GS Brands for WooCommerce Security & Risk Analysis

wordpress.org/plugins/gs-woo-brands

Display WooCommerce product brands in Grid, Slider & more layouts with GS Brands for WooCommerce. Flexible, responsive & easy to use.

30 active installs v1.3.3 PHP 5.6+ WP 4.3+ Updated Sep 11, 2025
best-woocommerce-brands-pluginbrand-plugin-for-woocommercebrands-pluginwoocommerce-brands-pluginwoocommerce-product-brand-plugin
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 11, 2025
Safety Verdict

Is GS Brands for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

GS Brands for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 11, 2025Updated 6mo ago
Risk Assessment

The gs-woo-brands plugin v1.3.3 exhibits a generally good security posture with several strengths. It correctly utilizes prepared statements for all SQL queries and implements a reasonable number of nonce and capability checks across its entry points. The absence of dangerous functions and file operations is also positive. However, there are areas for improvement. The relatively low percentage of properly escaped output (61%) suggests potential for Cross-Site Scripting (XSS) vulnerabilities, which aligns with its vulnerability history. The presence of a single flow with an unsanitized path, while not classified as critical or high, warrants attention as it indicates a potential for injection-type vulnerabilities if not handled carefully. The plugin's vulnerability history shows a past medium-severity XSS vulnerability, indicating a pattern that needs continuous monitoring and vigilance. While no current unpatched vulnerabilities exist, the historical pattern and the static analysis findings on output escaping suggest a need for ongoing security reviews and updates.

Key Concerns

  • Low percentage of properly escaped output (61%)
  • Flow with unsanitized path found
  • Medium severity vulnerability in history
Vulnerabilities
1

GS Brands for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11746medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 11, 2025 Patched in 1.3.3 (1d)
Code Analysis
Analyzed Mar 16, 2026

GS Brands for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
70
109 escaped
Nonce Checks
4
Capability Checks
7
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

61% escaped179 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
gswcbr_review_notice_message (woocommerce-brand.php:835)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GS Brands for WooCommerce Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 1

authwp_ajax_gs_product_brand_settings_savewoocommerce-brand.php:152

Shortcodes 3

[brands_products] woocommerce-brand.php:530
[brands_carousal] woocommerce-brand.php:531
[product_brand] woocommerce-brand.php:532
WordPress Hooks 34
actionswitch_themeappsero\Insights.php:132
actionswitch_themeappsero\Insights.php:133
actionadmin_footerappsero\Insights.php:145
actionadmin_noticesappsero\Insights.php:162
actionadmin_initappsero\Insights.php:165
filtercron_schedulesappsero\Insights.php:171
actionadmin_menugs-common-pages\gs-plugins-common-pages.php:16
actionadmin_enqueue_scriptsgs-common-pages\gs-plugins-common-pages.php:17
actioninitwoocommerce-brand.php:34
actionadmin_initwoocommerce-brand.php:62
actionadmin_noticeswoocommerce-brand.php:84
actionin_admin_headerwoocommerce-brand.php:97
actionadmin_enqueue_scriptswoocommerce-brand.php:135
actionadmin_initwoocommerce-brand.php:136
actionadmin_initwoocommerce-brand.php:139
actioninitwoocommerce-brand.php:143
actioninitwoocommerce-brand.php:147
actionwp_headwoocommerce-brand.php:148
actionwp_footerwoocommerce-brand.php:149
actionwp_enqueue_scriptswoocommerce-brand.php:150
actionadmin_menuwoocommerce-brand.php:151
actionwoocommerce_archive_descriptionwoocommerce-brand.php:153
filtertemplate_includewoocommerce-brand.php:154
actionwoocommerce_after_shop_loop_item_titlewoocommerce-brand.php:157
actionwoocommerce_shop_loop_item_titlewoocommerce-brand.php:159
actionwoocommerce_after_shop_loop_itemwoocommerce-brand.php:161
actionwoocommerce_before_single_productwoocommerce-brand.php:171
actionwoocommerce_single_product_summarywoocommerce-brand.php:174
actiongswcbr_brand_add_form_fieldswoocommerce-brand.php:653
actiongswcbr_brand_edit_form_fieldswoocommerce-brand.php:654
actioncreated_termwoocommerce-brand.php:655
actionedit_termwoocommerce-brand.php:656
actionadmin_noticeswoocommerce-brand.php:828
filterplugin_row_metawoocommerce-brand.php:1035
Maintenance & Trust

GS Brands for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 11, 2025
PHP min version5.6
Downloads6K

Community Trust

Rating86/100
Number of ratings6
Active installs30
Alternatives

GS Brands for WooCommerce Alternatives

No alternatives data available yet.

Developer Profile

GS Brands for WooCommerce Developer Profile

GS Plugins

19 plugins · 41K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
173 days
View full developer profile
Detection Fingerprints

How We Detect GS Brands for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gs-woo-brands/assets/css/gs-product-brand.css/wp-content/plugins/gs-woo-brands/assets/js/gs-product-brand.js/wp-content/plugins/gs-woo-brands/assets/js/admin-gs-product-brand.js/wp-content/plugins/gs-woo-brands/gs-common-pages/assets/css/gs-brands-common-pages.css/wp-content/plugins/gs-woo-brands/gs-common-pages/assets/js/gs-brands-common-pages.js
Script Paths
/wp-content/plugins/gs-woo-brands/assets/js/gs-product-brand.js/wp-content/plugins/gs-woo-brands/assets/js/admin-gs-product-brand.js/wp-content/plugins/gs-woo-brands/gs-common-pages/assets/js/gs-brands-common-pages.js
Version Parameters
gs-product-brand.css?ver=gs-product-brand.js?ver=admin-gs-product-brand.js?ver=gs-brands-common-pages.css?ver=gs-brands-common-pages.js?ver=

HTML / DOM Fingerprints

CSS Classes
gs-product-brand-widgetgs-product-brand-termgs-product-brand-single
Data Attributes
data-brand-slugdata-brand-iddata-brand-name
JS Globals
gs_product_brand_vars
FAQ

Frequently Asked Questions about GS Brands for WooCommerce