Popular Products Block for WooCommerce – Show Most Viewed or Sold Products Security & Risk Analysis

wordpress.org/plugins/popular-products-block

Display WooCommerce Popular Products in your website post or pages.

200 active installs v1.0.1 PHP 7.1+ WP 6.5+ Updated Mar 9, 2026
best-selling-productsblockgutenberg-blockpopular-productswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Popular Products Block for WooCommerce – Show Most Viewed or Sold Products Safe to Use in 2026?

Generally Safe

Score 100/100

Popular Products Block for WooCommerce – Show Most Viewed or Sold Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The "popular-products-block" plugin version 1.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and the complete reliance on prepared statements for SQL queries are significant strengths. Furthermore, the plugin demonstrates good practices by implementing capability checks and nonce checks on its entry points, which are crucial for protecting against common attack vectors. The limited attack surface, with no unprotected entry points, further contributes to its relative security.

However, a notable concern is the output escaping. With 25% of outputs not being properly escaped, there's a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered directly to the page without proper sanitization. While the taint analysis did not reveal any direct unsanitized flows, the high percentage of unescaped outputs warrants attention. The single external HTTP request, though not flagged as an immediate risk, should be monitored for potential vulnerabilities related to the external service it communicates with.

In conclusion, "popular-products-block" v1.0.1 has a solid foundation with good security practices in place, particularly regarding authentication and data integrity. The primary area for improvement lies in ensuring comprehensive output escaping to mitigate potential XSS risks. The lack of historical vulnerabilities is a positive indicator, suggesting consistent attention to security by the developers.

Key Concerns

  • Unescaped output (25% of 102 outputs)
  • Bundled Freemius library
Vulnerabilities
None known

Popular Products Block for WooCommerce – Show Most Viewed or Sold Products Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Popular Products Block for WooCommerce – Show Most Viewed or Sold Products Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
76 escaped
Nonce Checks
4
Capability Checks
7
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

75% escaped102 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
fs_init (freemius-lite\inc\Base\FSActivate.php:68)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Popular Products Block for WooCommerce – Show Most Viewed or Sold Products Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_fs_initfreemius-lite\inc\Base\FSActivate.php:42

Shortcodes 1

[wppb] inc\adminMenu.php:14
WordPress Hooks 18
actionadmin_headfreemius-lite\inc\Base\FSActivate.php:29
actionadmin_enqueue_scriptsfreemius-lite\inc\Base\FSActivate.php:30
actionadmin_menufreemius-lite\inc\Base\FSActivate.php:33
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:38
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:39
actionadmin_noticesfreemius-lite\inc\Base\FSActivate.php:44
actioninitfreemius-lite\inc\Base\FS_Lite.php:29
actionadmin_menuinc\adminMenu.php:8
actionadmin_menuinc\adminMenu.php:9
actionadmin_enqueue_scriptsinc\adminMenu.php:10
actioninitinc\adminMenu.php:13
filtermanage_wppb_posts_columnsinc\adminMenu.php:17
actionmanage_wppb_posts_custom_columninc\adminMenu.php:18
filteruse_block_editor_for_postinc\adminMenu.php:21
actioninitindex.php:88
actionplugins_loadedindex.php:89
actionenqueue_block_editor_assetsindex.php:90
actionadmin_noticesindex.php:100
Maintenance & Trust

Popular Products Block for WooCommerce – Show Most Viewed or Sold Products Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.1
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Popular Products Block for WooCommerce – Show Most Viewed or Sold Products Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Popular Products Block for WooCommerce – Show Most Viewed or Sold Products

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/popular-products-block/build/render.asset.php/wp-content/plugins/popular-products-block/build/index.js/wp-content/plugins/popular-products-block/build/style-index.css
Script Paths
/wp-content/plugins/popular-products-block/build/index.js
Version Parameters
popular-products-block/build/index.js?ver=popular-products-block/build/style-index.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-popular-products-block-popular-products-block
Data Attributes
data-wpp-block-settings
JS Globals
wppbpipecheck
FAQ

Frequently Asked Questions about Popular Products Block for WooCommerce – Show Most Viewed or Sold Products