autoSKU for WooCommerce Variable Products Security & Risk Analysis

wordpress.org/plugins/autosku-for-woocommerce-variable-products

Automatically assign unique SKU to all your product variations, adding a letter (a, b, c, ...) to the main product SKU.

10 active installs v0.2.0 PHP + WP 3.8+ Updated Oct 4, 2018
autoskuldavskuwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is autoSKU for WooCommerce Variable Products Safe to Use in 2026?

Generally Safe

Score 85/100

autoSKU for WooCommerce Variable Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of the 'autosku-for-woocommerce-variable-products' plugin version 0.2.0 reveals a seemingly strong security posture with no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in zero attack surface points. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and no recorded vulnerabilities in its history are positive indicators. The use of prepared statements for SQL queries is also a best practice. However, a significant concern is the complete lack of output escaping, with 100% of outputs being unescaped. This presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data, if not properly sanitized before being displayed, can be injected with malicious scripts. The absence of nonce and capability checks on any potential entry points, though currently zero, is a weakness that would become a critical risk if any new entry points are introduced in future versions without adequate security measures. In conclusion, while the plugin has a clean slate regarding known vulnerabilities and attack vectors, the critical oversight in output escaping is a major flaw that needs immediate attention.

Key Concerns

  • Unescaped output identified
  • Missing nonce checks on potential entry points
  • Missing capability checks on potential entry points
Vulnerabilities
None known

autoSKU for WooCommerce Variable Products Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

autoSKU for WooCommerce Variable Products Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

autoSKU for WooCommerce Variable Products Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedautosku.php:22
actionedit_form_advancedautosku.php:52
Maintenance & Trust

autoSKU for WooCommerce Variable Products Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedOct 4, 2018
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

autoSKU for WooCommerce Variable Products Developer Profile

labdav

4 plugins · 5K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect autoSKU for WooCommerce Variable Products

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/autosku-for-woocommerce-variable-products/autosku.php

HTML / DOM Fingerprints

CSS Classes
assegnaSku
JS Globals
assegnaSku
FAQ

Frequently Asked Questions about autoSKU for WooCommerce Variable Products