GRO Security & Risk Analysis

wordpress.org/plugins/grocerslist

GRO is a suite of tools for bloggers — monetize your site with paid memberships and Amazon deep links.

200 active installs v1.26.0 PHP 7.0+ WP 4.4+ Updated Jul 20, 2026
affiliateamazondeep-linksmembershipsmonetization
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GRO Safe to Use in 2026?

Generally Safe

Score 100/100

GRO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The grocerslist plugin v1.21.0 exhibits a generally good security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, or shortcodes with insufficient authentication checks, coupled with a significant number of capability checks and nonce checks, suggests a conscious effort to limit the attack surface and implement basic security measures. The high percentage of properly escaped outputs further contributes to a positive security outlook by mitigating common cross-site scripting (XSS) vulnerabilities.

However, the presence of 12 SQL queries, with 33% not using prepared statements, represents a potential risk for SQL injection vulnerabilities. While no specific taint flows or known CVEs are reported, this pattern of using raw SQL queries warrants caution. The existence of a single cron event, while not inherently insecure, could become a vector if not properly secured or if it interacts with other potentially vulnerable components. The plugin's clean vulnerability history is a strong positive indicator, suggesting a lack of past security issues.

In conclusion, grocerslist v1.21.0 shows strengths in its limited attack surface and output escaping. The primary concern lies in the non-prepared SQL queries, which could be exploited if an attacker can manipulate input leading to these queries. The low risk profile is bolstered by the lack of historical vulnerabilities, but vigilance is recommended regarding the SQL query practices.

Key Concerns

  • SQL queries without prepared statements
Vulnerabilities
None known

GRO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GRO Release Timeline

v1.26.0Current
v1.25.0
v1.24.0
v1.23.0
v1.22.1
v1.22.0
v1.21.0
v1.20.0
v1.19.0
v1.18.0
v1.17.0
v1.16.0
v1.15.0
v1.14.0
v1.13.0
v1.12.0
v1.11.0
v1.10.0
v1.9.0
v1.8.0
Code Analysis
Analyzed Mar 16, 2026

GRO Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
8 prepared
Unescaped Output
5
40 escaped
Nonce Checks
20
Capability Checks
11
File Operations
3
External Requests
12
Bundled Libraries
0

SQL Query Safety

67% prepared12 total queries

Output Escaping

89% escaped45 total outputs
Attack Surface

GRO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actionadmin_noticesgrocerslist.php:110
actionadmin_noticesgrocerslist.php:140
actioncategory_add_form_fieldsincludes\Admin\CategoryGating.php:13
actioncategory_edit_form_fieldsincludes\Admin\CategoryGating.php:14
actioncreated_categoryincludes\Admin\CategoryGating.php:15
actionedited_categoryincludes\Admin\CategoryGating.php:16
actionadd_meta_boxesincludes\Admin\PageGating.php:13
actionsave_postincludes\Admin\PageGating.php:14
actioninitincludes\Admin\PageGating.php:15
actionadd_meta_boxesincludes\Admin\PostGating.php:15
actionsave_postincludes\Admin\PostGating.php:16
actioninitincludes\Admin\PostGating.php:17
actionadmin_menuincludes\Admin\SettingsPage.php:16
filtershow_admin_barincludes\Frontend\ClientScripts.php:43
actionwp_enqueue_scriptsincludes\Frontend\ClientScripts.php:44
actionwp_headincludes\Frontend\ClientScripts.php:45
filterbody_classincludes\Frontend\ClientScripts.php:46
actionwp_footerincludes\Frontend\ClientScripts.php:48
actionmigration_visitor_run_asyncincludes\Plugin.php:40
filterwp_insert_post_dataincludes\Service\LinkRewriter.php:15
filterredirect_post_locationincludes\Service\LinkRewriter.php:44
filterthe_contentincludes\Support\ContentFilter.php:22

Scheduled Events 1

migration_visitor_run_async
Maintenance & Trust

GRO Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedJul 20, 2026
PHP min version7.0
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

GRO Developer Profile

GRO Engineering

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GRO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/grocerslist/admin-ui/dist/bundle.js
Script Paths
/wp-content/plugins/grocerslist/admin-ui/dist/bundle.js
Version Parameters
grocers-list-admin-ui?ver=

HTML / DOM Fingerprints

JS Globals
window.grocersList
FAQ

Frequently Asked Questions about GRO