
Product Catalog Mode For WooCommerce Security & Risk Analysis
wordpress.org/plugins/product-catalog-mode-for-woocommerceProduct Catalog Mode for WooCommerce TURN INTO your online store as CATALOG ONLY MODE hiding by product price, Add to Cart button on a single click.
Is Product Catalog Mode For WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Product Catalog Mode For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "product-catalog-mode-for-woocommerce" plugin v2.1.1 exhibits a generally positive security posture with no known vulnerabilities recorded historically. Static analysis reveals a limited attack surface, with only one shortcode identified and no unprotected entry points. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries and making no external HTTP requests or file operations, significantly reducing common attack vectors. However, there are notable areas of concern. A significant portion (40%) of the plugin's output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is included in these outputs. Furthermore, the taint analysis indicates two flows with unsanitized paths, which, while not classified as critical or high severity in this specific analysis, represent a potential risk for path traversal or file inclusion vulnerabilities. The absence of nonce checks and capability checks for its single entry point (the shortcode) is also a concern, as it means that any authenticated user could potentially trigger the functionality associated with this shortcode without proper authorization or protection against replay attacks. The bundled Freemius library also requires attention, as outdated versions can be a source of vulnerabilities, though its specific version (v1.0) is not flagged as immediately problematic without further context on its own vulnerability history.
Key Concerns
- Significant portion of output not properly escaped
- Taint analysis shows unsanitized paths
- No nonce checks on entry points
- No capability checks on entry points
- Bundled Freemius v1.0 library (potential for outdated code)
Product Catalog Mode For WooCommerce Security Vulnerabilities
Product Catalog Mode For WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Product Catalog Mode For WooCommerce Attack Surface
Shortcodes 1
WordPress Hooks 28
Maintenance & Trust
Product Catalog Mode For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Product Catalog Mode For WooCommerce Alternatives
Remove Product Content for WooCommerce
remove-product-content-for-woocommerce
The Remove Product Content for WooCommerce plugin allows store owners to easily customize product pages by removing unwanted sections or elements.
Product Catalog Feed by PixelYourSite
product-catalog-feed
WooCommerce auto-updated XML feeds for Facebook Product Catalogs (Dynamic Product Ads, Facebook Shops, Instagram), Google Merchant, and Pinterest Cata …
Remove Add to Cart Button for WooCommerce
remove-add-to-cart-button-for-woocommerce
Remove Add to Cart Button for WooCommerce plugin gives you a really easy interface to hide/remove the product Add to Cart button and product price.
Pinterest for WooCommerce
pinterest-for-woocommerce
Get your products in front of Pinterest users searching for ideas and things to buy. Connect your WooCommerce store to make your catalog browsable.
Product Enquiry for WooCommerce
product-enquiry-for-woocommerce
Product Enquiry allows prospective customers to "Make an Enquiry" about a product, or "Request a Quote" right from within the product page.
Product Catalog Mode For WooCommerce Developer Profile
4 plugins · 780 total installs
How We Detect Product Catalog Mode For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-catalog-mode-for-woocommerce/css/wapcm-settings.css/wp-content/plugins/product-catalog-mode-for-woocommerce/js/wapcm-settings.js/wp-content/plugins/product-catalog-mode-for-woocommerce/assets/css/frontend.css/wp-content/plugins/product-catalog-mode-for-woocommerce/assets/js/frontend.js/wp-content/plugins/product-catalog-mode-for-woocommerce/assets/js/frontend.min.js/wp-content/plugins/product-catalog-mode-for-woocommerce/js/wapcm-settings.js/wp-content/plugins/product-catalog-mode-for-woocommerce/assets/js/frontend.js/wp-content/plugins/product-catalog-mode-for-woocommerce/assets/js/frontend.min.jsproduct-catalog-mode-for-woocommerce/css/wapcm-settings.css?ver=product-catalog-mode-for-woocommerce/js/wapcm-settings.js?ver=product-catalog-mode-for-woocommerce/assets/css/frontend.css?ver=product-catalog-mode-for-woocommerce/assets/js/frontend.js?ver=product-catalog-mode-for-woocommerce/assets/js/frontend.min.js?ver=HTML / DOM Fingerprints
wapcm-plugins-gopro<!-- Product Catalog Mode For WooCommerce -->DO NOT REMOVE THIS IF, IT IS ESSENTIAL FOR THE `function_exists` CALL ABOVE TO PROPERLY WORK.<!-- Awesome Premium Features in Product Catalog Mode For WooCommerce Plugin -->data-wapcm-disable-add-to-cartdata-wapcm-disable-pricedata-wapcm-disable-buy-nowdata-wapcm-disable-checkoutdata-wapcm-hide-remove-cartdata-wapcm-hide-mini-cartwapcm_fs