Linked Variation for WooCommerce Security & Risk Analysis

wordpress.org/plugins/linked-variation-for-woocommerce

Linked separate products together by product attributes and More. Needs WooCommerce to work.

400 active installs v2.0.3 PHP 7.4+ WP 6.0+ Updated May 24, 2025
linked-variationvariationwoocommerce-attributeswoocommerce-productswoocommerce-variation
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 14, 2024
Safety Verdict

Is Linked Variation for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Linked Variation for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 14, 2024Updated 10mo ago
Risk Assessment

The "linked-variation-for-woocommerce" plugin v2.0.3 demonstrates a generally good security posture, with all identified entry points (AJAX handlers) protected by authentication checks. The code analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and the majority of output is properly escaped. Furthermore, the absence of file operations and external HTTP requests reduces potential attack vectors. The presence of nonce and capability checks on AJAX handlers further reinforces its security. However, a previous medium severity vulnerability of the Cross-Site Request Forgery (CSRF) type, though now patched, indicates a historical susceptibility in this area. The inclusion of the Select2 library, while common, could be a concern if it's an outdated version, though this is not explicitly stated in the provided data. Overall, the plugin is robust, but the historical CSRF vulnerability warrants continued vigilance.

Key Concerns

  • Past medium vulnerability (CSRF)
  • Bundled Select2 library
Vulnerabilities
1

Linked Variation for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-48047medium · 4.3Cross-Site Request Forgery (CSRF)

Linked Variation for WooCommerce <= 1.0.5 - Cross-Site Request Forgery

Oct 14, 2024 Patched in 2.0.0 (163d)
Code Analysis
Analyzed Mar 16, 2026

Linked Variation for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
69 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

84% escaped82 total outputs
Attack Surface

Linked Variation for WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_lvfw_get_source_productsincludes\admin\ajax.php:60
authwp_ajax_lvfw_get_source_taxonomyincludes\admin\ajax.php:105
authwp_ajax_lvfw_get_new_variationincludes\admin\ajax.php:146
WordPress Hooks 8
actioninitincludes\admin\cpt.php:73
actionadmin_enqueue_scriptsincludes\admin\enqueue.php:78
actionadd_meta_boxesincludes\admin\meta.php:42
actionsave_postincludes\admin\meta.php:157
actionwoocommerce_before_add_to_cart_formincludes\frontend\display.php:111
actionwp_enqueue_scriptsincludes\frontend\enqueue.php:55
actionupgrader_process_completeincludes\upgrade.php:76
actionadmin_noticeslinked-variation-for-woocommerce.php:55
Maintenance & Trust

Linked Variation for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 24, 2025
PHP min version7.4
Downloads9K

Community Trust

Rating92/100
Number of ratings10
Active installs400
Developer Profile

Linked Variation for WooCommerce Developer Profile

Razon Komar Pal

1 plugin · 400 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
163 days
View full developer profile
Detection Fingerprints

How We Detect Linked Variation for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/linked-variation-for-woocommerce/assets/css/backend/style.css/wp-content/plugins/linked-variation-for-woocommerce/assets/css/frontend/style.css/wp-content/plugins/linked-variation-for-woocommerce/assets/js/backend/main.js/wp-content/plugins/linked-variation-for-woocommerce/assets/js/frontend/main.js/wp-content/plugins/linked-variation-for-woocommerce/assets/js/shared/main.js
Script Paths
/wp-content/plugins/linked-variation-for-woocommerce/assets/js/backend/main.js/wp-content/plugins/linked-variation-for-woocommerce/assets/js/frontend/main.js/wp-content/plugins/linked-variation-for-woocommerce/assets/js/shared/main.js
Version Parameters
linked-variation-for-woocommerce/assets/css/backend/style.css?ver=linked-variation-for-woocommerce/assets/css/frontend/style.css?ver=linked-variation-for-woocommerce/assets/js/backend/main.js?ver=linked-variation-for-woocommerce/assets/js/frontend/main.js?ver=linked-variation-for-woocommerce/assets/js/shared/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
lvfw-admin-noticelvfw-backend-wrapper
Data Attributes
data-product-iddata-variation-id
JS Globals
LVFW_Admin
FAQ

Frequently Asked Questions about Linked Variation for WooCommerce