
CM Custom Reports – Flexible reporting to track what matters most Security & Risk Analysis
wordpress.org/plugins/cm-custom-reportsGenerate custom reports and get efficient analytics for your site with the custom reports plugin. Filter data and create tailored reports.
Is CM Custom Reports – Flexible reporting to track what matters most Safe to Use in 2026?
Generally Safe
Score 99/100CM Custom Reports – Flexible reporting to track what matters most has a strong security track record. Known vulnerabilities have been patched promptly.
The "cm-custom-reports" v1.2.8 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and implements a significant number of nonce checks. However, a substantial concern arises from the attack surface, with 4 out of 9 entry points lacking authentication checks, specifically within its AJAX handlers. Furthermore, the output escaping mechanism is only 46% effective, indicating a potential for cross-site scripting (XSS) vulnerabilities, especially given the plugin's past history of a medium severity XSS vulnerability. While there are no currently unpatched CVEs and no critical taint flows, the combination of unprotected entry points and insufficient output sanitization presents a notable risk. The plugin's historical vulnerability, though resolved, combined with the identified weaknesses, suggests that careful monitoring and potential mitigation efforts for the exposed AJAX handlers are warranted.
Key Concerns
- 4 AJAX handlers without auth checks
- Only 46% of outputs properly escaped
- Medium severity vulnerability in history
- 1 unsanitized path in taint analysis
CM Custom Reports – Flexible reporting to track what matters most Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CM Custom Reports <= 1.2.7 - Reflected Cross-Site Scripting via 'date_from' and 'date_to' Parameters
CM Custom Reports – Flexible reporting to track what matters most Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CM Custom Reports – Flexible reporting to track what matters most Attack Surface
AJAX Handlers 5
Shortcodes 4
WordPress Hooks 26
Maintenance & Trust
CM Custom Reports – Flexible reporting to track what matters most Maintenance & Trust
Maintenance Signals
Community Trust
CM Custom Reports – Flexible reporting to track what matters most Alternatives
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
Sales Report for WooCommerce
sales-report-for-woocommerce
Sales Report for WooCommerce generates daily, weekly and monthly sales report
REPORTiT – Advanced Reporting for WooCommerce
ithemelandco-woo-report
Stop guessing. Grow your sales with powerful, easy-to-understand reports and analytics for WooCommerce.
Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting
webd-woocommerce-advanced-reporting-statistics
A comprehensive WordPress Plugin for Advanced WooCommerce Reporting, Product Sales Report, Statistics, Analytics & Forecasting Tool for Orders, Pr …
Smart Reporter For WooCommerce and WP eCommerce
smart-reporter-for-wp-e-commerce
A phenomenal plugin that solves all your business related issues, from business analysis to reporting on your WooCommerce and WordPress eCommerce site …
CM Custom Reports – Flexible reporting to track what matters most Developer Profile
19 plugins · 22K total installs
How We Detect CM Custom Reports – Flexible reporting to track what matters most
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cm-custom-reports/shared/classes/Labels.php/wp-content/plugins/cm-custom-reports/backend/classes/Settings.php/wp-content/plugins/cm-custom-reports/shared/cm-custom-reports-shared.php/wp-content/plugins/cm-custom-reports/package/cminds-free.php/wp-content/plugins/cm-custom-reports/backend/cm-custom-reports-backend.php/wp-content/plugins/cm-custom-reports/backend/classes/modules/GraphModule.phpHTML / DOM Fingerprints
data-cmcr-report-slugCMCR_Graph_ModuleCM_Custom_Reports