
Commission Widget for Dokan Security & Risk Analysis
wordpress.org/plugins/commission-widget-for-dokanCommission Widget for Dokan displays the Vendor Commission on Dokan Vendor Dashboard.
Is Commission Widget for Dokan Safe to Use in 2026?
Generally Safe
Score 85/100Commission Widget for Dokan has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and a low number of entry points with proper authorization checks are positive indicators. The adherence to prepared statements for all SQL queries is a significant strength, mitigating the risk of SQL injection. Furthermore, the presence of nonce and capability checks on the AJAX handler demonstrates a commitment to secure handling of user actions.
However, a notable concern arises from the output escaping, where only 36% of outputs are properly escaped. This leaves a significant portion of the plugin's output vulnerable to cross-site scripting (XSS) attacks, which could be leveraged by an attacker to execute malicious scripts in a user's browser. The zero taint flows, while seemingly positive, might also indicate that the static analysis tools were not configured to analyze the specific types of flows present or that the plugin's functionality does not involve complex data handling that would trigger such flows. The lack of any recorded vulnerabilities in its history is a strong positive, suggesting a history of stable and secure development.
In conclusion, the "commission-widget-for-dokan" plugin demonstrates a solid foundation in secure coding practices, particularly concerning SQL and authentication. The primary area requiring immediate attention is the insufficient output escaping, which represents a tangible risk of XSS vulnerabilities. While the plugin has a clean vulnerability history, this doesn't negate the identified weaknesses in the current code.
Key Concerns
- Insufficient output escaping
Commission Widget for Dokan Security Vulnerabilities
Commission Widget for Dokan Code Analysis
Output Escaping
Commission Widget for Dokan Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
Commission Widget for Dokan Maintenance & Trust
Maintenance Signals
Community Trust
Commission Widget for Dokan Alternatives
Dokan Kits
dokan-kits
The ultimate toolkit to enhance and customize your Dokan-powered multivendor marketplace with powerful, easy-to-use features.
Dokan Vendor Dashboard
dokan-vendor-dashboard
THIS IS AN ADD-ON TO USE WITH DOKAN AND DOKAN PRO PLUGINS.
Dokan Vendor Info Hider – Hide Vendor info from Store-list and store page
dokan-vendor-info-hider
This plugin will help you to hide the informations of vendors on your marketplace.
Multi Vendor Marketplace B2B for WholesaleX Dokan
multi-vendor-marketplace-b2b-for-wholesalex-dokan
Synch WholesaleX and Dokan together to create a B2B Multi Vendor Marketplace in WooCommerce.
Migrate to WooCommerce Multivendor Marketplace
wc-multivendor-marketplace-migration
Migrate your WC Markerplace or WC Vendors Marketplace or Dokan Multivendor or WC Product Vendors store to WooCommerce Multivendor Marketplace (WCFM Ma …
Commission Widget for Dokan Developer Profile
3 plugins · 50 total installs
How We Detect Commission Widget for Dokan
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
commission-widget-dokan-installer-noticecommission-widget-dokan-installercommission_widget_dokan_install_dokan_lite