Extended Setup for WooCommerce – Customize your eCommerce Security & Risk Analysis

wordpress.org/plugins/extended-setup-for-woocommerce

WooCommerce Extended Setup is a powerful customizer for WooCommerce that helps you customize with no code.

10 active installs v1.0 PHP + WP 4.0+ Updated Unknown
commercee-commerceecommercewoocommercewordpress-ecommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Extended Setup for WooCommerce – Customize your eCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Extended Setup for WooCommerce – Customize your eCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "extended-setup-for-woocommerce" plugin v1.0 exhibits a mixed security posture. On the positive side, the static analysis reveals no apparent attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events, and all identified SQL queries use prepared statements. Furthermore, there's a record of at least one capability check, which is a fundamental security practice. The absence of known CVEs and a clean vulnerability history are also strong indicators of a well-maintained plugin.

However, a significant concern arises from the static analysis regarding output escaping. With 100% of the 25 identified outputs being improperly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis didn't reveal any unsanitized paths, the lack of output escaping means that any user-controlled data that finds its way into these outputs could potentially be exploited. The absence of nonce checks on potential entry points, though the attack surface is reported as zero, could become a concern if the plugin's functionality expands or is integrated in ways not immediately apparent from this analysis.

In conclusion, while the plugin has a clean vulnerability history and avoids common pitfalls like raw SQL queries and a broad attack surface, the pervasive issue of unescaped output is a critical weakness. This requires immediate attention to mitigate XSS risks. The plugin's strengths lie in its apparent limited attack surface and secure data handling for database operations, but its output sanitization practices need substantial improvement to ensure a robust security posture.

Key Concerns

  • All outputs are unescaped
  • No nonce checks found
Vulnerabilities
None known

Extended Setup for WooCommerce – Customize your eCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Extended Setup for WooCommerce – Customize your eCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped25 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
options_page (includes\admin\woocommerce-admin.php:40)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Extended Setup for WooCommerce – Customize your eCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 29
actionadmin_menuincludes\admin\woocommerce-admin.php:22
actionadmin_enqueue_scriptsincludes\admin\woocommerce-admin.php:36
actioninitwoocommerce-setup.php:42
filterwoocommerce_order_get_itemswoocommerce-setup.php:59
filterwoocommerce_order_get_itemswoocommerce-setup.php:67
filterwoocommerce_cart_totals_coupon_labelwoocommerce-setup.php:92
filterwoocommerce_coupons_enabledwoocommerce-setup.php:97
filterwc_product_sku_enabledwoocommerce-setup.php:102
filterwoocommerce_cart_shipping_method_full_labelwoocommerce-setup.php:107
filterwp_headwoocommerce-setup.php:112
filterwoocommerce_product_related_posts_relate_by_categorywoocommerce-setup.php:117
filterwoocommerce_product_related_posts_relate_by_tagwoocommerce-setup.php:122
filterwoocommerce_product_single_add_to_cart_textwoocommerce-setup.php:132
filterwoocommerce_product_tabswoocommerce-setup.php:136
filterwoocommerce_product_add_to_cart_textwoocommerce-setup.php:140
actionwoocommerce_after_shop_loop_itemwoocommerce-setup.php:146
filterwoocommerce_paypal_argswoocommerce-setup.php:148
actionwoocommerce_after_shop_loopwoocommerce-setup.php:153
filterpre_get_postswoocommerce-setup.php:158
filterwoocommerce_enqueue_styleswoocommerce-setup.php:163
actionadd_to_cart_redirectwoocommerce-setup.php:168
filterwoocommerce_free_price_htmlwoocommerce-setup.php:178
filterwoocommerce_package_rateswoocommerce-setup.php:183
filterloop_shop_per_pagewoocommerce-setup.php:188
filterloop_shop_columnswoocommerce-setup.php:193
actionwoocommerce_email_after_order_tablewoocommerce-setup.php:203
filterwoocommerce_paypal_iconwoocommerce-setup.php:208
actionwp_headwoocommerce-setup.php:214
actionwp_headwoocommerce-setup.php:216
Maintenance & Trust

Extended Setup for WooCommerce – Customize your eCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Extended Setup for WooCommerce – Customize your eCommerce Developer Profile

woocommercesetup

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Extended Setup for WooCommerce – Customize your eCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Extended Setup for WooCommerce – Customize your eCommerce