
Leo Product Recommendations for WooCommerce Security & Risk Analysis
wordpress.org/plugins/leo-product-recommendationsBoost WooCommerce sales with smart product recommendation popups on add to cart.
Is Leo Product Recommendations for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Leo Product Recommendations for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the 'leo-product-recommendations' plugin version 3.1.0 shows a mixed bag of good practices and significant concerns. On the positive side, the plugin demonstrates excellent output sanitization, with all 406 outputs properly escaped, and it has no recorded vulnerabilities (CVEs) or critical taint analysis findings. This suggests a level of diligence in handling user-generated content and a history of secure development. The absence of file operations and dangerous functions is also a strong positive indicator.
However, the plugin presents notable risks due to its attack surface. It exposes 12 AJAX handlers, with a critical flaw: 2 of these handlers lack any authentication checks. This opens the door for unauthenticated users to potentially trigger these handlers, leading to unpredictable behavior or the execution of unintended actions. Furthermore, the plugin uses 1 SQL query that is not protected by prepared statements, which could be a vector for SQL injection if the query handles user-supplied data without proper sanitization, even though no specific taint flows were identified in the static analysis. The lack of capability checks on any entry points is also a concern, as it implies that these operations might be accessible to users who shouldn't have permission to perform them.
In conclusion, while the plugin excels in output sanitization and has a clean vulnerability history, the unprotected AJAX endpoints and the non-prepared SQL query represent significant security weaknesses. The presence of these exploitable entry points without adequate authentication or authorization mechanisms significantly elevates the risk, despite the absence of known CVEs. Developers should prioritize addressing these exposed handlers and the SQL query to improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
- SQL query without prepared statements
- No capability checks on entry points
Leo Product Recommendations for WooCommerce Security Vulnerabilities
Leo Product Recommendations for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Leo Product Recommendations for WooCommerce Attack Surface
AJAX Handlers 12
WordPress Hooks 20
Maintenance & Trust
Leo Product Recommendations for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Leo Product Recommendations for WooCommerce Alternatives
Boost Sales for WooCommerce – Set up Up-Sells & Cross-Sells Popups & Auto Apply Coupon
woo-boost-sales
Boost Sales for WooCommerce with dynamic upsell popups, cross-sell bundles, and 'Frequently Bought Together' suggestions
Brave Popup Builder – Popup, Optins, Lead Generation, Survey & Interactive Content
brave-popup-builder
The best drag-and-drop Popup Builder for WordPress. Create Popups, exit-intent popups, slide-ins, and lead generation forms & Woocommerce popups i …
Related Products – Create Upsells, Cross-sells, and Product Recommendations for WooCommerce
wt-woocommerce-related-products
This WooCommerce related products plugin, lets you create upsells, and cross-sells with smart WooCommerce product recommendations widget.
CartPops – High Converting Add To Cart Popup For WooCommerce
cartpops
Included For Free
Poptics – Popup Builder, Email Opt-ins, Exit-Intent & WooCommerce Popups Sales
poptics
Create high-converting popups, email opt-ins, exit-intent popups & WooCommerce popups to boost leads, subscribers and sales.
Leo Product Recommendations for WooCommerce Developer Profile
1 plugin · 500 total installs
How We Detect Leo Product Recommendations for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/leo-product-recommendations/script.js/wp-content/plugins/leo-product-recommendations/style.cssleo-product-recommendations/script.js?ver=leo-product-recommendations/style.css?ver=HTML / DOM Fingerprints
lprw-feedback-modallprw-feedback-modal-backgroundlprw-feedback-modal-cardlprw-feedback-modal-card-headlprw-feedback-modal-card-titlelprw-feedback-modal-closelprw-feedback-modal-card-bodylprw-feedback-form-heading+5 moredata-plugin_slugleo_feedback_data