AutoROICalc for WooCommerce Security & Risk Analysis

wordpress.org/plugins/autoroicalc-for-woocommerce

Optimize WooCommerce sales with insightful reporting. Track ROI, analyze order profitability, and boost marketing efficiency.

0 active installs v1.0.0 PHP 8.0+ WP 3.0.1+ Updated Unknown
cost-of-goodse-commerce-analyticsmarketing-insightsroiwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AutoROICalc for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

AutoROICalc for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "autoroicalc-for-woocommerce" plugin version 1.0.0 presents a generally positive security posture, with a notable absence of documented vulnerabilities and a clean taint analysis. The static analysis indicates a very small attack surface with no directly exposed entry points like AJAX handlers, REST API routes, or shortcodes that lack authentication. Furthermore, all identified output points are properly escaped, and there are no file operations or dangerous function calls detected. However, there are areas for concern. The plugin utilizes a single SQL query that does not employ prepared statements, which introduces a risk of SQL injection if the input feeding this query is not rigorously sanitized elsewhere. Additionally, the lack of nonce checks and capability checks on any potential (though currently unlisted) entry points is a significant gap. The single external HTTP request also warrants scrutiny to ensure it doesn't expose the site to risks from external services. While the plugin's history is clean and the code analysis shows good practices in output escaping and avoiding dangerous functions, the SQL query and the absence of authorization checks on any potential endpoints are weaknesses that need to be addressed for a truly robust security profile.

Key Concerns

  • SQL query without prepared statements
  • No nonce checks detected
  • No capability checks detected
  • External HTTP request without context
Vulnerabilities
None known

AutoROICalc for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AutoROICalc for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped2 total outputs
Attack Surface

AutoROICalc for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filterwoocommerce_settings_tabs_arrayadmin\class-auto-roi-calc-for-woocommerce-admin.php:55
actionwoocommerce_settings_tabs_auto_roi_calcadmin\class-auto-roi-calc-for-woocommerce-admin.php:56
actionwoocommerce_update_options_auto_roi_calcadmin\class-auto-roi-calc-for-woocommerce-admin.php:57
actionplugins_loadedincludes\class-auto-roi-calc-for-woocommerce.php:139
actionadmin_enqueue_scriptsincludes\class-auto-roi-calc-for-woocommerce.php:151
actionadmin_enqueue_scriptsincludes\class-auto-roi-calc-for-woocommerce.php:152
actionwp_enqueue_scriptsincludes\class-auto-roi-calc-for-woocommerce.php:164
actionwp_enqueue_scriptsincludes\class-auto-roi-calc-for-woocommerce.php:165
actionwoocommerce_checkout_create_orderpublic\class-auto-roi-calc-for-woocommerce-public.php:52
Maintenance & Trust

AutoROICalc for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedUnknown
PHP min version8.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AutoROICalc for WooCommerce Developer Profile

autoroicalc

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AutoROICalc for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/autoroicalc-for-woocommerce/admin/css/autoroicalc-for-woocommerce-admin.css/wp-content/plugins/autoroicalc-for-woocommerce/public/css/autoroicalc-for-woocommerce-public.css/wp-content/plugins/autoroicalc-for-woocommerce/public/js/autoroicalc-for-woocommerce-public.js
Script Paths
/wp-content/plugins/autoroicalc-for-woocommerce/admin/js/autoroicalc-for-woocommerce-admin.js/wp-content/plugins/autoroicalc-for-woocommerce/public/js/autoroicalc-for-woocommerce-public.js
Version Parameters
autoroicalc-for-woocommerce/admin/css/autoroicalc-for-woocommerce-admin.css?ver=autoroicalc-for-woocommerce/public/css/autoroicalc-for-woocommerce-public.css?ver=autoroicalc-for-woocommerce/admin/js/autoroicalc-for-woocommerce-admin.js?ver=autoroicalc-for-woocommerce/public/js/autoroicalc-for-woocommerce-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
autoroicalc-for-woocommerce-admin-cssautoroicalc-for-woocommerce-public-css
FAQ

Frequently Asked Questions about AutoROICalc for WooCommerce