Advanced Reporting for Woocommerce Security & Risk Analysis

wordpress.org/plugins/advanced-reporting-for-woocommerce

WooCommerce Advance Reporting System plugin is a plugin which shows you a complete sales report of Total Summary, Recent Orders, Top Billing Country, …

400 active installs v3.0 PHP + WP 4.0+ Updated Dec 28, 2020
product-sales-reportsale-reportsale-reportssalessales-report
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced Reporting for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced Reporting for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The advanced-reporting-for-woocommerce plugin v3.0 demonstrates a strong security posture in several key areas. The absence of any known CVEs, unpatched vulnerabilities, or recorded common vulnerability types suggests a history of responsible development and maintenance. The static analysis reveals a notably small attack surface with zero unprotected entry points, which is excellent. Furthermore, the plugin exclusively uses prepared statements for its SQL queries and avoids file operations or external HTTP requests, significantly reducing common attack vectors. The presence of a nonce check is also a positive sign for input validation.

However, the analysis also highlights a significant concern regarding output escaping. With only 7% of outputs properly escaped out of 85 total outputs, this presents a substantial risk of cross-site scripting (XSS) vulnerabilities. This lack of proper sanitization means that data processed by the plugin and displayed to users could potentially be manipulated to execute malicious scripts within the user's browser. While the taint analysis did not reveal any immediate critical or high severity issues, the widespread improper output escaping is a critical weakness that needs immediate attention. The lack of capability checks on any entry points, although the entry points are currently unprotected, is also a theoretical concern if any new entry points were to be introduced in the future.

Key Concerns

  • Low percentage of properly escaped outputs
  • Missing capability checks on entry points
Vulnerabilities
None known

Advanced Reporting for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Advanced Reporting for Woocommerce Release Timeline

v3.0Current
v2.9
v2.8
v2.7
v2.6
v2.5
v2.4
v2.3
v2.2
v2.1
v1.8
v1.7
v1.6
v1.5
v1.4
v1.3
v1.2
v1.1
Code Analysis
Analyzed Mar 16, 2026

Advanced Reporting for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
79
6 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

7% escaped85 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<phoen_reporting_settings> (includes\phoen_reporting_settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Advanced Reporting for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_initphoen_advance_reporting.php:14
actionadmin_menuphoen_advance_reporting.php:40
Maintenance & Trust

Advanced Reporting for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedDec 28, 2020
PHP min version
Downloads29K

Community Trust

Rating62/100
Number of ratings17
Active installs400
Developer Profile

Advanced Reporting for Woocommerce Developer Profile

Phoeniixx

25 plugins · 5K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Reporting for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-reporting-for-woocommerce/assets/css/phoen-arfw-bootstrap-iso.css/wp-content/plugins/advanced-reporting-for-woocommerce/includes/./../assets/font-awesome/css/font-awesome.min.css

HTML / DOM Fingerprints

CSS Classes
nav-tab-activewoo-nav-tab-wrapper
Data Attributes
data-toggledata-targetdata-parent
JS Globals
phoen_reporting_enable_settingsphoen_usertotal_registedphoen_top_productsphoen_product_dataphoen_totle_sale_products+2 more
FAQ

Frequently Asked Questions about Advanced Reporting for Woocommerce