AboveWP Bulk Attribute Change Security & Risk Analysis

wordpress.org/plugins/abovewp-bulk-attribute-change

Find products with specific attribute terms, remove them, and add a different attribute term instead.

0 active installs v1.1.0 PHP 7.4+ WP 5.0+ Updated Unknown
attributesbulk-editproductswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AboveWP Bulk Attribute Change Safe to Use in 2026?

Generally Safe

Score 100/100

AboveWP Bulk Attribute Change has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'abovewp-bulk-attribute-change' v1.1.0 exhibits a strong security posture based on the provided static analysis. All identified entry points, including AJAX handlers, appear to have proper authentication and capability checks, and no unsanitized taint flows were detected. The use of prepared statements for all SQL queries and proper output escaping for all outputs are significant strengths. Furthermore, the absence of any known vulnerabilities or CVEs in its history suggests a proactive and secure development lifecycle or simply a lack of past security issues. This plugin demonstrates good security practices, including nonces and capability checks, which are essential for protecting against common WordPress attacks. The absence of file operations and external HTTP requests further reduces its attack surface. However, while the current analysis reveals no immediate critical risks, the small number of entry points analyzed (2 AJAX handlers) means the overall attack surface might be larger than what's immediately apparent in this snapshot. The plugin shows excellent adherence to secure coding principles based on the data provided.

Vulnerabilities
None known

AboveWP Bulk Attribute Change Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AboveWP Bulk Attribute Change Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
51 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped51 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
process_products (abovewp-bulk-attribute-change.php:371)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AboveWP Bulk Attribute Change Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_abovewp_bulk_attribute_changeabovewp-bulk-attribute-change.php:38
authwp_ajax_abovewp_dismiss_promo_noticeincludes\class-abovewp-admin-menu.php:26
WordPress Hooks 10
actionplugins_loadedabovewp-bulk-attribute-change.php:35
actionadmin_initabovewp-bulk-attribute-change.php:41
actionadmin_headabovewp-bulk-attribute-change.php:44
actionadmin_headabovewp-bulk-attribute-change.php:47
actionadmin_enqueue_scriptsabovewp-bulk-attribute-change.php:50
actionadmin_menuabovewp-bulk-attribute-change.php:61
actionabovewp_admin_dashboard_pluginsabovewp-bulk-attribute-change.php:64
actionadmin_menuincludes\class-abovewp-admin-menu.php:23
actionadmin_enqueue_scriptsincludes\class-abovewp-admin-menu.php:24
actionadmin_noticesincludes\class-abovewp-admin-menu.php:25
Maintenance & Trust

AboveWP Bulk Attribute Change Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads400

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AboveWP Bulk Attribute Change Developer Profile

AboveWP

6 plugins · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AboveWP Bulk Attribute Change

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/abovewp-bulk-attribute-change/assets/css/admin.css/wp-content/plugins/abovewp-bulk-attribute-change/assets/js/admin.js
Script Paths
/wp-content/plugins/abovewp-bulk-attribute-change/assets/js/admin.js
Version Parameters
abovewp-bulk-attribute-change/assets/css/admin.css?ver=abovewp-bulk-attribute-change/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
abovewp-wrapabovewp-bg-effectsabovewp-bg-orbabovewp-bg-orb-1abovewp-bg-orb-2abovewp-containerabovewp-headerabovewp-logo-section+7 more
Data Attributes
data-attribute_namedata-source_termsdata-target_termdata-batch_sizedata-noncedata-action
JS Globals
AboveWP_BAC_AJAXAboveWP_BAC_AJAX_URL
FAQ

Frequently Asked Questions about AboveWP Bulk Attribute Change