
Woo Show Product Discount Security & Risk Analysis
wordpress.org/plugins/woo-show-product-discountWooCommerce extension to show product discount on shop page as well as on product page. Most importantly provides lots of customization options to giv …
Is Woo Show Product Discount Safe to Use in 2026?
Generally Safe
Score 85/100Woo Show Product Discount has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-show-product-discount" plugin, version 1.0.4, exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that could serve as direct entry points for attackers. Furthermore, the analysis reveals a lack of dangerous functions and no SQL queries that do not use prepared statements, which are excellent practices. The absence of file operations and external HTTP requests also reduces potential attack vectors.
However, there are a few areas of concern. The most significant is the low percentage of properly escaped output (22%), indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully in the remaining outputs. The lack of nonce checks on AJAX handlers, while currently not a direct risk due to the absence of such handlers, suggests a potential oversight in defensive programming if functionality were to be added. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. This, combined with the internal code analysis, suggests the developers are likely following good security practices.
In conclusion, the plugin appears to be reasonably secure due to its limited attack surface and sound SQL handling. The primary weakness lies in output escaping, which requires attention to prevent potential XSS issues. The absence of a vulnerability history is a strong positive, but the lack of comprehensive output escaping is a notable area for improvement to further bolster its security.
Key Concerns
- Low percentage of properly escaped output
Woo Show Product Discount Security Vulnerabilities
Woo Show Product Discount Release Timeline
Woo Show Product Discount Code Analysis
Output Escaping
Woo Show Product Discount Attack Surface
WordPress Hooks 14
Maintenance & Trust
Woo Show Product Discount Maintenance & Trust
Maintenance Signals
Community Trust
Woo Show Product Discount Alternatives
No alternatives data available yet.
Woo Show Product Discount Developer Profile
2 plugins · 130 total installs
How We Detect Woo Show Product Discount
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-show-product-discount/admin/css/wspd-admin-settings.css/wp-content/plugins/woo-show-product-discount/admin/js/wspd-admin-settings.js/wp-content/plugins/woo-show-product-discount/frontend/css/woo-show-product-discount.css/wp-content/plugins/woo-show-product-discount/frontend/js/woo-show-product-discount.jswoo-show-product-discount/admin/css/wspd-admin-settings.css?ver=woo-show-product-discount/admin/js/wspd-admin-settings.js?ver=woo-show-product-discount/frontend/css/woo-show-product-discount.css?ver=woo-show-product-discount/frontend/js/woo-show-product-discount.js?ver=HTML / DOM Fingerprints
wspd-discount-percentagewspd-discount-amountwspd-discount-badgewspd-sale-badgeThanks for using <b>Woo Show Product Discount</b>.data-wspd-discount-percentagedata-wspd-discount-amountwspd_admin_settings_params{{*wspd_%_discount}}{{*wspd_amount_discount}}