WooProduct Discount period Security & Risk Analysis

wordpress.org/plugins/wooproduct-discount-period

Contributors: saiful.total Tags: woocommerce sale price, sales price with time, woocommerce price addon, woocommerce price schedule etc; Requires at …

0 active installs v1.0 PHP + WP + Updated Unknown
sales-price-with-timewoocommerce-price-addonwoocommerce-price-schedule-etcwoocommerce-sale-price
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WooProduct Discount period Safe to Use in 2026?

Generally Safe

Score 100/100

WooProduct Discount period has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "wooproduct-discount-period" plugin v1.0 presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having no known vulnerabilities or CVEs. Furthermore, the static analysis reveals no external HTTP requests or file operations, and zero taint flows, indicating a limited potential for certain classes of attacks. However, significant concerns exist regarding output escaping and the lack of explicit capability checks or nonce verification on its single shortcode entry point.

Despite a clean vulnerability history, the insufficient output escaping is a notable weakness. With only 33% of outputs properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered without proper sanitization. The absence of nonce checks and capability checks on the shortcode, while not directly indicative of a vulnerability without further context on what the shortcode does, represents a missed opportunity to enforce authorization and prevent unintended actions, especially if the shortcode interacts with sensitive data or functionality.

In conclusion, while the plugin appears to have a low attack surface and a clean track record, the lack of robust output escaping and authorization checks on its entry point are critical areas of concern that could be exploited. A thorough review of the shortcode's implementation is recommended to identify and mitigate potential XSS and authorization bypass vulnerabilities.

Key Concerns

  • Unescaped output
  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

WooProduct Discount period Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WooProduct Discount period Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Attack Surface

WooProduct Discount period Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[nss_showing_discount_product] nss_wooprice_discount.php:13
WordPress Hooks 3
actionadmin_menunss_wooprice_discount.php:15
actionadmin_initnss_wooprice_discount.php:16
actionwp_enqueue_scriptsnss_woo_sales.php:30
Maintenance & Trust

WooProduct Discount period Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version
Downloads955

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WooProduct Discount period Developer Profile

saiful.total

3 plugins · 80 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WooProduct Discount period

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wooproduct-discount-period/css/nss_woo_style.css

HTML / DOM Fingerprints

CSS Classes
nss_woo_product_mainnss_price_cart
Data Attributes
name="nss_option_page_item[nss_number_of_page]"
Shortcode Output
[nss_showing_discount_product][add_to_cart
FAQ

Frequently Asked Questions about WooProduct Discount period