License Manager for WooCommerce Security & Risk Analysis

wordpress.org/plugins/license-manager-for-woocommerce

Easily sell and manage software license keys through your WooCommerce shop

6K active installs v3.0.15 PHP 7.0+ WP 4.7+ Updated Mar 12, 2026
license-keylicense-managerserial-keysoftware-licensewoocommerce
95
A · Safe
CVEs total4
Unpatched0
Last CVESep 5, 2025
Safety Verdict

Is License Manager for WooCommerce Safe to Use in 2026?

Generally Safe

Score 95/100

License Manager for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Sep 5, 2025Updated 2mo ago
Risk Assessment

The "license-manager-for-woocommerce" plugin version 3.0.15 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped output, critical security concerns remain. The presence of an unprotected AJAX handler significantly increases the attack surface, making it a prime target for unauthorized actions. Furthermore, the taint analysis reveals a concerning number of high-severity flows with unsanitized paths, indicating potential for data leakage or manipulation if exploited.

Key Concerns

  • 1 unprotected AJAX handler found
  • 5 high severity taint flows with unsanitized paths
  • Total known CVEs: 4 (1 high, 3 medium)
  • Bundled library Freemius v1.0 might be outdated
Vulnerabilities
4 published

License Manager for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
3

4 total CVEs

CVE-2025-58788medium · 4.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

License Manager for WooCommerce <= 3.0.12 - Authenticated (Administrator+) SQL Injection

Sep 5, 2025 Patched in 3.0.13 (34d)
CVE-2025-32522medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

License Manager for WooCommerce <= 3.0.9 - Reflected Cross-Site Scripting

Apr 10, 2025 Patched in 3.0.10 (7d)
CVE-2024-1639medium · 6.5Missing Authorization

License Manager for WooCommerce <= 3.0.6 - Improper Authorization to Authenticated(Contributor+) Sensitive Information Exposure

Jun 20, 2024 Patched in 3.0.7 (12d)
CVE-2023-48742high · 7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

License Manager for WooCommerce <= 2.2.10 - Authenticated (Administrator+) SQL Injection

Nov 23, 2023 Patched in 2.2.11 (61d)
Code Analysis
Analyzed Mar 16, 2026

License Manager for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
18
80 prepared
Unescaped Output
24
609 escaped
Nonce Checks
27
Capability Checks
24
File Operations
16
External Requests
0
Bundled Libraries
3

Bundled Libraries

Select2Freemius1.0dompdf

SQL Query Safety

82% prepared98 total queries

Output Escaping

96% escaped633 total outputs
Data Flows · Security
6 unsanitized

Data Flow Analysis

18 flows6 with unsanitized paths
licenseDropdown (includes\Lists\ActivationsList.php:636)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

