Extended Coupon Features for WooCommerce FREE Security & Risk Analysis

wordpress.org/plugins/woocommerce-auto-added-coupons

Additional functionality for WooCommerce Coupons: Allow discounts to be automatically applied, applying coupons via url, etc...

10K active installs v3.4.2 PHP 7.0+ WP 5.0+ Updated Feb 14, 2026
couponsdiscountwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Extended Coupon Features for WooCommerce FREE Safe to Use in 2026?

Generally Safe

Score 100/100

Extended Coupon Features for WooCommerce FREE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "woocommerce-auto-added-coupons" v3.4.2 plugin appears to have a generally strong security posture. The static analysis reveals no identified entry points for attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events that are not protected by authentication. Furthermore, there are no detected dangerous functions or external HTTP requests, and importantly, no taint analysis revealed any critical or high severity vulnerabilities related to unsanitized data flow. The code also demonstrates a good level of output escaping, with 75% of outputs properly handled. However, a notable concern is the complete absence of nonce checks across all identified entry points, which is unusual given the 3 capability checks present. This lack of nonce verification could potentially be exploited if an attacker can trick a user into triggering actions associated with these capability checks without their explicit consent. Additionally, the SQL queries show that only 20% are using prepared statements, meaning a significant portion of the 5 SQL queries are susceptible to SQL injection if not handled with extreme care elsewhere in the code. The plugin's vulnerability history is entirely clean, with no recorded CVEs, which is a positive indicator. Overall, while the plugin exhibits strengths in preventing direct attack vectors and data flow vulnerabilities, the absence of nonce checks and the low percentage of prepared SQL statements represent significant areas for improvement to achieve a more robust security profile.

Key Concerns

  • No nonce checks present on entry points
  • Low percentage of prepared SQL statements (20%)
Vulnerabilities
None known

Extended Coupon Features for WooCommerce FREE Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Extended Coupon Features for WooCommerce FREE Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
1 prepared
Unescaped Output
26
77 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery3.6.0

