HexReport – Powerful report analytics for WooCommerce Security & Risk Analysis

wordpress.org/plugins/hexreport-sales-analytics-for-woocommerce

HexReport is a powerful report analytics WordPress plugin designed to give store owner insightful and real-time analytics of their store.

0 active installs v1.0.1 PHP 7.1+ WP 5.4+ Updated Aug 1, 2024
hexreportsales-report-for-woocommercesales-reportsstore-reportwoocommerce-reports
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HexReport – Powerful report analytics for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

HexReport – Powerful report analytics for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The hexreport-sales-analytics-for-woocommerce plugin version 1.0.1 exhibits a concerning security posture due to a significant number of unprotected entry points. While the code signals indicate good practices in areas like SQL query preparation and output escaping, the presence of three AJAX handlers without any authentication checks represents a substantial risk. This opens the door for unauthenticated users to interact with potentially sensitive functionalities, leading to unauthorized actions or information disclosure. The absence of any recorded vulnerability history, while seemingly positive, also means there's no established track record of the developer addressing security issues, which can be a double-edged sword. The lack of taint analysis flows is also notable, suggesting either a very simple codebase or a limitation in the analysis performed. Overall, the plugin has strong internal code hygiene but suffers from critical external security oversights that significantly elevate its risk profile.

Key Concerns

  • Unprotected AJAX handlers
  • Missing capability checks
Vulnerabilities
None known

HexReport – Powerful report analytics for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

HexReport – Powerful report analytics for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
37 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped38 total outputs
Attack Surface
3 unprotected

HexReport – Powerful report analytics for WooCommerce Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_total_sales_amountapp\Controllers\AjaxApiController.php:23
authwp_ajax_show_first_top_selling_product_monthly_dataapp\Controllers\AjaxApiController.php:24
authwp_ajax_get_top_two_selling_categories_namesapp\Controllers\AjaxApiController.php:25
WordPress Hooks 10
actionplugins_loadedapp\Controllers\AdminMenuController.php:21
actionadmin_menuapp\Controllers\AdminMenuController.php:37
actionadmin_noticesapp\Core\AdminNoticeManager.php:26
actionadmin_noticesapp\Core\AdminNoticeManager.php:28
actionadmin_noticesapp\Core\AdminNoticeManager.php:30
actionadmin_noticesapp\Core\AdminNoticeManager.php:32
actionadmin_enqueue_scriptsapp\Core\AssetsManager.php:28
actioninitapp\Core\DatabaseQuery.php:22
actionwpapp\Core\DatabaseQuery.php:23
actionbefore_woocommerce_inithexreport.php:40
Maintenance & Trust

HexReport – Powerful report analytics for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 1, 2024
PHP min version7.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

HexReport – Powerful report analytics for WooCommerce Developer Profile

wpHex

2 plugins · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HexReport – Powerful report analytics for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hexreport-sales-analytics-for-woocommerce/dist/assets/index.js/wp-content/plugins/hexreport-sales-analytics-for-woocommerce/dist/assets/index.css
Script Paths
/wp-content/plugins/hexreport-sales-analytics-for-woocommerce/dist/assets/index.js
Version Parameters
hexreport-sales-analytics-for-woocommerce/dist/assets/index.js?ver=hexreport-sales-analytics-for-woocommerce/dist/assets/index.css?ver=

HTML / DOM Fingerprints

Data Attributes
hexReportData
JS Globals
hexReportData
FAQ

Frequently Asked Questions about HexReport – Powerful report analytics for WooCommerce