Smart Related Products – AI-Inspired Recommendations for WooCommerce Security & Risk Analysis

wordpress.org/plugins/ai-related-products

Show the right products to the right customers. A smart WooCommerce add-on for personalized product recommendations.

1K active installs v2.0.8 PHP 5.6+ WP 5.6+ Updated Feb 26, 2026
products-recommendationrelated-productsupsellwoocommerce-automation
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 26, 2025
Safety Verdict

Is Smart Related Products – AI-Inspired Recommendations for WooCommerce Safe to Use in 2026?

Mostly Safe

Score 78/100

Smart Related Products – AI-Inspired Recommendations for WooCommerce is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Sep 26, 2025Updated 2mo ago
Risk Assessment

The "ai-related-products" plugin v2.0.8 exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped outputs, several concerning factors warrant attention. The absence of nonce checks and capability checks on its entry points, particularly its single shortcode, is a significant weakness. This means that any authenticated user could potentially trigger the functionality associated with this shortcode without proper authorization checks, opening the door for various attacks if the shortcode's output or functionality is not strictly controlled.

The vulnerability history reveals a pattern of past security issues, specifically cross-site scripting (XSS) vulnerabilities. The presence of a currently unpatched medium-severity vulnerability from late 2025 is a critical concern. This indicates that the plugin's developers may not be consistently addressing security flaws promptly, or that users are not updating to patched versions. While the static analysis didn't reveal new critical taint flows or dangerous functions in this version, the historical pattern coupled with the lack of authorization checks on the shortcode suggests a potential for future vulnerabilities, especially if the shortcode handles user-supplied data.

In conclusion, the plugin has strengths in its database query handling and output sanitization. However, the lack of robust authorization checks on its entry points and the unpatched historical vulnerability significantly detract from its overall security. Users should exercise caution and prioritize updating to a version that addresses the known CVE. The development team should implement nonce and capability checks for all entry points and ensure timely patching of all security vulnerabilities.

Key Concerns

  • Unpatched CVE (medium severity)
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • High percentage of outputs not properly escaped
Vulnerabilities
1 published

Smart Related Products – AI-Inspired Recommendations for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-60160medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Smart Related Products <= 2.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 26, 2025Unpatched
Version History

Smart Related Products – AI-Inspired Recommendations for WooCommerce Release Timeline

v2.0.8Current1 CVE
v2.0.71 CVE
v2.0.61 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.1.91 CVE
v1.1.81 CVE
v1.1.71 CVE
v1.1.61 CVE
Code Analysis
Analyzed Mar 16, 2026

Smart Related Products – AI-Inspired Recommendations for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
50 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped56 total outputs
Attack Surface

Smart Related Products – AI-Inspired Recommendations for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ST_WOO_AI_REL_PRODUCTS] include\shortcode.php:160
WordPress Hooks 22
actionactivate_pluginai-related-products.php:44
actionadmin_noticesai-related-products.php:104
actioninitai-related-products.php:108
actionadmin_enqueue_scriptsinclude\core.php:17
actionwp_enqueue_scriptsinclude\core.php:18
actionactivated_plugininclude\core.php:20
actionelementor/widgets/widgets_registeredinclude\core.php:22
actionwp_loadedinclude\functions.php:19
actionwp_loadedinclude\functions.php:21
filterwoocommerce_product_related_products_headinginclude\functions.php:30
filterwoocommerce_output_related_products_argsinclude\functions.php:39
filterwoocommerce_related_productsinclude\functions.php:42
filterquery_loop_block_query_varsinclude\functions.php:43
filterrender_blockinclude\functions.php:51
actionwoocommerce_after_cartinclude\functions.php:54
actionadmin_menuinclude\setting.php:35
actionadmin_initinclude\setting.php:36
actioninitinclude\shortcode.php:27
actionst_woo_ai_rel_products_shortcode_open_actioninclude\structure.php:14
actionst_woo_ai_rel_products_shortcode_open_actioninclude\structure.php:15
actionst_woo_ai_rel_products_shortcode_close_actioninclude\structure.php:18
actionst_woo_ai_rel_products_shortcode_close_actioninclude\structure.php:19
Maintenance & Trust

Smart Related Products – AI-Inspired Recommendations for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version5.6
Downloads63K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

Smart Related Products – AI-Inspired Recommendations for WooCommerce Developer Profile

sharkthemes

27 plugins · 5K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smart Related Products – AI-Inspired Recommendations for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-related-products/assets/css/style.css/wp-content/plugins/ai-related-products/assets/css/admin.css
Version Parameters
ai-related-products/assets/css/style.css?ver=ai-related-products/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
st_woo_ai_rel_productsai-related-products-container
HTML Comments
Smart Related Products ShortcodeDefault shortcode:Shortcode with atts:no of columns layout+3 more
Data Attributes
data-columndata-cart_refdata-no_of_productsdata-sort
Shortcode Output
[ST_WOO_AI_REL_PRODUCTS][ST_WOO_AI_REL_PRODUCTS column="3" cart_ref="true" no_of_products="6" orderby="date"]
FAQ

Frequently Asked Questions about Smart Related Products – AI-Inspired Recommendations for WooCommerce