
WPC Product Bundles for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-product-bundleWPC Product Bundles is a plugin that helps you bundle a few products, offer them at a discount, and watch the sales go up!
Is WPC Product Bundles for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100WPC Product Bundles for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "woo-product-bundle" plugin version 8.4.8 exhibits a generally positive security posture, with a robust approach to handling AJAX requests and SQL queries. The complete absence of unauthenticated entry points (AJAX handlers, REST API routes, shortcodes) and the consistent use of prepared statements for all SQL queries are strong indicators of good security practices. Furthermore, the plugin demonstrates a high rate of proper output escaping and implements a significant number of nonce and capability checks, which are vital for preventing various web attacks. The vulnerability history shows only one medium severity CVE, which is now patched, suggesting a proactive approach to addressing past security issues.
However, the presence of three instances of the `unserialize` function is a notable concern. While the static analysis doesn't highlight critical or high-severity taint flows related to `unserialize`, this function is inherently risky if the data being deserialized is not strictly controlled or validated. The three flows with unsanitized paths, although not classified as critical or high, warrant careful investigation. The external HTTP requests, while not explicitly flagged as problematic in this analysis, could represent a potential vector if not implemented with strict validation and sanitization of external data. Overall, the plugin is well-protected in many areas, but the `unserialize` usage and unsanitized paths introduce a level of risk that should not be overlooked.
Key Concerns
- Dangerous function `unserialize` used
- Flows with unsanitized paths found
- External HTTP requests present
WPC Product Bundles for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPC Product Bundles for WooCommerce <= 7.3.1 - Cross-Site Request Forgery
WPC Product Bundles for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WPC Product Bundles for WooCommerce Attack Surface
AJAX Handlers 7
Shortcodes 3
WordPress Hooks 97
Maintenance & Trust
WPC Product Bundles for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WPC Product Bundles for WooCommerce Alternatives
Product Bundle Builder for WooCommerce
easy-product-bundles-for-woocommerce
WooCommerce Product Bundle help to creates Product Bundles, Composite Products, Mix and Match, BOGO deals, Offer gift products, and Assembled Products …
WPC Composite Products for WooCommerce
wpc-composite-products
WPC Composite Products provide a powerful kit-building solution for WooCommerce store.
WPC Grouped Product for WooCommerce
wpc-grouped-product
WPC Grouped Product helps you make up standalone products that are presented as a group.
Product Bundles – Bulk Discounts
product-bundles-bulk-discounts-for-woocommerce
Free mini-extension for WooCommerce Product Bundles that allows you to offer bulk quantity discounts.
Product Bundles – Variation Bundles
product-bundles-variation-bundles
Free mini-extension for WooCommerce Product Bundles that allows you to map Bundles to variations. Once a Product Bundle has been mapped to a variation …
WPC Product Bundles for WooCommerce Developer Profile
71 plugins · 441K total installs
How We Detect WPC Product Bundles for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-product-bundle/assets/css/woosb-blocks.css/wp-content/plugins/woo-product-bundle/assets/js/woosb-blocks.js/wp-content/plugins/woo-product-bundle/assets/js/woosb-blocks.jswoo-product-bundle/assets/css/woosb-blocks.css?ver=woo-product-bundle/assets/js/woosb-blocks.js?ver=HTML / DOM Fingerprints
woosb-blocksdata-woosb-bundlesdata-woosb-bundleddata-woosb-hide-bundleddata-woosb-fixed-pricedata-woosb-pricewindow.wc_blocks_all_settingswindow.wc_blocks_products_block_editor_settingswindow.wc_blocks_cart_block_settings/wp-json/wc/store/v1/products/wp-json/wc/store/v1/cart/wp-json/wc/store/v1/checkout