Convert Username to Customer Code for Woocommerce Security & Risk Analysis

wordpress.org/plugins/convert-username-to-customer-code-for-woocommerce

Sfrutta la funzione username trasformandolo in codice cliente. Attribuisci professionalità al tuo woocommerce.

0 active installs v1.0.1 PHP 5.2.4+ WP 4.9+ Updated Jan 31, 2021
codice-clientecustomer-codeusername-codewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Convert Username to Customer Code for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Convert Username to Customer Code for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "convert-username-to-customer-code-for-woocommerce" plugin version 1.0.1 exhibits a generally good security posture, with strong adherence to several WordPress security best practices. Notably, all SQL queries are executed using prepared statements, mitigating the risk of SQL injection. Furthermore, the majority of output is properly escaped, and the plugin does not make any external HTTP requests. The absence of any recorded vulnerabilities or CVEs in its history is also a positive indicator of its development quality and maintenance.

However, a significant concern arises from the identified attack surface. The plugin exposes one AJAX handler, and critically, this handler lacks authentication checks. This means that any user, regardless of their logged-in status or capabilities, could potentially trigger this AJAX action. While the taint analysis shows no unsanitized flows, the unprotected entry point presents a direct pathway for potential abuse if the functionality it triggers can be exploited. The presence of only one nonce check and two capability checks, while present, is minimal given the unprotected AJAX handler.

In conclusion, while the plugin demonstrates strong foundations in secure coding practices like prepared statements and output escaping, the unprotected AJAX handler is a critical weakness that must be addressed. The lack of historical vulnerabilities is reassuring but does not negate the current risk posed by the exposed entry point. Prioritizing the securing of this AJAX handler is essential to improve the plugin's overall security.

Key Concerns

  • AJAX handler without authentication
  • Limited capability checks
  • Limited nonce checks
  • Some unescaped output detected
Vulnerabilities
None known

Convert Username to Customer Code for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Convert Username to Customer Code for Woocommerce Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Convert Username to Customer Code for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
4
16 escaped
Nonce Checks
1
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

80% escaped20 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
cutccfw_register_form (cutccfw-settings.php:33)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Convert Username to Customer Code for Woocommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_change_usernamecutccfw-settings.php:438
WordPress Hooks 25
actionadmin_noticesconvert-username-to-customer-code-for-woocommerce.php:37
filterwoocommerce_settings_tabs_arraycutccfw-admin-settings.php:8
actionwoocommerce_settings_tabs_cutccfwcutccfw-admin-settings.php:9
actionwoocommerce_update_options_cutccfwcutccfw-admin-settings.php:10
actionregister_formcutccfw-settings.php:28
actionregister_formcutccfw-settings.php:32
filterregistration_errorscutccfw-settings.php:53
actionuser_registercutccfw-settings.php:66
actionlogin_form_registercutccfw-settings.php:80
filtergettextcutccfw-settings.php:86
filtergettextcutccfw-settings.php:171
actionactivate_plugincutccfw-settings.php:221
actionwoocommerce_email_footercutccfw-settings.php:235
filtermanage_edit-shop_order_columnscutccfw-settings.php:241
actionmanage_shop_order_posts_custom_columncutccfw-settings.php:262
actionwoocommerce_admin_order_data_after_billing_addresscutccfw-settings.php:282
actionuser_registercutccfw-settings.php:309
filterpre_user_display_namecutccfw-settings.php:315
actionwoocommerce_register_form_startcutccfw-settings.php:332
filterwoocommerce_registration_errorscutccfw-settings.php:355
actionwoocommerce_created_customercutccfw-settings.php:370
actionwoocommerce_account_contentcutccfw-settings.php:393
filterwoocommerce_new_customer_datacutccfw-settings.php:398
actionadmin_enqueue_scriptscutccfw-settings.php:437
actionplugins_loadedcutccfw-settings.php:442
Maintenance & Trust

Convert Username to Customer Code for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedJan 31, 2021
PHP min version5.2.4
Downloads988

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Convert Username to Customer Code for Woocommerce Developer Profile

Roberto Bottalico

8 plugins · 230 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Convert Username to Customer Code for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/convert-username-to-customer-code-for-woocommerce/cutccfw-admin-settings.php/wp-content/plugins/convert-username-to-customer-code-for-woocommerce/cutccfw-settings.php/wp-content/plugins/convert-username-to-customer-code-for-woocommerce/js/script.js
Script Paths
/wp-content/plugins/convert-username-to-customer-code-for-woocommerce/js/script.js
Version Parameters
convert-username-to-customer-code-for-woocommerce/cutccfw-admin-settings.php?ver=convert-username-to-customer-code-for-woocommerce/cutccfw-settings.php?ver=convert-username-to-customer-code-for-woocommerce/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
notice-info
HTML Comments
<!-- Esci se l'accesso è diretto --><!-- Aggiungi il link dell'impostazione pagina del plugin --><!-- Ricorda che se vuoi, puoi modificare singolarmente ad ogni utente il proprio codice cliente. Basta accedere in modifica utente e potrai cambiarlo. Se invece vuoi disattivare delle funzioni che non ti interessano clicca qui per le impostazioni del plugin CONVERT USERNAME TO CUSTOMER CODE FOR WOOCOMMERCE. --><!-- Controlla se Woocommerce è attivo nel sito web -->+15 more
Data Attributes
page=wc-settings&tab=cutccfw
JS Globals
change_username
FAQ

Frequently Asked Questions about Convert Username to Customer Code for Woocommerce