C4D Woo Filter Security & Risk Analysis

wordpress.org/plugins/c4d-woo-filter

C4D Woo Filter - create filter by ajax for WooCommerce category

10 active installs v1.0.7 PHP + WP 3.3+ Updated Jul 5, 2019
woocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is C4D Woo Filter Safe to Use in 2026?

Generally Safe

Score 85/100

C4D Woo Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The c4d-woo-filter plugin version 1.0.7 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and a complete reliance on prepared statements for SQL queries are all positive indicators. Furthermore, the plugin demonstrates good practices by not bundling external libraries, which can often introduce vulnerabilities. The lack of any recorded vulnerabilities in its history further supports this positive assessment, suggesting a history of stable and secure development.

However, there are areas that warrant attention and potential concern. The most significant gap identified is the complete absence of nonce checks and capability checks. This means that potentially sensitive actions, particularly those exposed through its 5 shortcodes, could be vulnerable to Cross-Site Request Forgery (CSRF) attacks if these shortcodes perform any privileged operations or modify data. Additionally, while 77% of output is properly escaped, the remaining 23% of unescaped output presents a risk of Cross-Site Scripting (XSS) vulnerabilities. Taint analysis results are absent, making it impossible to assess the risk of data being improperly handled through insecure code paths, though the lack of raw SQL and dangerous functions might contribute to this absence.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • Unescaped output (23%)
Vulnerabilities
None known

C4D Woo Filter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

C4D Woo Filter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

77% escaped30 total outputs
Attack Surface

C4D Woo Filter Attack Surface

Entry Points5
Unprotected0

Shortcodes 5

[c4d-woo-filter] includes\shortcodes.php:3
[c4d-woo-filter-soft] includes\shortcodes.php:4
[c4d-woo-filter-price] includes\shortcodes.php:5
[c4d-woo-filter-tax] includes\shortcodes.php:6
[c4d-woo-filter-tag] includes\shortcodes.php:7
WordPress Hooks 12
actionadmin_enqueue_scriptsc4d-woo-filter.php:14
actionwp_enqueue_scriptsc4d-woo-filter.php:15
actionadmin_enqueue_scriptsc4d-woo-filter.php:16
actionc4d-plugin-manager-sectionc4d-woo-filter.php:17
filterplugin_row_metac4d-woo-filter.php:18
filterbody_classc4d-woo-filter.php:19
actionwoocommerce_before_shop_loopincludes\hook.php:2
actionwoocommerce_close_shop_loopincludes\hook.php:3
actionwoocommerce_shortcode_before_products_loopincludes\hook.php:4
actionwoocommerce_shortcode_after_products_loopincludes\hook.php:5
actionwoocommerce_shortcode_products_queryincludes\shortcodes.php:10
actionwidgets_initincludes\widgets.php:75
Maintenance & Trust

C4D Woo Filter Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJul 5, 2019
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

C4D Woo Filter Developer Profile

coffee4dev

18 plugins · 400 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect C4D Woo Filter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/c4d-woo-filter/assets/default.js/wp-content/plugins/c4d-woo-filter/assets/default.css/wp-content/plugins/c4d-woo-filter/assets/admin.js/wp-content/plugins/c4d-woo-filter/assets/admin.css
Script Paths
/wp-content/plugins/c4d-woo-filter/assets/default.js/wp-content/plugins/c4d-woo-filter/assets/admin.js
Version Parameters
c4d-woo-filter/assets/default.js?ver=c4d-woo-filter/assets/default.css?ver=c4d-woo-filter/assets/admin.js?ver=c4d-woo-filter/assets/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
c4d-woo-filterc4w-woo-filter-mainc4d-woo-filter-template-tagc4d-woo-filter-template-taxc4d-woo-filter-load-more-active
Data Attributes
data-c4d-woo-filter
JS Globals
c4d_plugin_manager
Shortcode Output
<div class="c4d-woo-filter c4w-woo-filter-main"><div class="c4d-woo-filter-template-tag"><div class="tagcloud"><div class="c4d-woo-filter-template-tax">
FAQ

Frequently Asked Questions about C4D Woo Filter