Pick&Scan Lite Security & Risk Analysis

wordpress.org/plugins/pickscan-lite

Prepare your WooCommerce orders quickly and without errors. Optimized PDF generation for smooth picking and logistics.

0 active installs v1.0.4 PHP 7.4+ WP 6.8+ Updated Unknown
order-pickingpackingprint-orderwarehousewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pick&Scan Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Pick&Scan Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The pickscan-lite v1.0.4 plugin exhibits a generally strong security posture based on the provided static analysis. A significant strength is the complete absence of known CVEs and a robust approach to handling SQL queries with prepared statements. The plugin also demonstrates good practices regarding output escaping, with a very high percentage of outputs being properly escaped. The limited attack surface, consisting only of two AJAX handlers, and the presence of nonce and capability checks further contribute to its secure design. There are no identified taint flows of critical or high severity, and no direct file operations or external HTTP requests, which are common vectors for vulnerabilities.

While the static analysis reveals no immediate critical risks, the absence of taint analysis results (0 flows analyzed) is a minor concern. This could imply that the analysis tool did not identify any potential data flows to analyze, or that the analysis was not comprehensive in that area. The presence of AJAX handlers, even with checks, represents a potential entry point that, if a flaw were to be introduced, could be exploited. However, the existing checks mitigate this risk considerably. The lack of any recorded vulnerabilities in its history is a positive indicator of consistent security practices by the developers. Overall, pickscan-lite v1.0.4 appears to be a well-developed and secure plugin, with its main area for potential enhancement being the comprehensive nature of taint analysis.

Vulnerabilities
None known

Pick&Scan Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Pick&Scan Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
89 escaped
Nonce Checks
5
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped93 total outputs
Attack Surface

Pick&Scan Lite Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_pickli_generate_bon_preparationinc\pickli_admin.php:119
authwp_ajax_view_pickli_orderinc\pickli_admin.php:317
WordPress Hooks 7
actionwoocommerce_product_options_general_product_datainc\pickli_products.php:5
actionwoocommerce_product_after_variable_attributesinc\pickli_products.php:42
actionwoocommerce_process_product_metainc\pickli_products.php:72
actionwoocommerce_save_product_variationinc\pickli_products.php:87
actionplugins_loadedpickscan-lite.php:21
actionadmin_enqueue_scriptspickscan-lite.php:41
actionadmin_menupickscan-lite.php:91
Maintenance & Trust

Pick&Scan Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads257

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pick&Scan Lite Developer Profile

Agence Best Of Site

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pick&Scan Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pickscan-lite/assets/css/pickli_admin.css/wp-content/plugins/pickscan-lite/assets/js/pickli_admin.js/wp-content/plugins/pickscan-lite/assets/js/sweetalert.js/wp-content/plugins/pickscan-lite/assets/css/fonticons.css
Script Paths
/wp-content/plugins/pickscan-lite/assets/js/pickli_admin.js/wp-content/plugins/pickscan-lite/assets/js/sweetalert.js
Version Parameters
pickscan-lite/assets/css/pickli_admin.css?ver=pickscan-lite/assets/js/pickli_admin.js?ver=pickscan-lite/assets/js/sweetalert.js?ver=pickscan-lite/assets/css/fonticons.css?ver=

HTML / DOM Fingerprints

CSS Classes
container-pickscancontener-pslogo-pickscanpremium_pickscancc-psldecouverte-pslmenu-pslpickspremium+5 more
Data Attributes
id="psl-check-all"id="ps-parameter"
JS Globals
pickli_ajax_vars
FAQ

Frequently Asked Questions about Pick&Scan Lite