Category collapser SEO for WooCommerce Security & Risk Analysis

wordpress.org/plugins/category-collapser-seo-for-woocommerce

Improve the SEO of your WooCommerce categories

40 active installs v1.0.1 PHP 5.6+ WP + Updated Apr 20, 2020
category-collapserwoocommerce-category-collapserwoocommerce-category-seowoocommerce-seo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Category collapser SEO for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Category collapser SEO for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "category-collapser-seo-for-woocommerce" plugin v1.0.1 exhibits a strong security posture in several key areas. The static analysis reveals no identified dangerous functions, no file operations, and no external HTTP requests, all of which are positive indicators. Furthermore, all SQL queries are performed using prepared statements, and there are no recorded vulnerabilities in its history. This suggests a generally well-developed and securely coded plugin with minimal known attack vectors.

However, a significant concern arises from the output escaping analysis, where only 23% of the 26 total outputs are properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as untrusted data displayed to users could be manipulated to inject malicious scripts. While the plugin has only one nonce check and one capability check, the lack of these checks on other potential entry points (which are currently zero, but could change with future updates) combined with the poor output escaping presents a notable weakness that could be exploited if new entry points are introduced or if the plugin's functionality is extended.

In conclusion, while the plugin demonstrates good practices in terms of database interactions and avoiding common risky operations, the poor output escaping is a critical flaw. The absence of any past vulnerabilities is a positive sign, but the current static analysis flags a substantial risk that needs immediate attention. Addressing the output escaping should be the top priority to mitigate potential XSS attacks.

Key Concerns

  • Poor output escaping (23% proper)
Vulnerabilities
None known

Category collapser SEO for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Category collapser SEO for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
6 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

23% escaped26 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<settings_page> (includes\settings_page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Category collapser SEO for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initcategory-collapse.php:18
actionadmin_noticescategory-collapse.php:22
actioninitcategory-collapse.php:52
actionwp_headcategory-collapse.php:72
actiontemplate_redirectincludes\main.php:28
actionwp_headincludes\main.php:32
actionwp_headincludes\main.php:33
actionadmin_menuincludes\settings.php:2
Maintenance & Trust

Category collapser SEO for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 20, 2020
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Category collapser SEO for WooCommerce Developer Profile

Camilo

5 plugins · 6K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Category collapser SEO for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/category-collapser-seo-for-woocommerce/assets/js/jquery.collapser.min.js
Script Paths
assets/js/jquery.collapser.min.js

HTML / DOM Fingerprints

CSS Classes
term-descriptionarchive-description
FAQ

Frequently Asked Questions about Category collapser SEO for WooCommerce