
Is Checkout Upsell Order Bump for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Checkout Upsell Order Bump for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-upsell-and-order-bump" plugin v2.0.4 exhibits a concerningly open attack surface due to multiple unprotected AJAX handlers. While the static analysis indicates good practices in SQL query handling, output escaping, and a lack of critical taint flows, the presence of three AJAX entry points without authentication checks represents a significant security weakness. This means that unauthenticated users could potentially trigger these AJAX actions, leading to unintended behavior or exploitation if the handler's logic is vulnerable. Fortunately, the plugin has no recorded vulnerabilities (CVEs) and a clean history, suggesting a generally mature and well-maintained codebase in other areas. However, the unprotected AJAX endpoints are a direct and exploitable risk that needs immediate attention. The plugin's strengths lie in its secure database interactions and output sanitization, but this is overshadowed by the readily available, unprotected entry points.
Key Concerns
- Unprotected AJAX handlers
- Large attack surface without auth
- Bundled library (Select2)
Checkout Upsell Order Bump for WooCommerce Security Vulnerabilities
Checkout Upsell Order Bump for WooCommerce Release Timeline
Checkout Upsell Order Bump for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Checkout Upsell Order Bump for WooCommerce Attack Surface
AJAX Handlers 3
WordPress Hooks 20
Maintenance & Trust
Checkout Upsell Order Bump for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Checkout Upsell Order Bump for WooCommerce Alternatives
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
wpfunnels
WPFunnels is a powerful funnel builder for WooCommerce that helps store owners create high-converting WooCommerce checkout pages, sales funnels, one-c …
Checkout Upsell Funnel for WooCommerce
checkout-upsell-funnel-for-woo
Elevate your checkout experience with enticing product suggestions and smart order bumps, all featuring attractive discounts
Magic Order Bump for WooCommerce
magic-order-bump-for-woocommerce
Adds a beautiful, interactive order bump to the WooCommerce block checkout. One click adds a real product to the order.
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce
cartflows
1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.
FunnelKit – Funnel Builder for WooCommerce Checkout
funnel-builder
Create high-converting WooCommerce checkout pages, WooCommerce thank you pages & sales funnels with the highest-rated WordPress funnel builder.
Checkout Upsell Order Bump for WooCommerce Developer Profile
9 plugins · 4K total installs
How We Detect Checkout Upsell Order Bump for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-upsell-and-order-bump/xswcusop-assets/xswcusop-css/swiper-bundle.min.css/wp-content/plugins/wc-upsell-and-order-bump/xswcusop-assets/xswcusop-js/swiper-bundle.min.js/wp-content/plugins/wc-upsell-and-order-bump/xswcusop-assets/xswcusop-css/xswcusop-stylefrondend.css/wp-content/plugins/wc-upsell-and-order-bump/xswcusop-assets/xswcusop-js/xswcusop-mainfrontend.js/wp-content/plugins/wc-upsell-and-order-bump/xswcusop-assets/xswcusop-js/swiper-bundle.min.js/wp-content/plugins/wc-upsell-and-order-bump/xswcusop-assets/xswcusop-js/xswcusop-mainfrontend.jswc-upsell-and-order-bump/xswcusop-assets/xswcusop-css/swiper-bundle.min.css?ver=wc-upsell-and-order-bump/xswcusop-assets/xswcusop-js/swiper-bundle.min.js?ver=wc-upsell-and-order-bump/xswcusop-assets/xswcusop-css/xswcusop-stylefrondend.css?ver=wc-upsell-and-order-bump/xswcusop-assets/xswcusop-js/xswcusop-mainfrontend.js?ver=HTML / DOM Fingerprints
xswcusop-upsell-popupxswcusop-order-bump-popupxswcusop-upsell-product-sliderxswcusop-order-bump-container<!-- xswcusop_upsellviewofproducts --><!-- xswcusop_orderbumpviewofproducts -->data-xswcusop-upsell-iddata-xswcusop-order-bump-idxswcusop_upselloptionsdataxswcusop_orderbumpdataxswcusop_mainfrontend