SKU generator for Woocommerce by ATR Security & Risk Analysis

wordpress.org/plugins/atr-random-sku-for-woocommerce

Generates custom SKUs for WooCommerce products automatically or on-demand, with flexible formatting options and duplicate checking.

100 active installs v2.0.1 PHP + WP 3.8+ Updated Jan 12, 2025
product-skuskusku-generatorwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SKU generator for Woocommerce by ATR Safe to Use in 2026?

Generally Safe

Score 92/100

SKU generator for Woocommerce by ATR has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'atr-random-sku-for-woocommerce' plugin v2.0.1 exhibits a mixed security posture. While it demonstrates good practices in avoiding dangerous functions, file operations, external requests, and utilizes prepared statements for all SQL queries, several critical concerns remain. The most significant issue is a single unprotected AJAX handler, representing the entire attack surface accessible without authentication. This, coupled with two high-severity taint flows indicating potential unsanitized data that could be exploited, presents a notable risk.

The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a history of secure development or a lack of public discovery of past vulnerabilities. However, this positive track record doesn't negate the immediate risks identified in the static analysis. The limited attack surface (one AJAX endpoint) is unfortunately unprotected, and the taint analysis points to potential pathways for malicious data injection or manipulation. Therefore, despite its clean history, the presence of an unprotected entry point and high-severity taint flows necessitates caution.

Key Concerns

  • Unprotected AJAX handler
  • High severity taint flows (2)
  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

SKU generator for Woocommerce by ATR Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SKU generator for Woocommerce by ATR Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
10
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

44% escaped18 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
settings_page (includes\class-atr-random-sku-for-woocommerce-settings.php:238)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

SKU generator for Woocommerce by ATR Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_atr_check_sku_actionincludes\class-atr-random-sku-for-woocommerce.php:125
WordPress Hooks 9
actioninitincludes\class-atr-random-sku-for-woocommerce-settings.php:45
actionadmin_initincludes\class-atr-random-sku-for-woocommerce-settings.php:48
actionadmin_menuincludes\class-atr-random-sku-for-woocommerce-settings.php:51
actionadmin_enqueue_scriptsincludes\class-atr-random-sku-for-woocommerce.php:109
actionadmin_enqueue_scriptsincludes\class-atr-random-sku-for-woocommerce.php:110
actioninitincludes\class-atr-random-sku-for-woocommerce.php:118
actionwoocommerce_product_options_inventory_product_dataincludes\class-atr-random-sku-for-woocommerce.php:121
actionadmin_footerincludes\class-atr-random-sku-for-woocommerce.php:124
actionsave_postincludes\class-atr-random-sku-for-woocommerce.php:127
Maintenance & Trust

SKU generator for Woocommerce by ATR Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 12, 2025
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

SKU generator for Woocommerce by ATR Developer Profile

yehudaT

7 plugins · 940 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SKU generator for Woocommerce by ATR

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atr-random-sku-for-woocommerce/assets/js/atr-random-sku-for-woocommerce.js
Version Parameters
/wp-content/plugins/atr-random-sku-for-woocommerce/assets/js/atr-random-sku-for-woocommerce.js?ver=

HTML / DOM Fingerprints

CSS Classes
auto_sku_messageoverwrite
HTML Comments
Check if the suggested sku exist in DB
Data Attributes
id="auto-sku"name="test_sku"id="test_sku0"id="test_sku1"class="overwrite"name="overwrite"
JS Globals
ATR_random_sku_for_Woocommerceatr_check_sku_action_javascript
REST Endpoints
/wp-json/atr-random-sku-for-woocommerce/v1/check
FAQ

Frequently Asked Questions about SKU generator for Woocommerce by ATR