Choose Your Best Selling Products Security & Risk Analysis

wordpress.org/plugins/choose-your-best-selling-products

A WordPress plugin to display top selling products with flexible settings for manual or automated product selection.

20 active installs v1.0.1 PHP 7.2+ WP 5.2+ Updated May 8, 2025
best-selling-productsblocksgutenbergproduct-gridwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Choose Your Best Selling Products Safe to Use in 2026?

Generally Safe

Score 100/100

Choose Your Best Selling Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "choose-your-best-selling-products" v1.0.1 plugin exhibits a generally good security posture with several positive indicators. Notably, the absence of dangerous functions, file operations, external HTTP requests, and the adherence to prepared statements for all SQL queries are strong security practices. The plugin also demonstrates 100% output escaping, which is crucial for preventing cross-site scripting vulnerabilities. The clean vulnerability history with no recorded CVEs further suggests a well-maintained and secure codebase.

However, the analysis reveals a significant concern regarding its attack surface. There is one unprotected REST API route. This lack of permission callback means that any unauthenticated user could potentially interact with this endpoint, opening the door for unauthorized actions or information disclosure. While taint analysis shows no issues, the presence of an unprotected entry point is a critical weakness that needs immediate attention. The plugin's strength lies in its internal code hygiene, but its external interface has a clear vulnerability.

In conclusion, while the plugin's internal code is commendably secure, the unprotected REST API route presents a substantial risk. This single, unauthenticated entry point could be exploited to compromise the site's integrity or data. Addressing this specific vulnerability should be the top priority to ensure the plugin's overall security.

Key Concerns

  • Unprotected REST API route
Vulnerabilities
None known

Choose Your Best Selling Products Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Choose Your Best Selling Products Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface
1 unprotected

Choose Your Best Selling Products Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/cbsp/v1/products/includes\CbspWCRestApi.php:57
WordPress Hooks 6
actionwp_enqueue_scriptsincludes\CbspAssets.php:26
actionwp_enqueue_scriptsincludes\CbspAssets.php:27
actioninitincludes\CbspAssets.php:32
filterblock_categories_allincludes\CbspBlocks.php:32
actioninitincludes\CbspWCRestApi.php:28
actionrest_api_initincludes\CbspWCRestApi.php:29
Maintenance & Trust

Choose Your Best Selling Products Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 8, 2025
PHP min version7.2
Downloads900

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Choose Your Best Selling Products Developer Profile

veeraj

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Choose Your Best Selling Products

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/choose-your-best-selling-products/assets/src/library/css/bootstrap.min.css/wp-content/plugins/choose-your-best-selling-products/assets/src/css/blocks.css/wp-content/plugins/choose-your-best-selling-products/assets/src/library/js/bootstrap.min.js/wp-content/plugins/choose-your-best-selling-products/assets/build/js/blocks.js
Script Paths
/wp-content/plugins/choose-your-best-selling-products/assets/src/library/js/bootstrap.min.js/wp-content/plugins/choose-your-best-selling-products/assets/build/js/blocks.js
Version Parameters
choose-your-best-selling-products/assets/src/library/css/bootstrap.min.css?ver=choose-your-best-selling-products/assets/src/css/blocks.css?ver=choose-your-best-selling-products/assets/src/library/js/bootstrap.min.js?ver=choose-your-best-selling-products/assets/build/js/blocks.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-cbsp-best-selling-products
JS Globals
cbspProductData
REST Endpoints
/cbsp/v1/products/
FAQ

Frequently Asked Questions about Choose Your Best Selling Products