License Manager for WooCommerce Attack Surface

Entry Points6
Unprotected1

AJAX Handlers 6

authwp_ajax_lmfwc_dropdown_searchincludes\Controllers\Dropdowns.php:26
authwp_ajax_lmfwc_show_license_keyincludes\Controllers\License.php:28
authwp_ajax_lmfwc_show_all_license_keysincludes\Controllers\License.php:29
authwp_ajax_lmfwc_dropdown_searchincludes\Integrations\WooCommerce\Controller.php:47
authwp_ajax_lmfwc_handle_tool_processincludes\Settings.php:46
authwp_ajax_lmfwc_dismiss_pro_noticelicense-manager-for-woocommerce.php:146
WordPress Hooks 70
filterlmfwc_duplicatefunctions\lmfwc-core-functions.php:58
actionadmin_menuincludes\AdminMenus.php:82
actionadmin_initincludes\AdminMenus.php:83
filterset-screen-optionincludes\AdminMenus.php:86
filteradmin_footer_textincludes\AdminMenus.php:89
filterwoocommerce_settings_tabs_arrayincludes\AdminMenus.php:91
actionadmin_noticesincludes\AdminNotice.php:32
filterdetermine_current_userincludes\Api\Authentication.php:36
filterrest_authentication_errorsincludes\Api\Authentication.php:37
filterrest_post_dispatchincludes\Api\Authentication.php:38
filterrest_pre_dispatchincludes\Api\Authentication.php:39
actionrest_api_initincludes\Api\Setup.php:20
actionadmin_post_lmfwc_api_key_updateincludes\Controllers\ApiKey.php:20
actionadmin_post_lmfwc_save_generatorincludes\Controllers\Generator.php:20
actionadmin_post_lmfwc_update_generatorincludes\Controllers\Generator.php:21
actionadmin_post_lmfwc_generate_license_keysincludes\Controllers\Generator.php:22
actionadmin_post_lmfwc_import_license_keysincludes\Controllers\License.php:23
actionadmin_post_lmfwc_add_license_keyincludes\Controllers\License.php:24
actionadmin_post_lmfwc_update_license_keyincludes\Controllers\License.php:25
filterlmfwc_encryptincludes\Crypto.php:62
filterlmfwc_decryptincludes\Crypto.php:63
filterlmfwc_hashincludes\Crypto.php:64
filterlmfwc_activation_hashincludes\Crypto.php:65
actionlmfwc_export_license_keys_pdfincludes\Export.php:20
actionlmfwc_export_license_keys_csvincludes\Export.php:21
actionlmfwc_export_license_keys_by_date_csvincludes\Export.php:22
filterlmfwc_generate_license_keysincludes\Generator.php:17
filterlmfwc_import_license_keys_fileincludes\Import.php:19
filterlmfwc_import_license_keys_clipboardincludes\Import.php:20
filterlmfwc_get_customer_license_keysincludes\Integrations\WooCommerce\Controller.php:41
filterlmfwc_get_all_customer_license_keysincludes\Integrations\WooCommerce\Controller.php:42
filterlmfwc_get_license_activationsincludes\Integrations\WooCommerce\Controller.php:43
filterlmfwc_insert_generated_license_keysincludes\Integrations\WooCommerce\Controller.php:44
filterlmfwc_insert_imported_license_keysincludes\Integrations\WooCommerce\Controller.php:45
actionlmfwc_sell_imported_license_keysincludes\Integrations\WooCommerce\Controller.php:46
actionwoocommerce_email_after_order_tableincludes\Integrations\WooCommerce\Email.php:20
actionwoocommerce_email_classesincludes\Integrations\WooCommerce\Email.php:21
actionlmfwc_email_customer_deliver_license_keysincludes\Integrations\WooCommerce\Emails\CustomerDeliverLicenseKeys.php:43
actionlmfwc_email_customer_preorder_completeincludes\Integrations\WooCommerce\Emails\CustomerPreorderComplete.php:43
actionlmfwc_email_order_detailsincludes\Integrations\WooCommerce\Emails\Templates.php:17
actionlmfwc_email_order_license_keysincludes\Integrations\WooCommerce\Emails\Templates.php:18
filterwoocommerce_account_menu_itemsincludes\Integrations\WooCommerce\MyAccount.php:23
actionwoocommerce_account_view-license-keys_endpointincludes\Integrations\WooCommerce\MyAccount.php:24
actionlmfwc_myaccount_licenses_single_page_endincludes\Integrations\WooCommerce\MyAccount.php:25
actionwp_loadedincludes\Integrations\WooCommerce\MyAccount.php:26
actionwoocommerce_order_action_lmfwc_send_license_keysincludes\Integrations\WooCommerce\Order.php:30
actionwoocommerce_order_details_after_order_tableincludes\Integrations\WooCommerce\Order.php:31
filterwoocommerce_order_actionsincludes\Integrations\WooCommerce\Order.php:32
actionwoocommerce_after_order_itemmetaincludes\Integrations\WooCommerce\Order.php:33
filterwoocommerce_product_data_tabsincludes\Integrations\WooCommerce\ProductData.php:34
actionwoocommerce_product_data_panelsincludes\Integrations\WooCommerce\ProductData.php:35
actionwoocommerce_product_after_variable_attributesincludes\Integrations\WooCommerce\ProductData.php:37
actionwoocommerce_save_product_variationincludes\Integrations\WooCommerce\ProductData.php:44
actionadmin_headincludes\Integrations\WooCommerce\ProductData.php:52
actionsave_postincludes\Integrations\WooCommerce\ProductData.php:53
filterlmfwc_stock_increaseincludes\Integrations\WooCommerce\Stock.php:20
filterlmfwc_stock_decreaseincludes\Integrations\WooCommerce\Stock.php:21
filterlmfwc_stock_synchronizeincludes\Integrations\WooCommerce\Stock.php:22
filterwoocommerce_product_data_store_cpt_get_products_queryincludes\Integrations\WooCommerce\Stock.php:24
actioninitincludes\Main.php:49
actionadmin_enqueue_scriptsincludes\Main.php:319
filterplugin_row_metaincludes\Main.php:320
filterlmfwc_duplicateincludes\Main.php:354
filterlmfwc_license_keys_table_headingincludes\Main.php:365
filterlmfwc_license_keys_table_valid_untilincludes\Main.php:380
filterlmfwc_get_assigned_productsincludes\Repositories\PostMeta.php:16
filterlmfwc_get_usersincludes\Repositories\Users.php:15
actionbefore_woocommerce_initlicense-manager-for-woocommerce.php:41
actionadmin_noticeslicense-manager-for-woocommerce.php:64
actionadmin_enqueue_scriptslicense-manager-for-woocommerce.php:132
Maintenance & Trust

License Manager for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version7.0
Downloads154K

Community Trust

Rating92/100
Number of ratings147
Active installs6K
Developer Profile

License Manager for WooCommerce Developer Profile

Saad Iqbal

89 plugins · 1.4M total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
267 days
View full developer profile
Detection Fingerprints

How We Detect License Manager for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/license-manager-for-woocommerce/assets/css/pro-notice.css/wp-content/plugins/license-manager-for-woocommerce/assets/js/pro-notice.js
Script Paths
/wp-content/plugins/license-manager-for-woocommerce/assets/js/pro-notice.js
Version Parameters
license-manager-for-woocommerce/assets/css/pro-notice.css?ver=license-manager-for-woocommerce/assets/js/pro-notice.js?ver=

HTML / DOM Fingerprints

CSS Classes
lmfwc-pro-conversion-noticelmfwc-pro-notice-bannerlmfwc-banner-confettilmfwc-banner-confetti-itemlmfwc-banner-confetti-lmfwc-pro-notice-contentlmfwc-black-friday-sectionlmfwc-pro-notice-left+13 more
Data Attributes
data-dismiss-actionaria-label
JS Globals
lmfwcProNotice
FAQ

Frequently Asked Questions about License Manager for WooCommerce