Next Product Toolbox for WooCommerce Security & Risk Analysis

wordpress.org/plugins/next-wc-product-toolbox

Next Product Toolbox for WooCommerce helps you easily hide or modify information displayed on your WooCommerce product pages.

0 active installs v1.4 PHP + WP 5.3+ Updated May 13, 2025
shopsinglevariablewoo-commercewoocommwerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Next Product Toolbox for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Next Product Toolbox for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The plugin "next-wc-product-toolbox" v1.4 appears to have a generally strong security posture based on the provided static analysis. It demonstrates good practices by not utilizing dangerous functions and ensuring all SQL queries are prepared. The high percentage of properly escaped output is also a positive indicator. The plugin also has a clean vulnerability history, with no known CVEs, which suggests a history of secure development or diligent patching. The attack surface is minimal, with all entry points having some form of protection, although the specifics of these protections are not detailed.

However, there are a few areas for concern. The absence of nonce checks across all entry points is a significant weakness. This lack of CSRF protection makes the plugin vulnerable to Cross-Site Request Forgery attacks, especially given the presence of shortcodes that could potentially trigger actions. While taint analysis didn't reveal any specific unsanitized paths, the limited scope of the analysis (0 flows analyzed) means this doesn't provide much reassurance. The plugin also performs file operations, and without further analysis, it's unclear if these are handled securely.

Overall, while the plugin has several strengths, the lack of nonce checks is a critical oversight that significantly increases its risk profile. The absence of any recorded vulnerabilities is positive, but the identified code signals suggest potential weaknesses that could lead to future issues if not addressed. The minimal attack surface and good SQL practices are commendable, but they are overshadowed by the critical omission of CSRF protection.

Key Concerns

  • Missing nonce checks on entry points
  • Limited taint analysis coverage
Vulnerabilities
None known

Next Product Toolbox for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Next Product Toolbox for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
60 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped67 total outputs
Attack Surface

Next Product Toolbox for WooCommerce Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[subcats_cloud] includes\wcptb-functions.php:272
[tags_cloud] includes\wcptb-functions.php:315
[cats_list] includes\wcptb-functions.php:394
[tags_list] includes\wcptb-functions.php:622
WordPress Hooks 22
actionadmin_enqueue_scriptsincludes\wcptb-functions.php:21
actionplugins_loadedincludes\wcptb-functions.php:33
actionadmin_menuincludes\wcptb-functions.php:49
actionadmin_initincludes\wcptb-functions.php:66
actioninitincludes\wcptb-functions.php:69
filtergettextincludes\wcptb-functions.php:149
filterngettextincludes\wcptb-functions.php:150
actionwp_footerincludes\wcptb-functions.php:153
actionwp_headincludes\wcptb-functions.php:198
actionwoocommerce_single_product_summaryincludes\wcptb-functions.php:402
filterwc_product_sku_enabledincludes\wcptb-functions.php:415
actionwoocommerce_single_product_summaryincludes\wcptb-functions.php:447
filterwoocommerce_product_add_to_cart_textincludes\wcptb-functions.php:460
filterwoocommerce_product_single_add_to_cart_textincludes\wcptb-functions.php:472
actionwoocommerce_after_shop_loop_itemincludes\wcptb-functions.php:541
filterwoocommerce_get_availability_textincludes\wcptb-functions.php:640
filterwoocommerce_sale_flashincludes\wcptb-functions.php:645
filterwoocommerce_product_tabsincludes\wcptb-functions.php:652
filterwoocommerce_product_tabsincludes\wcptb-functions.php:659
filterwoocommerce_product_description_headingincludes\wcptb-functions.php:667
filterwoocommerce_product_description_tab_titleincludes\wcptb-functions.php:676
actionwoocommerce_before_cartincludes\wcptb-functions.php:693
Maintenance & Trust

Next Product Toolbox for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 13, 2025
PHP min version
Downloads787

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Next Product Toolbox for WooCommerce Developer Profile

nxtweb

8 plugins · 320 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Next Product Toolbox for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/next-wc-product-toolbox/images/icon.png
Script Paths
/wp-content/plugins/next-wc-product-toolbox/js/wcptb_script.js
Version Parameters
next-wc-product-toolbox/css/style.css?ver=next-wc-product-toolbox/js/wcptb_script.js?ver=

HTML / DOM Fingerprints

CSS Classes
stabilo
HTML Comments
Copyright 2022 F.Leroux
Data Attributes
data-wcptb-key-donatedata-wcptb-plugin-namedata-wcptb-plugin-slugdata-wcptb-versiondata-wcptb-typedata-wcptb-plugin-page
JS Globals
wcptb_key_donatewcptb_plugin_namewcptb_plugin_slugwcptb_versionwcptb_typewcptb_plugin_page+2 more
Shortcode Output
[next_wc_product_toolbox_tags][next_wc_product_toolbox_categories][next_wc_product_toolbox_latest][next_wc_product_toolbox_related]
FAQ

Frequently Asked Questions about Next Product Toolbox for WooCommerce