
Ni Cost of Goods for WooCommerce Security & Risk Analysis
wordpress.org/plugins/ni-woocommerce-cost-of-goodsNI Cost of Goods for WooCommerce adds cost prices and offers profit insights, helping you optimize pricing and enhance profitability in your store.
Is Ni Cost of Goods for WooCommerce Safe to Use in 2026?
Generally Safe
Score 97/100Ni Cost of Goods for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "ni-woocommerce-cost-of-goods" plugin version 3.4.0 exhibits a generally good security posture, with strong adherence to best practices like prepared statements for all SQL queries and a high percentage of properly escaped output. The attack surface is minimal, consisting of only one AJAX handler, and importantly, this entry point appears to have proper authorization checks. The absence of file operations, external HTTP requests, and the presence of nonce and capability checks further reinforce this positive assessment.
However, concerns arise from the taint analysis, which identified two flows with unsanitized paths, both flagged as high severity. While no critical vulnerabilities were found in the taint analysis, these high-severity flows represent a potential risk for improper neutralization of input, which could lead to security issues if exploited. The vulnerability history, despite having no currently unpatched CVEs, shows a pattern of past medium-severity issues including Cross-site Scripting (XSS), Missing Authorization, and SQL Injection. This indicates a need for continued vigilance and thorough security reviews, as these types of vulnerabilities, even if patched, suggest past weaknesses in input sanitization and authorization handling.
In conclusion, the plugin demonstrates strong technical implementation regarding database queries and output handling. The primary areas of concern are the high-severity unsanitized paths identified in the taint analysis and the historical presence of medium-severity vulnerabilities, particularly those related to input sanitization and authorization. While the current version appears to be free of critical or unpatched vulnerabilities, the identified taint flows warrant immediate investigation and remediation to ensure the plugin's robust security.
Key Concerns
- High severity taint flows with unsanitized paths
- Past medium severity vulnerabilities (XSS, SQLi, Auth)
Ni Cost of Goods for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Ni WooCommerce Cost Of Goods <= 3.2.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Ni WooCommerce Cost Of Goods <= 3.2.8 - Missing Authorization
Ni WooCommerce Cost Of Goods <= 3.2.8 - Authenticated (Administrator+) SQL Injection
Ni Cost of Goods for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ni Cost of Goods for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 27
Maintenance & Trust
Ni Cost of Goods for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Ni Cost of Goods for WooCommerce Alternatives
Alpha Insights – Profit Intelligence & Analytics for WooCommerce
alpha-insights-sales-report-builder-analytics-for-woocommerce
WooCommerce reporting plugin for profit & loss, cost of goods (COGS), ad spend, ROI and custom sales reports.
Cost of Goods: Product Cost & Profit Calculator for WooCommerce
cost-of-goods-for-woocommerce
Unlock detailed insights into products profitability, calculate COGS & profit margins, and get a better financial analytics insights with our Cost …
F4 Total Stock Value for WooCommerce
f4-total-stock-value-for-woocommerce
Adds a few infos about the current stock value to the WooCommerce Analytics.
REPORTiT – Advanced Reporting for WooCommerce
ithemelandco-woo-report
Stop guessing. Grow your sales with powerful, easy-to-understand reports and analytics for WooCommerce.
Debloat for WooCommerce
disable-analytics-for-woocommerce
Optimize WooCommerce website performance.
Ni Cost of Goods for WooCommerce Developer Profile
25 plugins · 5K total installs
How We Detect Ni Cost of Goods for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/css/ni-cog-admin.css/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-admin.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-report.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-sales-report.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-update-product.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-other-plugin.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-setting.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-top-profit.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-admin.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-report.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-sales-report.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-update-product.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-other-plugin.js/wp-content/plugins/ni-woocommerce-cost-of-goods/assets/js/ni-cog-setting.js+1 moreni-woocommerce-cost-of-goods/assets/css/ni-cog-admin.css?ver=ni-woocommerce-cost-of-goods/assets/js/ni-cog-admin.js?ver=ni-woocommerce-cost-of-goods/assets/js/ni-cog-report.js?ver=ni-woocommerce-cost-of-goods/assets/js/ni-cog-sales-report.js?ver=ni-woocommerce-cost-of-goods/assets/js/ni-cog-update-product.js?ver=ni-woocommerce-cost-of-goods/assets/js/ni-cog-other-plugin.js?ver=ni-woocommerce-cost-of-goods/assets/js/ni-cog-setting.js?ver=ni-woocommerce-cost-of-goods/assets/js/ni-cog-top-profit.js?ver=HTML / DOM Fingerprints
ni-cog-adminni-cog-reportni-cog-sales-reportni-cog-update-productni-cog-other-pluginni-cog-settingni-cog-top-profit<!-- Start Ni Cog Sales Report --><!-- End Ni Cog Sales Report --><!-- Start Ni Cog Update Product --><!-- End Ni Cog Update Product -->+6 moredata-ni-cog-sales-print-noncename="ni_cog_sales_print_nonce"id="footer-thankyou"ni_cog_admin_paramsni_cog_report_paramsni_cog_sales_report_paramsni_cog_update_product_paramsni_cog_other_plugin_paramsni_cog_setting_params+1 more/wp-json/ni-cog/v1/update-product