Dynamic Pricing & Discounts Lite Security & Risk Analysis

wordpress.org/plugins/woo-dynamic-pricing-discounts-lite

Eminent plugin for WooCommerce stores with all type of discounts – dynamic pricing & discounts, category discount, product discount, BOGO rule & more.

500 active installs v2.0.4 PHP + WP 5.0.0+ Updated Dec 19, 2025
bogobulk-discountdynamic-discountdynamic-pricingwoocommerce
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEMay 19, 2025
Safety Verdict

Is Dynamic Pricing & Discounts Lite Safe to Use in 2026?

Mostly Safe

Score 78/100

Dynamic Pricing & Discounts Lite is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: May 19, 2025Updated 3mo ago
Risk Assessment

The 'woo-dynamic-pricing-discounts-lite' plugin version 2.0.4 exhibits a mixed security posture. The static analysis reveals a very small attack surface with zero identified entry points, which is a strong positive indicator. Furthermore, the code demonstrates good security practices by utilizing prepared statements for all SQL queries and performing a high percentage of output escaping, along with a decent number of nonce and capability checks. Taint analysis shows no critical or high-severity issues, suggesting a lack of readily exploitable code injection or manipulation vulnerabilities within the analyzed flows.

However, the plugin's vulnerability history is a significant concern. It has one known CVE, which is currently unpatched. This medium-severity vulnerability, historically of the Cross-Site Request Forgery (CSRF) type, indicates a past weakness that has not been remediated. The presence of an unpatched CVE, regardless of its historical severity, introduces a tangible risk to any WordPress site using this version. While the code itself appears robust in its current state according to the static analysis, the unpatched vulnerability necessitates immediate attention and mitigation.

Key Concerns

  • Unpatched CVE present
  • Bundled library: DataTables
Vulnerabilities
1

Dynamic Pricing & Discounts Lite Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48342medium · 4.7Cross-Site Request Forgery (CSRF)

Dynamic Pricing &amp; Discounts Lite for WooCommerce <= 2.0.3 - Cross-Site Request Forgery

May 19, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Dynamic Pricing & Discounts Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
73
571 escaped
Nonce Checks
10
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

89% escaped644 total outputs
Data Flows
All sanitized

Data Flow Analysis

7 flows
<rtwwdpdl_bogo_rule> (admin\partials\rtwwdpdl_subtabs\rtwwdpdl_bogo_rule.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Dynamic Pricing & Discounts Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionbefore_woocommerce_initdynamic-pricing-discounts-lite-for-woocommerce.php:80
actionadmin_noticesdynamic-pricing-discounts-lite-for-woocommerce.php:135
actioninitpublic\classes\modules\rtwwdpdl-class-simple-base.php:24
Maintenance & Trust

Dynamic Pricing & Discounts Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 19, 2025
PHP min version
Downloads26K

Community Trust

Rating78/100
Number of ratings8
Active installs500
Developer Profile

Dynamic Pricing & Discounts Lite Developer Profile

RedefiningTheWeb

6 plugins · 2K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
180 days
View full developer profile
Detection Fingerprints

How We Detect Dynamic Pricing & Discounts Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Dynamic Pricing & Discounts Lite