
{eac}SoftwareRegistry Subscriptions for WooCommerce Security & Risk Analysis
wordpress.org/plugins/eacsoftwareregistry-subscription-webhooksAdds a custom Webhook topic to WooCommerrce Webhooks for subscription updates; adds subscription and product data to WooCommerce order Webhooks.
Is {eac}SoftwareRegistry Subscriptions for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100{eac}SoftwareRegistry Subscriptions for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The eacsoftwareregistry-subscription-webhooks plugin v2.1.6 demonstrates a strong security posture in several key areas based on the provided static analysis. The absence of any reported CVEs and the fact that there are no currently unpatched vulnerabilities is a significant positive indicator. Furthermore, the code analysis reveals a clean slate regarding dangerous functions, SQL injection risks (100% prepared statements), file operations, and external HTTP requests. The fact that there are no identified taint flows with unsanitized paths is also commendable.
However, the analysis does highlight some areas for potential improvement. The complete lack of nonce checks and capability checks across all entry points (even though the attack surface is currently zero) presents a potential future risk. If the plugin were to gain additional features that introduce AJAX handlers, REST API routes, or shortcodes without proper authentication and authorization, these could become significant vulnerabilities. The 78% output escaping rate, while good, still leaves room for improvement, as unescaped output can lead to cross-site scripting (XSS) vulnerabilities. The vulnerability history being completely empty could indicate a well-maintained plugin, or it could simply mean that no vulnerabilities have been discovered or reported yet.
Overall, the plugin appears to be developed with security in mind, particularly regarding data handling and preventing common server-side attacks. The lack of historical vulnerabilities is a positive sign. The main area for caution is the foundational security mechanisms (nonces, capabilities) which are entirely absent. This means that if the plugin's functionality expands, the responsibility will fall on future development to ensure these are implemented correctly to avoid introducing new attack vectors.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
- Unescaped output present
{eac}SoftwareRegistry Subscriptions for WooCommerce Security Vulnerabilities
{eac}SoftwareRegistry Subscriptions for WooCommerce Code Analysis
Output Escaping
{eac}SoftwareRegistry Subscriptions for WooCommerce Attack Surface
WordPress Hooks 17
Maintenance & Trust
{eac}SoftwareRegistry Subscriptions for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
{eac}SoftwareRegistry Subscriptions for WooCommerce Alternatives
Subscriptions for WooCommerce
subscriptions-for-woocommerce
With WooCommerce Subscription, turn your physical or online store into a WooCommerce product subscription store and avail recurring revenue.
Flexible Subscriptions
flexible-subscriptions
Meet Flexible Subscriptions for WooCommerce. The best & free plugin for recurring payments and subscriptions in WooCommerce.
Recurio – Ultimate Subscription Plugin for WooCommerce
recurio
A powerful and comprehensive WooCommerce subscription management plugin with advanced analytics, automated billing, and customer portal.
Autoship Cloud for WooCommerce Subscription Products
autoship-cloud
Use one plugin to automate repeat orders, product subscriptions, and scheduled deliveries for your WooCommerce subscriptions products.
TakBull For WooCommerce
takbull-gateway
Accept Credit Cards and Invoicing !
{eac}SoftwareRegistry Subscriptions for WooCommerce Developer Profile
6 plugins · 60 total installs
How We Detect {eac}SoftwareRegistry Subscriptions for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eacsoftwareregistry-subscription-webhooks/eacsoftwareregistry-subscription-webhooks.php/wp-content/plugins/eacsoftwareregistry-subscription-webhooks/eacsoftwareregistry-subscription-webhooks.phpeacsoftwareregistry-subscription-webhooks/eacsoftwareregistry-subscription-webhooks.php?ver=HTML / DOM Fingerprints
<!-- Append related subscriptions to orders --><!-- Append related subscriptions to renewals --><!-- Append product meta data to all orders -->checked=checked