{eac}SoftwareRegistry Subscriptions for WooCommerce Security & Risk Analysis

wordpress.org/plugins/eacsoftwareregistry-subscription-webhooks

Adds a custom Webhook topic to WooCommerrce Webhooks for subscription updates; adds subscription and product data to WooCommerce order Webhooks.

0 active installs v2.1.6 PHP 7.4+ WP 5.8+ Updated Jul 24, 2025
subscriptionssumo-subscriptionswoocommerce-subscriptionswoocommerce-webhookseacsoftwareregistry
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is {eac}SoftwareRegistry Subscriptions for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

{eac}SoftwareRegistry Subscriptions for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The eacsoftwareregistry-subscription-webhooks plugin v2.1.6 demonstrates a strong security posture in several key areas based on the provided static analysis. The absence of any reported CVEs and the fact that there are no currently unpatched vulnerabilities is a significant positive indicator. Furthermore, the code analysis reveals a clean slate regarding dangerous functions, SQL injection risks (100% prepared statements), file operations, and external HTTP requests. The fact that there are no identified taint flows with unsanitized paths is also commendable.

However, the analysis does highlight some areas for potential improvement. The complete lack of nonce checks and capability checks across all entry points (even though the attack surface is currently zero) presents a potential future risk. If the plugin were to gain additional features that introduce AJAX handlers, REST API routes, or shortcodes without proper authentication and authorization, these could become significant vulnerabilities. The 78% output escaping rate, while good, still leaves room for improvement, as unescaped output can lead to cross-site scripting (XSS) vulnerabilities. The vulnerability history being completely empty could indicate a well-maintained plugin, or it could simply mean that no vulnerabilities have been discovered or reported yet.

Overall, the plugin appears to be developed with security in mind, particularly regarding data handling and preventing common server-side attacks. The lack of historical vulnerabilities is a positive sign. The main area for caution is the foundational security mechanisms (nonces, capabilities) which are entirely absent. This means that if the plugin's functionality expands, the responsibility will fall on future development to ensure these are implemented correctly to avoid introducing new attack vectors.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Unescaped output present
Vulnerabilities
None known

{eac}SoftwareRegistry Subscriptions for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

{eac}SoftwareRegistry Subscriptions for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped9 total outputs
Attack Surface

{eac}SoftwareRegistry Subscriptions for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionbefore_woocommerce_initeacSoftwareRegistry_Subscription_Webhooks.php:54
actionadmin_initeacSoftwareRegistry_Subscription_Webhooks.php:61
actionwoocommerce_webhook_optionseacSoftwareRegistry_Subscription_Webhooks.php:68
actionwoocommerce_webhook_options_saveeacSoftwareRegistry_Subscription_Webhooks.php:71
actioniniteacSoftwareRegistry_Subscription_Webhooks.php:74
actionplugins_loadedeacSoftwareRegistry_Subscription_Webhooks.php:79
filterwoocommerce_webhook_topicseacSoftwareRegistry_Subscription_Webhooks.php:82
actionwoocommerce_subscription_status_updatedeacSoftwareRegistry_Subscription_Webhooks.php:98
actionsumosubscriptions_subscription_createdeacSoftwareRegistry_Subscription_Webhooks.php:104
actionsumosubscriptions_subscription_resumedeacSoftwareRegistry_Subscription_Webhooks.php:109
actionsumosubscriptions_subscription_is_switchedeacSoftwareRegistry_Subscription_Webhooks.php:114
actionsumosubscriptions_subscription_expiredeacSoftwareRegistry_Subscription_Webhooks.php:123
actionsumosubscriptions_active_subscriptioneacSoftwareRegistry_Subscription_Webhooks.php:125
actionsumosubscriptions_pause_subscriptioneacSoftwareRegistry_Subscription_Webhooks.php:126
actionsumosubscriptions_cancel_subscriptioneacSoftwareRegistry_Subscription_Webhooks.php:127
filterwoocommerce_webhook_payloadeacSoftwareRegistry_Subscription_Webhooks.php:131
actionwoocommerce_webhook_deliveryeacSoftwareRegistry_Subscription_Webhooks.php:134
Maintenance & Trust

{eac}SoftwareRegistry Subscriptions for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 24, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

{eac}SoftwareRegistry Subscriptions for WooCommerce Developer Profile

Kevin Burkholder

6 plugins · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect {eac}SoftwareRegistry Subscriptions for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eacsoftwareregistry-subscription-webhooks/eacsoftwareregistry-subscription-webhooks.php/wp-content/plugins/eacsoftwareregistry-subscription-webhooks/eacsoftwareregistry-subscription-webhooks.php
Version Parameters
eacsoftwareregistry-subscription-webhooks/eacsoftwareregistry-subscription-webhooks.php?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Append related subscriptions to orders --><!-- Append related subscriptions to renewals --><!-- Append product meta data to all orders -->
Data Attributes
checked=checked
FAQ

Frequently Asked Questions about {eac}SoftwareRegistry Subscriptions for WooCommerce