SQL Query Safety

20% prepared5 total queries

Output Escaping

75% escaped103 total outputs
Attack Surface

Extended Coupon Features for WooCommerce FREE Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 50
filterwoocommerce_coupon_is_validincludes\class-wjecf-controller.php:87
actionwoocommerce_checkout_update_order_reviewincludes\class-wjecf-controller.php:90
actionwoocommerce_after_checkout_validationincludes\class-wjecf-controller.php:91
filterwoocommerce_coupon_messageincludes\class-wjecf-controller.php:94
actionadmin_noticesincludes\plugins\WJECF_Admin.php:36
filterplugin_row_metaincludes\plugins\WJECF_Admin.php:39
actionadmin_headincludes\plugins\WJECF_Admin.php:40
filterwoocommerce_coupon_data_tabsincludes\plugins\WJECF_Admin.php:42
actionwoocommerce_coupon_data_panelsincludes\plugins\WJECF_Admin.php:43
actionwoocommerce_process_shop_coupon_metaincludes\plugins\WJECF_Admin.php:44
actionwoocommerce_coupon_options_usage_restrictionincludes\plugins\WJECF_Admin.php:46
actionwjecf_coupon_metabox_checkoutincludes\plugins\WJECF_Admin.php:48
actionwjecf_coupon_metabox_customerincludes\plugins\WJECF_Admin.php:49
actionadmin_menuincludes\plugins\WJECF_Admin_Settings.php:26
actionadmin_initincludes\plugins\WJECF_Admin_Settings.php:27
actionwoocommerce_cart_loaded_from_sessionincludes\plugins\WJECF_Autocoupon.php:40
actionwoocommerce_checkout_update_order_reviewincludes\plugins\WJECF_Autocoupon.php:43
actionwoocommerce_check_cart_itemsincludes\plugins\WJECF_Autocoupon.php:44
actionwoocommerce_after_calculate_totalsincludes\plugins\WJECF_Autocoupon.php:47
filterwoocommerce_cart_totals_coupon_labelincludes\plugins\WJECF_Autocoupon.php:50
filterwoocommerce_cart_totals_coupon_htmlincludes\plugins\WJECF_Autocoupon.php:51
filterwoocommerce_checkout_fieldsincludes\plugins\WJECF_Autocoupon.php:54
actionwoocommerce_review_order_before_paymentincludes\plugins\WJECF_Autocoupon.php:55
filteroption_woocommerce_cart_redirect_after_addincludes\plugins\WJECF_Autocoupon.php:58
actionwp_loadedincludes\plugins\WJECF_Autocoupon.php:62
actionwoocommerce_applied_couponincludes\plugins\WJECF_Autocoupon.php:71
actionwoocommerce_removed_couponincludes\plugins\WJECF_Autocoupon.php:72
actionwoocommerce_cart_emptiedincludes\plugins\WJECF_Autocoupon.php:73
actionwjecf_woocommerce_coupon_options_extended_featuresincludes\plugins\WJECF_Autocoupon.php:80
actionwoocommerce_update_couponincludes\plugins\WJECF_Autocoupon.php:84
actionwoocommerce_delete_couponincludes\plugins\WJECF_Autocoupon.php:85
actionwoocommerce_trash_couponincludes\plugins\WJECF_Autocoupon.php:86
actionwoocommerce_new_couponincludes\plugins\WJECF_Autocoupon.php:87
filterviews_edit-shop_couponincludes\plugins\WJECF_Autocoupon.php:105
filterrequestincludes\plugins\WJECF_Autocoupon.php:106
actionwjecf_admin_before_settingsincludes\plugins\WJECF_Autocoupon.php:108
filterwjecf_admin_validate_settingsincludes\plugins\WJECF_Autocoupon.php:109
actionwp_loadedincludes\plugins\WJECF_Debug.php:34
actionwp_footerincludes\plugins\WJECF_Debug.php:35
actionwjecf_coupon_metabox_miscincludes\plugins\WJECF_Debug.php:50
filterwjecf_get_product_idincludes\plugins\WJECF_WPML.php:27
filterwjecf_get_product_idsincludes\plugins\WJECF_WPML.php:28
filterwjecf_get_product_cat_idincludes\plugins\WJECF_WPML.php:29
filterwjecf_get_product_cat_idsincludes\plugins\WJECF_WPML.php:30
filterwoocommerce_coupon_get_descriptionincludes\plugins\WJECF_WPML.php:31
actioninitwoocommerce-jos-autocoupon.php:26
actioninitwoocommerce-jos-autocoupon.php:27
actionadmin_noticeswoocommerce-jos-autocoupon.php:86
actionadmin_noticeswoocommerce-jos-autocoupon.php:94
actionbefore_woocommerce_initwoocommerce-jos-autocoupon.php:112
Maintenance & Trust

Extended Coupon Features for WooCommerce FREE Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 14, 2026
PHP min version7.0
Downloads529K

Community Trust

Rating100/100
Number of ratings69
Active installs10K
Developer Profile

Extended Coupon Features for WooCommerce FREE Developer Profile

Soft79

4 plugins · 11K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Extended Coupon Features for WooCommerce FREE

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-auto-added-coupons/assets/css/wjecf-admin-styles.css/wp-content/plugins/woocommerce-auto-added-coupons/assets/js/wjecf-admin-coupons.js/wp-content/plugins/woocommerce-auto-added-coupons/assets/js/wjecf-admin-usage-restriction.js
Script Paths
/wp-content/plugins/woocommerce-auto-added-coupons/assets/js/wjecf-admin-coupons.js/wp-content/plugins/woocommerce-auto-added-coupons/assets/js/wjecf-admin-usage-restriction.js
Version Parameters
woocommerce-auto-added-coupons/assets/css/wjecf-admin-styles.css?ver=woocommerce-auto-added-coupons/assets/js/wjecf-admin-coupons.js?ver=woocommerce-auto-added-coupons/assets/js/wjecf-admin-usage-restriction.js?ver=

HTML / DOM Fingerprints

CSS Classes
wjecf-not-wide
Data Attributes
data-wjecf-coupon-id
JS Globals
wjecf_admin_coupons_paramswjecf_usage_restriction_params
FAQ

Frequently Asked Questions about Extended Coupon Features for WooCommerce FREE