LorInsight Security & Risk Analysis

wordpress.org/plugins/lorinsight-for-wc

Short Description: Unlock powerful insights and grow your business with LorInsight for WooCommerce-powered stores.

0 active installs v1.0.0 PHP 7.4+ WP 5.6+ Updated May 12, 2025
aianalyticsdata-visualizationinsightswoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LorInsight Safe to Use in 2026?

Generally Safe

Score 92/100

LorInsight has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The lorinsight-for-wc v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. All identified entry points, including REST API routes and AJAX handlers, appear to have proper authentication and capability checks in place, which is a significant positive. The code demonstrates excellent practices with 100% of SQL queries using prepared statements and all output being properly escaped, mitigating risks of SQL injection and cross-site scripting (XSS) vulnerabilities. The absence of file operations and dangerous functions further strengthens its security profile.

However, the lack of nonce checks on any entry points, while not directly indicated as an issue in this static analysis, represents a potential weakness. Nonce checks are a crucial layer of defense against Cross-Site Request Forgery (CSRF) attacks. The plugin's vulnerability history is clean, with no recorded CVEs, which is highly encouraging and suggests a history of secure development or diligent patching by the developers. The external HTTP requests, while present, are not flagged for immediate concern without further context, but they are an area that warrants awareness.

In conclusion, lorinsight-for-wc v1.0.0 is commendably secure in its handling of data and access control, with robust SQL and output sanitization. The primary area for improvement lies in implementing nonce checks to bolster its defense against CSRF attacks. The clean vulnerability history is a strong indicator of developer diligence.

Key Concerns

  • Missing nonce checks on entry points
Vulnerabilities
None known

LorInsight Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LorInsight Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

LorInsight Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
30 escaped
Nonce Checks
0
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped30 total outputs
Attack Surface

LorInsight Attack Surface

Entry Points5
Unprotected0

REST API Routes 5

POST/wp-json/lorinsight/sync/datautils/endpoints.php:4
POST/wp-json/lorinsight/sync/activateutils/endpoints.php:12
GET/wp-json/lorinsight/sync/settingsutils/endpoints.php:20
POST/wp-json/lorinsight/sync/settingsutils/endpoints.php:36
GET/wp-json/lorinsight/shopapper-tokenutils/endpoints.php:44
WordPress Hooks 9
actionadmin_menulorinsight-for-wc.php:31
actionadmin_initlorinsight-for-wc.php:53
actionadmin_enqueue_scriptslorinsight-for-wc.php:78
actionplugins_loadedlorinsight-for-wc.php:102
actionrest_api_initlorinsight-for-wc.php:122
actionuser_registerlorinsight-for-wc.php:123
actionprofile_updatelorinsight-for-wc.php:124
actionwoocommerce_new_orderlorinsight-for-wc.php:125
actionwoocommerce_update_orderlorinsight-for-wc.php:126
Maintenance & Trust

LorInsight Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 12, 2025
PHP min version7.4
Downloads271

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LorInsight Developer Profile

lorinsight

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LorInsight

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lorinsight-for-wc/icon.png
Script Paths
/wp-content/plugins/lorinsight-for-wc/build/bundle.js

HTML / DOM Fingerprints

CSS Classes
lorinsight-root
JS Globals
lorinsightForWcSettings
REST Endpoints
/wp-json/lorinsight/sync/data/wp-json/lorinsight/sync/activate/wp-json/lorinsight/sync/settings/wp-json/lorinsight/shopapper-token
FAQ

Frequently Asked Questions about LorInsight