HPOS Status Indicator for WooCommerce Security & Risk Analysis

wordpress.org/plugins/hpos-status-indicator-for-woocommerce

Adds a High Performance Order Storage (HPOS) status indicator to the admin bar that shows the status of HPOS on the site, perfect for debugging.

20 active installs v1.0.3 PHP 7.4+ WP 6.0+ Updated Jul 13, 2025
debugdebug-bardebug-tooldevelopmentwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is HPOS Status Indicator for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

HPOS Status Indicator for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The hpos-status-indicator-for-woocommerce plugin, version 1.0.3, exhibits a generally strong security posture based on the provided static analysis. The absence of any detected dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant positive. The 100% use of prepared statements for SQL queries and the 80% rate of proper output escaping are also commendable practices. The plugin also appears to have a very limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks.

However, a notable concern is the complete lack of nonce checks. While the attack surface is minimal and there's only one identified capability check, the absence of nonces on any potential entry points, however few, represents a potential weakness that could be exploited if new entry points are introduced or existing ones are misconfigured in future updates. The taint analysis showing zero flows with unsanitized paths is reassuring, but the lack of comprehensive taint analysis (0 flows analyzed) makes it difficult to definitively rule out all potential taint-related vulnerabilities. The plugin also has no recorded vulnerability history, which is positive, but doesn't guarantee future security.

In conclusion, the plugin is currently in a good security state due to its clean code and limited attack surface. The primary area for improvement and vigilance is the implementation of nonce checks, even on seemingly secure entry points. The lack of historical vulnerabilities is a good sign, but continuous monitoring and secure development practices are essential to maintain this status.

Key Concerns

  • Missing nonce checks on potential entry points
  • Limited taint analysis coverage
Vulnerabilities
None known

HPOS Status Indicator for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

HPOS Status Indicator for WooCommerce Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

HPOS Status Indicator for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
8 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped10 total outputs
Attack Surface

HPOS Status Indicator for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionbefore_woocommerce_initincludes/Hpos_Status_Activation.php:24
actioninitincludes/Hpos_Status_Activation.php:25
actionadmin_noticesincludes/Hpos_Status_Activation.php:28
actionadmin_noticesincludes/Hpos_Status_Activation.php:30
actionadmin_bar_menuincludes/Hpos_Status_Output.php:27
actionwp_headincludes/Hpos_Status_Output.php:28
actionadmin_headincludes/Hpos_Status_Output.php:29
Maintenance & Trust

HPOS Status Indicator for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 13, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

HPOS Status Indicator for WooCommerce Developer Profile

YMMV Plugins

4 plugins · 820 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HPOS Status Indicator for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hpos-status-indicator-for-woocommerce/includes/Hpos_Status_Activation.php/wp-content/plugins/hpos-status-indicator-for-woocommerce/includes/Hpos_Status_Output.php

HTML / DOM Fingerprints

CSS Classes
woocommerce-site-status-hpos-statusactiveinactive
Data Attributes
data-original-titletitle
FAQ

Frequently Asked Questions about HPOS Status Indicator for WooCommerce