Customer Reports for WC Security & Risk Analysis

wordpress.org/plugins/customer-reports-for-wc

Displays summarised WooCommerce order information by individual customers in a more friendly table view.

0 active installs v1.0.0 PHP + WP 4.7+ Updated Dec 10, 2024
customerreportwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Customer Reports for WC Safe to Use in 2026?

Generally Safe

Score 92/100

Customer Reports for WC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "customer-reports-for-wc" v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points, including AJAX handlers, REST API routes, shortcodes, and cron events, significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by exclusively utilizing prepared statements for its SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. The lack of any recorded vulnerabilities in its history further bolsters this positive assessment.

However, a notable concern arises from the output escaping. With 45% of outputs properly escaped, a substantial 55% remain unescaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress environment. While the plugin has no other obvious security flaws according to this analysis, this unescaped output is a critical area that requires immediate attention. The absence of capability checks and nonce checks, while not directly causing a deduction without associated entry points, suggests a lack of defense-in-depth that could become a weakness if new entry points are introduced in future versions.

In conclusion, the plugin has a solid foundation with no critical code-level vulnerabilities detected and no known past exploits. The most pressing issue is the insufficient output escaping, which presents a clear risk of XSS. Addressing this would significantly enhance the plugin's overall security. The absence of other common vulnerability patterns in its history is a positive indicator of past development diligence, but the output escaping flaw highlights the need for continued vigilance and thorough code review.

Key Concerns

  • Output escaping is insufficient (55% unescaped)
Vulnerabilities
None known

Customer Reports for WC Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Customer Reports for WC Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

45% escaped20 total outputs
Attack Surface

Customer Reports for WC Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedincludes\class-customer-reports-for-wc.php:133
actionadmin_enqueue_scriptsincludes\class-customer-reports-for-wc.php:148
actionadmin_enqueue_scriptsincludes\class-customer-reports-for-wc.php:149
actionplugins_loadedincludes\class-customer-reports-for-wc.php:150
actionadmin_menuincludes\class-customer-reports-for-wc.php:151
Maintenance & Trust

Customer Reports for WC Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 10, 2024
PHP min version
Downloads683

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Customer Reports for WC Developer Profile

WpExpertPlugins

2 plugins · 1K total installs

75
trust score
Avg Security Score
81/100
Avg Patch Time
67 days
View full developer profile
Detection Fingerprints

How We Detect Customer Reports for WC

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/customer-reports-for-wc/assets/css/custom-admin-style.css/wp-content/plugins/customer-reports-for-wc/assets/js/custom-admin-script.js
Script Paths
/wp-content/plugins/customer-reports-for-wc/assets/js/custom-admin-script.js
Version Parameters
customer-reports-for-wc/assets/css/custom-admin-style.css?ver=customer-reports-for-wc/assets/js/custom-admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
woo_customer_info
Data Attributes
data-id
FAQ

Frequently Asked Questions about Customer Reports for WC