Popcustoms – Print on demand & dropshipping, Free Personalizer Security & Risk Analysis

wordpress.org/plugins/popcustoms-integration-for-woocommerce

Print on demand products & embroidery provider, fulfillment & global dropshipping, customize shoes, T-shirt, hats, hoodie, jacket, blanket and more.

100 active installs v1.1.7 PHP 8.0+ WP 5.3+ Updated Apr 7, 2025
dropshippingembroiderypopcustomsprint-on-demandwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Popcustoms – Print on demand & dropshipping, Free Personalizer Safe to Use in 2026?

Generally Safe

Score 100/100

Popcustoms – Print on demand & dropshipping, Free Personalizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12mo ago
Risk Assessment

The 'popcustoms-integration-for-woocommerce' plugin, version 1.1.7, exhibits a generally good security posture based on the provided static analysis. The complete absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events, especially those lacking authentication checks, is a strong indicator of a well-designed, secure integration. Furthermore, the plugin uses prepared statements for all its SQL queries, mitigating the risk of SQL injection vulnerabilities. It also avoids file operations and dangerous functions. However, the analysis does reveal some areas for improvement. A significant concern is that only 30% of output is properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered in the output without adequate sanitization. The presence of unsanitized paths in the taint analysis, though not critical or high severity, indicates a potential area where sensitive data or functionality could be exposed. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of responsible development. Despite the clean history, the insufficient output escaping and the identified taint flow present moderate risks that should be addressed to maintain a robust security profile.

Key Concerns

  • Low output escaping percentage
  • Unsanitized paths in taint analysis
Vulnerabilities
None known

Popcustoms – Print on demand & dropshipping, Free Personalizer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Popcustoms – Print on demand & dropshipping, Free Personalizer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

30% escaped23 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<entry> (includes\templates\entry.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Popcustoms – Print on demand & dropshipping, Free Personalizer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionadmin_menuincludes\admin.php:19
filterwoocommerce_load_shipping_methodsincludes\shipping.php:38
filterwoocommerce_shipping_methodsincludes\shipping.php:39
filterwoocommerce_cart_shipping_packagesincludes\shipping.php:41
filterwoocommerce_cart_no_shipping_available_htmlincludes\shipping.php:280
filterwoocommerce_no_shipping_available_htmlincludes\shipping.php:281
filterthe_contentincludes\template-designer.php:13
actionwp_footerincludes\template-designer.php:14
filterwoocommerce_add_cart_item_dataincludes\template-designer.php:15
actionwoocommerce_add_order_item_metaincludes\template-designer.php:16
actionwoocommerce_after_cart_item_nameincludes\template-designer.php:17
filterwoocommerce_cart_item_price_htmlincludes\template-designer.php:18
filterwoocommerce_widget_cart_item_quantityincludes\template-designer.php:19
actionwoocommerce_cart_calculate_feesincludes\template-designer.php:20
actionwoocommerce_get_item_dataincludes\template-designer.php:21
filterwoocommerce_ajax_variation_thresholdincludes\template-designer.php:22
filterwoocommerce_cart_item_thumbnailincludes\template-designer.php:23
filterwoocommerce_store_api_cart_item_imagesincludes\template-designer.php:24
actionbefore_woocommerce_initindex.php:17
actioninitindex.php:30
Maintenance & Trust

Popcustoms – Print on demand & dropshipping, Free Personalizer Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 7, 2025
PHP min version8.0
Downloads6K

Community Trust

Rating88/100
Number of ratings5
Active installs100
Developer Profile

Popcustoms – Print on demand & dropshipping, Free Personalizer Developer Profile

popcustoms

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Popcustoms – Print on demand & dropshipping, Free Personalizer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/popcustoms-integration-for-woocommerce/includes/admin.php/wp-content/plugins/popcustoms-integration-for-woocommerce/includes/admin-dashboard.php/wp-content/plugins/popcustoms-integration-for-woocommerce/includes/integration.php/wp-content/plugins/popcustoms-integration-for-woocommerce/includes/shipping.php/wp-content/plugins/popcustoms-integration-for-woocommerce/includes/template-designer.php
Script Paths
https://popcustoms.com/cn-template-designer.jshttps://popcustoms.com/template-designer.js

HTML / DOM Fingerprints

CSS Classes
pop-support-template-designer
Data Attributes
data-pop-storedata-pop-sku
Shortcode Output
<span style="display:none">pop:
FAQ

Frequently Asked Questions about Popcustoms – Print on demand & dropshipping, Free Personalizer