Auto Product Restock Security & Risk Analysis

wordpress.org/plugins/auto-product-restock

A simple way to automatically restock products in WooCommerce daily.

20 active installs v1.01 PHP 5.6+ WP 5.1+ Updated Apr 9, 2020
ecommercerestockwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Auto Product Restock Safe to Use in 2026?

Generally Safe

Score 85/100

Auto Product Restock has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'auto-product-restock' plugin v1.01 demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, properly escaped output, and the exclusive use of prepared statements for SQL queries are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of secure development or diligent patching by its maintainers. The attack surface is also commendably low, with no identified AJAX handlers, REST API routes, or shortcodes that present an immediate entry point for attackers.

However, there are some areas that warrant attention despite the overall positive assessment. The lack of any nonce checks or capability checks across the analyzed code is a significant concern. While the current attack surface is reported as zero, this absence of checks means that if new entry points were to be introduced in future versions, they might be vulnerable to unauthorized access or actions. The presence of a single cron event without explicit authorization checks also represents a potential, albeit currently unexploited, risk. The absence of taint analysis data is not necessarily a negative, but it means that potential complex data flow vulnerabilities cannot be assessed from this report.

In conclusion, 'auto-product-restock' v1.01 appears to be a well-developed plugin with good internal code security practices concerning SQL and output handling. Its vulnerability history is also clean. The primary weakness lies in the foundational security checks like nonces and capability checks, which are crucial for preventing unauthorized operations, especially as the plugin evolves. Addressing these would significantly strengthen its overall security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Cron event without explicit auth check
Vulnerabilities
None known

Auto Product Restock Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Auto Product Restock Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Auto Product Restock Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwoocommerce_product_options_stock_statusapr.php:14
actionwoocommerce_process_product_metaapr.php:56
actioninitapr.php:83
actioninitapr.php:93
actionadmin_enqueue_scriptsapr.php:143

Scheduled Events 1

nwp_apr_reset_stock_daily
Maintenance & Trust

Auto Product Restock Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 9, 2020
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Auto Product Restock Developer Profile

nerdywp

2 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto Product Restock

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-product-restock/apr.js

HTML / DOM Fingerprints

CSS Classes
nwp_apr_option_metas
Data Attributes
nwp_apr_restock_this_productnwp_apr_restock_amountnwp_apr_restock_time
FAQ

Frequently Asked Questions about Auto Product Restock