
WPEC Bulk Category Pricing Security & Risk Analysis
wordpress.org/plugins/wp-e-commerce-bulk-category-pricingThis plugin allows WP E-Commerce store admins to select certain categories as 'bulk pricing' categories, add a product threshold and discoun …
Is WPEC Bulk Category Pricing Safe to Use in 2026?
Generally Safe
Score 85/100WPEC Bulk Category Pricing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp-e-commerce-bulk-category-pricing" v1.0.2 exhibits a generally good security posture based on the static analysis, with no dangerous functions identified and all SQL queries utilizing prepared statements. The complete absence of known CVEs also suggests a history of stable security. However, a significant concern arises from the taint analysis, which reveals two flows with unsanitized paths. While these are not classified as critical or high severity in this analysis, they represent potential avenues for injection attacks if input is not properly validated and sanitized downstream. Additionally, the output escaping is low, with only 20% of outputs properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization.
The plugin's attack surface appears to be zero based on the provided metrics, which is a strong positive indicator. The lack of shortcodes, cron events, and exposed AJAX/REST API endpoints suggests a limited exposure. However, the absence of nonce checks and capability checks across all identified entry points (even if there are none listed) is a general weakness that could become a problem if new entry points are introduced in future versions without proper security considerations. The vulnerability history is clean, which is excellent, but the current taint flow and output escaping issues indicate that diligence is still required.
Key Concerns
- Flows with unsanitized paths found
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
WPEC Bulk Category Pricing Security Vulnerabilities
WPEC Bulk Category Pricing Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPEC Bulk Category Pricing Attack Surface
WordPress Hooks 6
Maintenance & Trust
WPEC Bulk Category Pricing Maintenance & Trust
Maintenance Signals
Community Trust
WPEC Bulk Category Pricing Alternatives
WP E-Commerce Advance Sales Report Lite
wp-e-commerce-advance-sales-report-lite
WP E-Commerce Advance Sales Report Lite shows you all key sales information in one main Dashboard in very intuitive, easy to understand format which g …
WP E-commerce Expanding Categories
wp-e-commerce-expanding-categories
WP E-commerce Expanding Categories converts the WP e-commerce categories widget into a collapsible menu
ShippingEasy for WP e-Commerce
shippingeasy-for-wp-ecommerce
ShippingEasy is a powerful online shipping platform that integrates seamlessly with your WordPress WP e-Commerce store to give you a complete end-to-e …
DropStream – Automated eCommerce Fulfillment
wp-dropstream
DropStream is a powerful eCommerce plugin that integrates your WordPress site with your shipping solution or third-party fulfillment provider, allowin …
WP e-Commerce Related Products
wpec-related-products
WPEC Related Products for WP e-Commerce uses information available within the Single Product template to display related Products.
WPEC Bulk Category Pricing Developer Profile
3 plugins · 30 total installs
How We Detect WPEC Bulk Category Pricing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wpsc_cat_boxwpsc_cat_image_size