
ACL – Woo Advanced Customer Dashboard Security & Risk Analysis
wordpress.org/plugins/acl-woo-advanced-customer-dashboardCustomer Dashboard Plugin is the most Advanced Award Wining WooCommerce plugin that lets you create the decorative users end dashboard with many inter …
Is ACL – Woo Advanced Customer Dashboard Safe to Use in 2026?
Generally Safe
Score 85/100ACL – Woo Advanced Customer Dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the acl-woo-advanced-customer-dashboard plugin version 0.8.0 presents significant concerns due to a large number of unprotected entry points. With 30 out of 32 total entry points lacking authentication checks, the plugin exposes a vast attack surface to unauthorized users. The taint analysis, while not revealing critical or high severity flaws, did identify 11 flows with unsanitized paths, indicating a potential for various injection vulnerabilities if not handled carefully. Furthermore, the complete absence of nonce checks on AJAX handlers is a critical oversight, making it highly susceptible to Cross-Site Request Forgery (CSRF) attacks. The extensive use of raw SQL queries without prepared statements (100% of them) is another major security weakness, increasing the risk of SQL injection vulnerabilities. The low percentage of properly escaped output (38%) further exacerbates these risks, as it can lead to Cross-Site Scripting (XSS) vulnerabilities. While the plugin has no recorded vulnerability history, this does not negate the clear and present dangers identified in the static and taint analysis. The plugin's strengths are minimal in terms of security; its only positive aspects are the absence of dangerous functions, file operations, and external HTTP requests, along with no unpatched CVEs. However, these do not outweigh the numerous and severe security weaknesses.
Key Concerns
- AJAX handlers without auth checks
- SQL queries without prepared statements
- Low output escaping percentage
- Missing nonce checks on AJAX
- Unsanitized paths in taint flows
- No capability checks
ACL – Woo Advanced Customer Dashboard Security Vulnerabilities
ACL – Woo Advanced Customer Dashboard Release Timeline
ACL – Woo Advanced Customer Dashboard Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ACL – Woo Advanced Customer Dashboard Attack Surface
AJAX Handlers 30
Shortcodes 2
WordPress Hooks 64
Maintenance & Trust
ACL – Woo Advanced Customer Dashboard Maintenance & Trust
Maintenance Signals
Community Trust
ACL – Woo Advanced Customer Dashboard Alternatives
No alternatives data available yet.
ACL – Woo Advanced Customer Dashboard Developer Profile
4 plugins · 40 total installs
How We Detect ACL – Woo Advanced Customer Dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acl-woo-advanced-customer-dashboard/css/style.css/wp-content/plugins/acl-woo-advanced-customer-dashboard/js/admin.js/wp-content/plugins/acl-woo-advanced-customer-dashboard/js/frontend.js/wp-content/plugins/acl-woo-advanced-customer-dashboard/js/admin.js/wp-content/plugins/acl-woo-advanced-customer-dashboard/js/frontend.jsacl-woo-advanced-customer-dashboard/style.css?ver=acl-woo-advanced-customer-dashboard/js/admin.js?ver=acl-woo-advanced-customer-dashboard/js/frontend.js?ver=HTML / DOM Fingerprints
acl-wooacd-custom-request-wrapacl-wooacd-estimated-delivery-wrapacl-wooacd-section-header<!-- Custom fields added by ACL Woo Advanced Customer Dashboard --><!-- ACL Woo Advanced Customer Dashboard custom fields end -->data-acl-wooacd-current-pagedata-acl-wooacd-ajax-urlacl_wooacd_ajax_object/wp-json/acl-wooacd/v1/get_dashboard_data/wp-json/acl-wooacd/v1/update_dashboard_settings[acl_wooacd_dashboard][acl_wooacd_custom_request]