OlalaWeb – WooCommerce Category Prices Security & Risk Analysis

wordpress.org/plugins/olalaweb-woocommerce-category-prices

Display your products' prices on your WooCommerce Category Archive pages.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Jan 3, 2015
archivecategorypriceproductwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OlalaWeb – WooCommerce Category Prices Safe to Use in 2026?

Generally Safe

Score 85/100

OlalaWeb – WooCommerce Category Prices has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The static analysis of the "olalaweb-woocommerce-category-prices" plugin v1.0 reveals a generally positive security posture. The plugin appears to have a very small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. Furthermore, the code signals indicate no usage of dangerous functions, no file operations, no external HTTP requests, and importantly, all SQL queries utilize prepared statements. This suggests good practices regarding data handling and protection against common web vulnerabilities like SQL injection.

However, a significant concern arises from the output escaping analysis. With 5 total outputs and 0% properly escaped, this indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the user interface without proper escaping could be manipulated by attackers to inject malicious scripts. The absence of capability checks and nonce checks, while not directly exploitable due to the minimal attack surface, represents a missed opportunity for robust security, especially if the plugin's functionality were to expand or its attack surface increased in future versions.

The vulnerability history being entirely clear (0 known CVEs, 0 unpatched) is a strong positive indicator, suggesting the plugin has historically been developed with security in mind or has not attracted significant security research. The lack of critical or high severity issues in the past is encouraging. In conclusion, while the plugin demonstrates strengths in areas like SQL query safety and a limited attack surface, the critical weakness in output escaping presents a substantial risk of XSS. The absence of capability and nonce checks are areas for improvement.

Key Concerns

  • All outputs are unescaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

OlalaWeb – WooCommerce Category Prices Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

OlalaWeb – WooCommerce Category Prices Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

OlalaWeb – WooCommerce Category Prices Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitola-wccp.php:104
actionwoocommerce_after_subcategoryola-wccp.php:154
Maintenance & Trust

OlalaWeb – WooCommerce Category Prices Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedJan 3, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

OlalaWeb – WooCommerce Category Prices Developer Profile

Matthieu

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OlalaWeb – WooCommerce Category Prices

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
price
Data Attributes
itemprop="offers"itemscopeitemtype="http://schema.org/Offer"itemtype="http://schema.org/AggregateOffer"itemprop="price"itemprop="priceCurrency"+2 more
FAQ

Frequently Asked Questions about OlalaWeb – WooCommerce Category Prices