
IM WooCommerce My Account Widget Security & Risk Analysis
wordpress.org/plugins/im-woocommerce-my-account-widgetThis plugin adds a widget with customer account information to your WooCommerce shop.
Is IM WooCommerce My Account Widget Safe to Use in 2026?
Generally Safe
Score 85/100IM WooCommerce My Account Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'im-woocommerce-my-account-widget' plugin v0.4.0 presents a mixed security posture. On the positive side, the plugin exhibits excellent practices regarding SQL query sanitization, with 100% of queries using prepared statements. It also avoids file operations and external HTTP requests, which are common vectors for vulnerabilities. Furthermore, there is no recorded vulnerability history, suggesting a generally stable and secure development track record.
However, several concerns are raised by the static analysis. The presence of the `create_function` dangerous function is a significant red flag, as this function is deprecated and can lead to code injection if not handled with extreme care. While the taint analysis shows no critical or high-severity unsanitized flows, the fact that 2 out of 2 analyzed flows involved unsanitized paths indicates a potential area for concern, even if the immediate risk is not assessed as high. The output escaping is also moderately concerning, with only 64% of outputs properly escaped, leaving 36% potentially vulnerable to XSS attacks. Finally, the complete absence of nonce checks and capability checks on its entry points is a notable weakness, increasing the risk of unauthorized actions if any entry points are discovered or if malicious input is crafted.
Key Concerns
- Use of dangerous function create_function
- Unsanitized paths in taint analysis flows
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
IM WooCommerce My Account Widget Security Vulnerabilities
IM WooCommerce My Account Widget Release Timeline
IM WooCommerce My Account Widget Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
IM WooCommerce My Account Widget Attack Surface
WordPress Hooks 6
Maintenance & Trust
IM WooCommerce My Account Widget Maintenance & Trust
Maintenance Signals
Community Trust
IM WooCommerce My Account Widget Alternatives
WooCom Account Widget
woocom-account-widget
This widget is for WooCommerce, developed specially for developers, following WordPress VIP coding standard. Checked by PHPCodesniffer along with Word …
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Element Pack – Widgets, Templates & Addons for Elementor
bdthemes-element-pack-lite
Elementor addons with 300+ widgets, templates, WooCommerce widgets, mega menu, header footer builder, and powerful design extensions.
Feeds for TikTok (TikTok feed, video, and gallery plugin)
feeds-for-tiktok
The best way to display TikTok videos on your WordPress website. Display clean, customizable, and responsive TikTok feeds from your TikTok account.
Exclusive Addons for Elementor
exclusive-addons-for-elementor
Exclusive Addons is one of the Best Elementor Addons With 90+ Elementor Free & Pro Widgets with all the customizations options you ever imagined.
IM WooCommerce My Account Widget Developer Profile
1 plugin · 10 total installs
How We Detect IM WooCommerce My Account Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/im-woocommerce-my-account-widget/css/style.cssim-woocommerce-my-account-widget/css/style.css?ver=HTML / DOM Fingerprints
IMWooCommerceMyAccountWidgetfor="im-woocommerce-my-account-widget-logged_out_title"id="im-woocommerce-my-account-widget-logged_out_title"name="im-woocommerce-my-account-widget-logged_out_title"for="im-woocommerce-my-account-widget-logged_in_title"id="im-woocommerce-my-account-widget-logged_in_title"name="im-woocommerce-my-account-widget-logged_in_title"+34 more