Category Discounts for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-category-discount

Category Discounts plugin allows you to manage discounts for your WooCommerce store in an intelligent yet simple ways.

30 active installs v1.0.8 PHP + WP 4.6+ Updated Apr 9, 2023
category-discounts-for-woocommercewoocommercewoocommerce-category-discountswoocommerce-discount
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Category Discounts for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Category Discounts for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "woo-category-discount" v1.0.8 plugin exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities, uses prepared statements for all SQL queries, and avoids dangerous functions and external HTTP requests. However, significant concerns arise from the static analysis. A notable weakness is the presence of an AJAX handler without any authentication checks, exposing a direct attack vector. Furthermore, a substantial portion (52%) of output operations are not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved. The lack of nonce checks on the exposed AJAX endpoint is also a critical omission.

The absence of any vulnerability history suggests the plugin may have been overlooked or has historically been secure, but this does not negate the immediate risks identified in the code analysis. The direct, unprotected entry point via AJAX and the unescaped output represent tangible security gaps that require immediate attention. While the plugin demonstrates good practices in areas like SQL handling and avoiding dangerous functions, these strengths are overshadowed by the identified attack surface and output escaping issues. A balanced conclusion would be that the plugin has potential for secure operation, but the current version contains critical, addressable security flaws.

Key Concerns

  • Unprotected AJAX handler
  • Insufficient output escaping
  • Missing nonce checks
Vulnerabilities
None known

Category Discounts for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Category Discounts for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
25 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

48% escaped52 total outputs
Attack Surface
1 unprotected

Category Discounts for WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wcd_add_disc_catincludes\admin\class-woo-cat-disc-admin.php:178
WordPress Hooks 12
actionwoocommerce_product_write_panel_tabsincludes\admin\class-woo-cat-disc-admin.php:169
actionwoocommerce_product_data_panelsincludes\admin\class-woo-cat-disc-admin.php:172
actionwoocommerce_process_product_metaincludes\admin\class-woo-cat-disc-admin.php:175
filterwoocommerce_get_price_htmlincludes\class-woo-cat-disc-public.php:250
filterwoocommerce_get_item_dataincludes\class-woo-cat-disc-public.php:253
actionwoocommerce_before_calculate_totalsincludes\class-woo-cat-disc-public.php:256
actionwoocommerce_checkout_create_order_line_itemincludes\class-woo-cat-disc-public.php:259
filterwoocommerce_available_variationincludes\class-woo-cat-disc-public.php:262
filterwoocommerce_product_is_on_saleincludes\class-woo-cat-disc-public.php:265
actionadmin_enqueue_scriptsincludes\class-woo-cat-disc-scripts.php:137
actionadmin_enqueue_scriptsincludes\class-woo-cat-disc-scripts.php:140
actionplugins_loadedwildprog-woo-cat-discount.php:130
Maintenance & Trust

Category Discounts for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 9, 2023
PHP min version
Downloads4K

Community Trust

Rating60/100
Number of ratings4
Active installs30
Developer Profile

Category Discounts for WooCommerce Developer Profile

wildprogrammers

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Category Discounts for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-category-discount/includes/js/woo-cat-disc-taxonomy-scripts.js/wp-content/plugins/woo-category-discount/includes/js/woo-cat-disc-product-scripts.js/wp-content/plugins/woo-category-discount/includes/js/woo-cat-disc-settings-scripts.js
Script Paths
/wp-content/plugins/woo-category-discount/includes/js/woo-cat-disc-taxonomy-scripts.js/wp-content/plugins/woo-category-discount/includes/js/woo-cat-disc-product-scripts.js/wp-content/plugins/woo-category-discount/includes/js/woo-cat-disc-settings-scripts.js
Version Parameters
woo-category-discount/includes/js/woo-cat-disc-taxonomy-scripts.js?ver=woo-category-discount/includes/js/woo-cat-disc-product-scripts.js?ver=woo-category-discount/includes/js/woo-cat-disc-settings-scripts.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-wcd-product-iddata-wcd-discount-id
JS Globals
wcd_product
FAQ

Frequently Asked Questions about Category Discounts for WooCommerce