PowerUp! for WooCommerce Security & Risk Analysis

wordpress.org/plugins/powerup-for-woocommerce

Power up your WooCommerce with over 50 popular options without writing any code!

10 active installs v1.0.3 PHP + WP 4.4+ Updated Apr 15, 2021
woocommercewoocommerce-filterswoocommerce-shopwoocommerce-text
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PowerUp! for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

PowerUp! for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin "powerup-for-woocommerce" v1.0.3 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces the potential attack surface. Furthermore, the code signals indicate no dangerous functions, file operations, or external HTTP requests, which are common vectors for exploitation. The complete reliance on prepared statements for SQL queries is a notable strength, mitigating SQL injection risks. However, a concerning aspect is the low percentage of properly escaped output (38%), suggesting that user-supplied data might not be adequately sanitized before being displayed to users, potentially leading to cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history is positive, implying a commitment to security or simply a lack of past exposure. Despite the low output escaping rate, the overall lack of exploitable patterns and historical issues points towards a plugin that, while not perfect, has a solid foundation. The primary concern lies in the potential for XSS due to insufficient output escaping. Addressing this would significantly improve its security profile.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

PowerUp! for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PowerUp! for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped8 total outputs
Attack Surface

PowerUp! for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 35
filterwc_powerup_settingsincludes\class-wc-powerup-integrations.php:49
filterwoocommerce_product_add_to_cart_textincludes\class-wc-powerup-integrations.php:50
actionadmin_noticeswoocommerce-powerup.php:36
actionadmin_noticeswoocommerce-powerup.php:42
actioninitwoocommerce-powerup.php:82
filterwoocommerce_get_settings_pageswoocommerce-powerup.php:88
filterplugin_row_metawoocommerce-powerup.php:94
actionwoocommerce_initwoocommerce-powerup.php:102
filterwoocommerce_product_single_add_to_cart_textwoocommerce-powerup.php:192
filterwoocommerce_product_add_to_cart_textwoocommerce-powerup.php:196
filterwoocommerce_sale_flashwoocommerce-powerup.php:208
filterwoocommerce_get_availability_textwoocommerce-powerup.php:212
filterwoocommerce_get_availability_textwoocommerce-powerup.php:216
filterwoocommerce_get_breadcrumbwoocommerce-powerup.php:220
filterwoocommerce_show_page_titlewoocommerce-powerup.php:224
filterwoocommerce_page_titlewoocommerce-powerup.php:228
actionwoocommerce_archive_descriptionwoocommerce-powerup.php:232
filterwoocommerce_add_to_cart_redirectwoocommerce-powerup.php:236
filtergettextwoocommerce-powerup.php:240
filtergettextwoocommerce-powerup.php:244
filtergettextwoocommerce-powerup.php:248
filtergettextwoocommerce-powerup.php:252
filtergettextwoocommerce-powerup.php:256
filtergettextwoocommerce-powerup.php:260
filtergettextwoocommerce-powerup.php:264
actionwoocommerce_after_add_to_cart_buttonwoocommerce-powerup.php:268
actionwoocommerce_after_shop_loop_itemwoocommerce-powerup.php:269
actionwoocommerce_single_product_summarywoocommerce-powerup.php:273
filterwoocommerce_add_cart_item_datawoocommerce-powerup.php:277
filterwoocommerce_package_rateswoocommerce-powerup.php:281
actionwp_enqueue_scriptswoocommerce-powerup.php:285
actionwoocommerce_after_cart_tablewoocommerce-powerup.php:289
filterwoocommerce_currencieswoocommerce-powerup.php:293
filterwoocommerce_currency_symbolwoocommerce-powerup.php:294
filterwoocommerce_show_page_titlewoocommerce-powerup.php:456
Maintenance & Trust

PowerUp! for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedApr 15, 2021
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

PowerUp! for WooCommerce Developer Profile

3 Mini Monsters

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PowerUp! for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/powerup-for-woocommerce/assets/css/powerup-admin.css/wp-content/plugins/powerup-for-woocommerce/assets/js/powerup-admin.js
Version Parameters
powerup-for-woocommerce/assets/css/powerup-admin.css?ver=powerup-for-woocommerce/assets/js/powerup-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
powerup-notice
HTML Comments
<!-- The Admin Bar Menu is created by PowerUp! --><!-- Admin Bar Menu (Generated by PowerUp!) -->
JS Globals
PowerupAdmin
FAQ

Frequently Asked Questions about PowerUp! for WooCommerce