
Add Customer for WooCommerce Security & Risk Analysis
wordpress.org/plugins/add-customer-for-woocommerceAdds a new checkbox to the orders page to add a new customer/user and links orders to existing accounts
Is Add Customer for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Add Customer for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The 'add-customer-for-woocommerce' plugin v1.9.5 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, indicating good practices in these areas. However, a significant concern is the low percentage (18%) of properly escaped output, which suggests a potential for Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while not highlighting critical or high-severity flows, did identify two flows with unsanitized paths, which should be investigated further.
The plugin's vulnerability history, while not showing any currently unpatched vulnerabilities, does include a past medium-severity XSS vulnerability. This history, coupled with the low output escaping rate, reinforces the concern for XSS. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with authentication checks results in a zero attack surface from these entry points, which is a strong security positive. However, the complete lack of nonce and capability checks across the board is a significant weakness that could be exploited if any entry points were to be introduced or if existing entry points are not properly secured by other means.
In conclusion, while the plugin demonstrates strengths in secure SQL handling and avoiding risky functions or external calls, the pervasive issue of unescaped output and the absence of robust authentication checks present notable security weaknesses. The past XSS vulnerability further emphasizes the need for careful code review and improvement in output sanitization. The lack of any identified entry points with authentication checks is a good indicator of current security but leaves room for future risk if new entry points are added without proper checks.
Key Concerns
- Low output escaping rate (18%)
- Two taint flows with unsanitized paths
- Past medium severity XSS vulnerability
- No nonce checks found
- No capability checks found
Add Customer for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Add Customer for WooCommerce <= 1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
Add Customer for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Add Customer for WooCommerce Attack Surface
WordPress Hooks 29
Maintenance & Trust
Add Customer for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Add Customer for WooCommerce Alternatives
Hibiscus Login As Customer for WooCommerce
hibiscus-login-as-customer
Securely log in as any WooCommerce customer and return to admin with one click.
E.T.T – Easy Time Tracker for WooCommerce
ett-easy-time-tracker-for-woocommerce
An easy and efficient way to track time spent on WooCommerce order products.
Customer Reviews for WooCommerce
customer-reviews-woocommerce
Customer Reviews for WooCommerce plugin helps you get more sales with social proof. Set up automated review reminders and increase conversion rate.
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Add Customer for WooCommerce Developer Profile
3 plugins · 1K total installs
How We Detect Add Customer for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-customer-for-woocommerce/assets/css/style.css/wp-content/plugins/add-customer-for-woocommerce/assets/js/wac-admin.js/wp-content/plugins/add-customer-for-woocommerce/assets/js/wac-frontend.js/wp-content/plugins/add-customer-for-woocommerce/assets/js/wac-admin.js/wp-content/plugins/add-customer-for-woocommerce/assets/js/wac-frontend.jsadd-customer-for-woocommerce/assets/css/style.css?ver=add-customer-for-woocommerce/assets/js/wac-admin.js?ver=add-customer-for-woocommerce/assets/js/wac-frontend.js?ver=HTML / DOM Fingerprints
wac-add-customer-fieldwac-new-customer-buttonwac-add-new-customer-sectionwac-customer-added-message<!-- WAC: Add New Customer Section --><!-- WAC: Customer Added Confirmation -->data-wac-noncedata-wac-actiondata-wac-customer-addedwac_frontend_params