
Dynamic Pricing and Discount Rules for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-conditional-discount-rules-for-checkoutConditional Discount Rules For WooCommerce Checkout Plugin will help you to create and manage complex discount rules based on your requirement.
Is Dynamic Pricing and Discount Rules for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Dynamic Pricing and Discount Rules for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "woo-conditional-discount-rules-for-checkout" v2.5.3 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and a high percentage of properly escaped output. The absence of file operations and external HTTP requests in the static analysis also suggests a more contained footprint. However, a significant concern arises from the substantial attack surface composed of 13 AJAX handlers, all of which lack authentication checks. This creates a broad entry point for potential attacks. While taint analysis shows no critical or high-severity unsanitized flows, the presence of 2 flows with unsanitized paths, even if not immediately exploitable in this analysis, warrants attention.
The vulnerability history shows a single medium-severity CVE in the past, specifically a Cross-Site Request Forgery (CSRF). The fact that this vulnerability is not currently unpatched is a positive sign, but the historical presence of CSRF indicates a pattern that users should be aware of. The plugin's strengths lie in its secure SQL handling and output escaping. The primary weaknesses are the large number of unprotected AJAX endpoints and the existence of unsanitized flows in the taint analysis, despite the absence of critical vulnerabilities from this analysis. The historical CSRF vulnerability, while addressed, serves as a reminder of potential risks.
Key Concerns
- 13 unprotected AJAX handlers
- 2 flows with unsanitized paths
- 1 medium severity CVE historically
- Bundled outdated library (Freemius v1.0)
Dynamic Pricing and Discount Rules for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WooCommerce Dynamic Pricing and Discount Rules <= 2.4.0 - Cross-Site Request Forgery
Dynamic Pricing and Discount Rules for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Dynamic Pricing and Discount Rules for WooCommerce Attack Surface
AJAX Handlers 13
WordPress Hooks 36
Maintenance & Trust
Dynamic Pricing and Discount Rules for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Dynamic Pricing and Discount Rules for WooCommerce Alternatives
PiWeb Conditional Discount / Bulk discounts for WooCommerce
conditional-discount-rule-for-woocommerce
Discount woocommerce plugin / Bulk discounts for woocommerce / dynamic pricing rule like product discount, product category discounts etc..
Conditional Discounts for WooCommerce – A simple yet complete woocommerce dynamic pricing plugin
woo-advanced-discounts
A powerful WooCommerce dynamic pricing plugin for bulk discounts, free gifts, BOGOs, customer role or groups based deals and much more.
Dynamic Pricing With Discount Rules for WooCommerce
aco-woo-dynamic-pricing
The Dynamic Pricing With Discount Rules plugin enables bulk discounts for WooCommerce products. Its simple design allows easy setup in minutes.
Simple Discount Rules for Woocommerce
woo-product-category-discount
Simple Discount Rules for Woocommerce allows administrator to add and remove discount to products based on Category.
Discount Rules for WooCommerce – Disco | Dynamic Pricing, Conditions, Bulk, Bundle, BOGO
disco
WooCommerce discount rules plugin to create automatic product and cart discounts, bulk pricing, BOGO deals, and dynamic pricing without coupon codes.
Dynamic Pricing and Discount Rules for WooCommerce Developer Profile
37 plugins · 95K total installs
How We Detect Dynamic Pricing and Discount Rules for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-conditional-discount-rules-for-checkout/admin/css/wcdrfc-admin.css/wp-content/plugins/woo-conditional-discount-rules-for-checkout/admin/css/wcdrfc-plugin-setup-wizard.css/wp-content/plugins/woo-conditional-discount-rules-for-checkout/admin/js/wcdrfc-admin.js/wp-content/plugins/woo-conditional-discount-rules-for-checkout/freemius/assets/css/style.csswoo-conditional-discount-rules-for-checkout/admin/css/wcdrfc-admin.css?ver=woo-conditional-discount-rules-for-checkout/admin/css/wcdrfc-plugin-setup-wizard.css?ver=woo-conditional-discount-rules-for-checkout/admin/js/wcdrfc-admin.js?ver=woo-conditional-discount-rules-for-checkout/freemius/assets/css/style.css?ver=HTML / DOM Fingerprints
ds-wizard-wrapds-wizard-contentcta-titledata-wcdrfc-idwcdrfc_fs