Comparis – Price comparison system (WooCommerce) Security & Risk Analysis

wordpress.org/plugins/comparis-price-comparison-system-woocommerce

Compare woocommerce products into your WordPress website.

10 active installs v1.0.0 PHP + WP 3.8+ Updated Mar 31, 2015
brandscompareecommercewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Comparis – Price comparison system (WooCommerce) Safe to Use in 2026?

Generally Safe

Score 85/100

Comparis – Price comparison system (WooCommerce) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin "comparis-price-comparison-system-woocommerce" v1.0.0 exhibits several concerning security weaknesses despite a lack of reported past vulnerabilities. The static analysis reveals a significant attack surface concentrated in AJAX handlers, with both identified handlers lacking authentication checks. This presents a direct pathway for unauthenticated users to trigger plugin functionality, potentially leading to unintended actions or information disclosure.

While the plugin avoids some common pitfalls like dangerous functions or direct file operations, its output escaping is poor, with only a third of outputs properly escaped. This significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the user's browser. The absence of nonce checks on the unprotected AJAX handlers further exacerbates this risk. The vulnerability history showing no known CVEs is a positive sign, but it does not negate the immediate risks identified in the code. The plugin's overall security posture is weak due to the exposed attack surface and inadequate input/output validation.

Key Concerns

  • AJAX handlers without auth checks
  • Poor output escaping (33% proper)
  • No nonce checks
Vulnerabilities
None known

Comparis – Price comparison system (WooCommerce) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Comparis – Price comparison system (WooCommerce) Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Comparis – Price comparison system (WooCommerce) Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
8 prepared
Unescaped Output
31
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

73% prepared11 total queries

Output Escaping

33% escaped46 total outputs
Attack Surface
2 unprotected

Comparis – Price comparison system (WooCommerce) Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_uou_comparis_searchincludes\class-ucp-ajax.php:22
noprivwp_ajax_uou_comparis_searchincludes\class-ucp-ajax.php:23
WordPress Hooks 21
actionplugins_loadedcomparis-plugin.php:54
actionwp_enqueue_scriptscomparis-plugin.php:56
actionadmin_enqueue_scriptscomparis-plugin.php:57
filtertemplate_includecomparis-plugin.php:60
filterwc_get_template_partcomparis-plugin.php:63
filterwoocommerce_locate_templatecomparis-plugin.php:66
filterwoocommerce_output_related_products_argscomparis-plugin.php:68
actionadmin_noticescomparis-plugin.php:270
filtermanage_edit-product_cat_columnsincludes\class-ucp-post-type.php:111
filtermanage_product_cat_custom_columnincludes\class-ucp-post-type.php:113
filtermanage_edit-brand_columnsincludes\class-ucp-post-type.php:130
filtermanage_brand_custom_columnincludes\class-ucp-post-type.php:134
actiondo_meta_boxesincludes\class-ucp-post-type.php:138
filterenter_title_hereincludes\class-ucp-post-type.php:139
actioninitincludes\class-ucp-router.php:21
filterquery_varsincludes\class-ucp-router.php:22
filtertemplate_includeincludes\class-ucp-router.php:23
actionucp_filter_underscore_templateincludes\ucp-functions.php:80
actionuou_theme_wrapper_startincludes\ucp-functions.php:160
actionuou_theme_wrapper_endincludes\ucp-functions.php:181
filterwp_titleincludes\ucp-functions.php:353
Maintenance & Trust

Comparis – Price comparison system (WooCommerce) Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedMar 31, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Comparis – Price comparison system (WooCommerce) Developer Profile

uouapps

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Comparis – Price comparison system (WooCommerce)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/bootstrap.css/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/font-awesome.min.css/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/style.css/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/responsive.css/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/script.js/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/pagination.js/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/comparis-ajax.js/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/underscore-min.js+8 more
Script Paths
/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/underscore-min.js/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/typeahead.bundle.js/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/maplace.min.js/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/script.js/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/pagination.js/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/comparis-ajax.js+3 more
Version Parameters
/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/bootstrap.css?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/font-awesome.min.css?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/style.css?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/responsive.css?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/script.js?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/pagination.js?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/comparis-ajax.js?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/underscore-min.js?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/typeahead.bundle.js?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/maplace.min.js?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/twentythirteen.css?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/twentyfourteen.css?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/css/fontawesome-iconpicker.css?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/fontawesome-iconpicker.js?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/admin_script.js?ver=/wp-content/plugins/comparis-price-comparison-system-woocommerce/assets/js/gps_converter.js?ver=

HTML / DOM Fingerprints

CSS Classes
ucp-related-products
Data Attributes
data-toggle="tooltip"
JS Globals
ajax_object
FAQ

Frequently Asked Questions about Comparis – Price comparison system (WooCommerce)