WT Variation Bulk Order Security & Risk Analysis

wordpress.org/plugins/wt-variation-bulk-order

WT Variation Bulk Order plugin simplifies purchasing variant products by streamlining the selection process for bulk orders.

0 active installs v1.0.0 PHP 7.0+ WP 3.0.1+ Updated Mar 31, 2025
display-product-variations-in-table-for-woocommercequick-bulk-orderwoocommerce-table-variationswoocommerce-variations-tablewoocommerce-variations-to-table
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WT Variation Bulk Order Safe to Use in 2026?

Generally Safe

Score 92/100

WT Variation Bulk Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "wt-variation-bulk-order" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of exploitable taint flows, raw SQL queries, file operations, and external HTTP requests is highly commendable. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and employing nonce checks on its entry points. Furthermore, the plugin has no recorded vulnerability history, suggesting a commitment to secure development or a lack of past exposure.

Despite these strengths, there are a few areas that warrant attention. While the attack surface is small and no entry points are explicitly listed as unprotected, the lack of capability checks on the AJAX handlers is a significant concern. This means that any authenticated user, regardless of their role or permissions, could potentially trigger these AJAX actions. Additionally, the output escaping is not universally applied, with 28% of outputs potentially being unescaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is involved in those outputs. The bundled Select2 library, while common, also represents a potential dependency risk if it's not kept up-to-date.

In conclusion, the plugin is built on a solid foundation with many secure coding practices in place. However, the absence of capability checks on AJAX handlers and the incomplete output escaping represent the most critical vulnerabilities that need immediate attention to mitigate potential security risks. The clean vulnerability history is a positive indicator but should not lead to complacency.

Key Concerns

  • AJAX handlers without capability checks
  • Unescaped output (28% of total)
  • Bundled library (Select2) without version info
Vulnerabilities
None known

WT Variation Bulk Order Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WT Variation Bulk Order Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

WT Variation Bulk Order Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
103
271 escaped
Nonce Checks
9
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

72% escaped374 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
plugin_setting_page (admin/class-admin.php:77)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WT Variation Bulk Order Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_wtvbo_variation_bulk_order_add_to_cartpublic/includes/wtvbo-variation-bulk-order-ajax-functions.php:41
noprivwp_ajax_wtvbo_variation_bulk_order_add_to_cartpublic/includes/wtvbo-variation-bulk-order-ajax-functions.php:42
WordPress Hooks 15
actionadmin_menuadmin/class-admin.php:41
actionadmin_enqueue_scriptsadmin/class-admin.php:42
actionadmin_enqueue_scriptsadmin/class-admin.php:43
actionadmin_print_scriptsadmin/class-field-functions.php:41
filterwtvbo_variation_bulk_order_settings_navadmin/class-wtvbo-variation-bulk-order-custom-setting.php:41
filterwtvbo_variation_bulk_order_settings_paneladmin/class-wtvbo-variation-bulk-order-custom-setting.php:42
actionplugins_loadedincludes/packages.php:142
actionwp_enqueue_scriptspublic/class-public.php:72
actionwp_enqueue_scriptspublic/class-public.php:73
actionwtvbo_variation_bulk_order_table_before_contentpublic/includes/wtvbo-variation-bulk-order-table-body-hook.php:9
actionwtvbo_variation_bulk_order_table_beforepublic/includes/wtvbo-variation-bulk-order-table-body-hook.php:16
actionwtvbo_variation_bulk_order_table_afterpublic/includes/wtvbo-variation-bulk-order-table-body-hook.php:24
actionwtvbo_variation_bulk_order_table_after_contentpublic/includes/wtvbo-variation-bulk-order-table-body-hook.php:32
actionwoocommerce_before_add_to_cart_formpublic/templates/wtvbo-variation-bulk-order-table.php:94
actionwoocommerce_after_add_to_cart_formpublic/templates/wtvbo-variation-bulk-order-table.php:95
Maintenance & Trust

WT Variation Bulk Order Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMar 31, 2025
PHP min version7.0
Downloads630

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

WT Variation Bulk Order Alternatives

No alternatives data available yet.

Developer Profile

WT Variation Bulk Order Developer Profile

Akash Soni

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WT Variation Bulk Order

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wt-variation-bulk-order/admin/css/style.css/wp-content/plugins/wt-variation-bulk-order/admin/js/settings.js/wp-content/plugins/wt-variation-bulk-order/admin/js/admin.js
Version Parameters
wt-variation-bulk-order/admin/css/style.css?ver=wt-variation-bulk-order/admin/js/settings.js?ver=wt-variation-bulk-order/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wt-panel-settingsnav-tab-wrapperpanel-wrapperwt-submitalertaction-wrapperdocumentationreset+3 more
Data Attributes
id="plugin-data"name="reset"name="submit"
JS Globals
var wt_settings
REST Endpoints
wp_ajax_wt-variation-bulk-order_datasavewp_ajax_nopriv_wt-variation-bulk-order_datasavewp_ajax_wt-variation-bulk-order_dataresetwp_ajax_nopriv_wt-variation-bulk-order_datareset
FAQ

Frequently Asked Questions about WT Variation Bulk Order