
WPC Frequently Bought Together for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-bought-togetherWPC Frequently Bought Together helps you increase your sales with personalized product recommendations.
Is WPC Frequently Bought Together for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100WPC Frequently Bought Together for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "woo-bought-together" plugin v7.7.7 demonstrates a mixed security posture. On the positive side, it has a substantial number of nonce and capability checks, and all SQL queries utilize prepared statements, indicating good practices in these areas. The absence of raw SQL queries and file operations is also a strength. However, the presence of the "unserialize" function is a notable concern, as it can be a vector for remote code execution if user-supplied data is directly unserialized without proper sanitization. While the taint analysis did not reveal critical or high severity unsanitized paths, the fact that two flows with unsanitized paths were found warrants attention, especially in conjunction with the use of "unserialize".
The plugin's vulnerability history shows two medium severity CVEs, both related to missing authorization. While there are currently no unpatched vulnerabilities, the pattern of past authorization issues suggests a recurring theme that needs continuous vigilance. The most recent vulnerability being on August 16, 2024, indicates that even recent versions have had exploitable flaws. In conclusion, while the plugin employs several security best practices, the potential risks associated with "unserialize" and the historical pattern of authorization vulnerabilities represent areas that require careful monitoring and potentially further hardening.
Key Concerns
- Dangerous function 'unserialize' used
- Flows with unsanitized paths found
- Medium severity CVEs in history
WPC Frequently Bought Together for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WPC Frequently Bought Together for WooCommerce <= 7.1.9 - Missing Authorization
WPC Frequently Bought Together for WooCommerce <= 7.0.3 - Missing Authorization
WPC Frequently Bought Together for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WPC Frequently Bought Together for WooCommerce Attack Surface
AJAX Handlers 13
Shortcodes 2
WordPress Hooks 71
Maintenance & Trust
WPC Frequently Bought Together for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WPC Frequently Bought Together for WooCommerce Alternatives
Carousel Upsells and Related Product for Woocommerce
carousel-upsells-and-related-product-for-woocommerce
The plugin replaces the standard related and upsells products on carousel slider using a script glide.js that does not depend on the jquery, which muc …
WPC Custom Related Products for WooCommerce
wpc-custom-related-products
WPC Custom Related Products allows you to choose custom related products for each product.
WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce
wpc-smart-linked-products
WPC Smart Linked Products plugin simplifies managing related, upsells, and cross-sells products in bulk with custom rules and mixed combinations.
Mighty Frequently Bought Together for WooCommerce
mighty-frequently-bought-together
Increase your product sales by recommending them to buy together with other relevant products on your WooCommerce Store.
WPC Smart Quick View for WooCommerce
woo-smart-quick-view
WPC Smart Quick View allows users to get a quick look at products without opening the product page.
WPC Frequently Bought Together for WooCommerce Developer Profile
71 plugins · 441K total installs
How We Detect WPC Frequently Bought Together for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-bought-together/assets/css/blocks.css/wp-content/plugins/woo-bought-together/assets/js/blocks.js/wp-content/plugins/woo-bought-together/assets/css/woobt.css/wp-content/plugins/woo-bought-together/assets/js/woobt.js/wp-content/plugins/woo-bought-together/assets/js/wpc-smart-quantity.js/wp-content/plugins/woo-bought-together/assets/js/wpc-smart-shortcode.js/wp-content/plugins/woo-bought-together/assets/js/blocks.js/wp-content/plugins/woo-bought-together/assets/js/woobt.js/wp-content/plugins/woo-bought-together/assets/js/wpc-smart-quantity.js/wp-content/plugins/woo-bought-together/assets/js/wpc-smart-shortcode.jswoo-bought-together/assets/css/blocks.css?ver=woo-bought-together/assets/js/blocks.js?ver=woo-bought-together/assets/css/woobt.css?ver=woo-bought-together/assets/js/woobt.js?ver=woo-bought-together/assets/js/wpc-smart-quantity.js?ver=woo-bought-together/assets/js/wpc-smart-shortcode.js?ver=HTML / DOM Fingerprints
woobt-itemswoobt-main-wrapwoobt-add-to-cartwoobt-main-productwoobt-product-itemdata-woobt_iddata-product_iddata-woobt_groupwoobt_paramswpc_smart_quantity_paramswpc_smart_shortcode_params[bought_together][wpc_smart_shortcode]