
Premmerce Security & Risk Analysis
wordpress.org/plugins/premmercePremmerce is a must-have toolkit for WooCommerce with a detailed Setup Wizard for your store.
Is Premmerce Safe to Use in 2026?
Generally Safe
Score 93/100Premmerce has a strong security track record. Known vulnerabilities have been patched promptly.
The Premmerce plugin v1.3.22 presents a mixed security posture. While it demonstrates good practices in SQL query handling with 100% prepared statements and a high rate of output escaping, significant concerns arise from its attack surface and vulnerability history. The presence of two AJAX handlers without authentication checks creates a direct entry point for unauthorized actions. Taint analysis, though showing no critical or high severity unsanitized flows, still indicates six flows with unsanitized paths, suggesting potential for vulnerabilities if not handled carefully in future updates. The plugin's history of four known CVEs, including a high severity cross-site scripting (XSS) vulnerability and PHP remote file inclusion (RFI) issues, is a significant red flag. The recentness of the last reported vulnerability (2026-02-06) is also concerning, indicating ongoing issues. The combination of an exposed attack surface and past critical vulnerability types points to a need for heightened vigilance.
Key Concerns
- 2 AJAX handlers without auth checks
- 6 flows with unsanitized paths
- 1 high severity vulnerability in history
- 3 medium severity vulnerabilities in history
- Bundled Freemius v1.0 library
- 67% output escaping is not properly escaped
Premmerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Premmerce <= 1.3.20 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'premmerce_wizard_actions' AJAX Endpoint
Premmerce <= 1.3.19 - Unauthenticated Local File Inclusion
Premmerce <= 1.3.19 - Cross-Site Request Forgery
Premmerce <= 1.3.18 - Cross-Site Request Forgery via runAction
Premmerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Premmerce Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 36
Maintenance & Trust
Premmerce Maintenance & Trust
Maintenance Signals
Community Trust
Premmerce Developer Profile
14 plugins · 60K total installs
How We Detect Premmerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/premmerce-product-comparison/frontend/css/premmerce-product-comparison.css/wp-content/plugins/premmerce-product-comparison/frontend/js/premmerce-product-comparison.js/wp-content/plugins/premmerce-woocommerce-toolkit/assets/css/admin/premium.css/wp-content/plugins/premmerce-woocommerce-toolkit/assets/css/frontend/premium.css/wp-content/plugins/premmerce-woocommerce-toolkit/assets/js/admin/premium.js/wp-content/plugins/premmerce-woocommerce-toolkit/assets/js/frontend/premium.js/wp-content/plugins/premmerce-product-comparison/frontend/js/premmerce-product-comparison.jsHTML / DOM Fingerprints
premmerce-product-comparisondata-premmerce-compare-url/wp-json/premmerce/comparison/delete/[comparisons_page]