Products Wizard Lite for WooCommerce Security & Risk Analysis

wordpress.org/plugins/products-wizard-lite-for-woocommerce

This plugin helps you sell your products by the step-by-step wizard. Use the [woocommerce-products-wizard] shortcode to init.

30 active installs v2.0.0 PHP 7.4+ WP 4.5+ Updated Feb 17, 2026
composite-productwoocommerce-bundlewoocommerce-product-bundle
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Products Wizard Lite for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Products Wizard Lite for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "products-wizard-lite-for-woocommerce" plugin v2.0.0 demonstrates a generally strong security posture, adhering to many WordPress security best practices. The plugin utilizes prepared statements for all SQL queries and shows a high percentage of properly escaped outputs. Nonce and capability checks are present on all identified entry points, which is commendable. The absence of external HTTP requests and bundled libraries further reduces the attack surface.

However, the presence of the `unserialize` function, even if not immediately flagged by taint analysis, is a potential concern. While taint analysis did not reveal critical or high-severity unsanitized flows, the fact that 2 out of 4 flows had unsanitized paths warrants caution. The vulnerability history is clean, indicating a lack of publicly disclosed security issues, which is a positive sign, but it doesn't entirely negate the risks associated with potentially dangerous functions or unsanitized data flows.

In conclusion, the plugin has many strengths, particularly in its handling of SQL and output escaping. The absence of known vulnerabilities is also a significant positive. The primary areas for improvement and continued monitoring are the use of `unserialize` and the observed unsanitized paths in taint analysis, which could represent a latent risk that may be exploited under specific conditions.

Key Concerns

  • Use of unserialize function
  • Flows with unsanitized paths detected
Vulnerabilities
None known

Products Wizard Lite for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Products Wizard Lite for WooCommerce Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
26
888 escaped
Nonce Checks
5
Capability Checks
5
File Operations
2
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$item = is_array($item) ? $item : (array) unserialize($item);includes\classes\Cart.php:222

Output Escaping

97% escaped914 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
outputItemSettingsFormAjax (includes\classes\Admin\Extensions\AdvancedDataTable.php:240)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Products Wizard Lite for WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 1

authwp_ajax_wcpwSearchProductCategoriesincludes\classes\Entities\ProductCategory.php:20

Shortcodes 2

[woocommerce-products-wizard] includes\global\shortcodes.php:12
[wcpw-cart-total-price] includes\global\shortcodes.php:35
WordPress Hooks 60
actionadmin_enqueue_scriptsincludes\classes\Admin\Admin.php:32
actionbulk_edit_custom_boxincludes\classes\Admin\Admin.php:35
actionwcpw_output_settings_table_rowincludes\classes\Admin\Admin.php:38
actionwcpw_output_setting_fieldincludes\classes\Admin\Admin.php:39
actionedit_form_topincludes\classes\Admin\Admin.php:40
filterplugin_action_linksincludes\classes\Admin\Admin.php:43
filterplugin_row_metaincludes\classes\Admin\Admin.php:44
actionadd_meta_boxesincludes\classes\Admin\Entities\PostType.php:37
actionadmin_enqueue_scriptsincludes\classes\Admin\Entities\PostType.php:38
actionadmin_footerincludes\classes\Admin\Extensions\AdvancedDataTable.php:76
filterwoocommerce_get_settings_pagesincludes\classes\Admin\SettingsPage.php:19
filterwoocommerce_cart_item_remove_linkincludes\classes\Cart\WooCommerce.php:34
filterwoocommerce_cart_item_quantityincludes\classes\Cart\WooCommerce.php:35
filterwoocommerce_cart_item_classincludes\classes\Cart\WooCommerce.php:36
filterwoocommerce_cart_item_priceincludes\classes\Cart\WooCommerce.php:37
filterwoocommerce_cart_item_subtotalincludes\classes\Cart\WooCommerce.php:38
filterwoocommerce_cart_item_thumbnailincludes\classes\Cart\WooCommerce.php:39
filterwoocommerce_cart_item_nameincludes\classes\Cart\WooCommerce.php:40
filterwoocommerce_cart_item_visibleincludes\classes\Cart\WooCommerce.php:41
filterwoocommerce_widget_cart_item_visibleincludes\classes\Cart\WooCommerce.php:42
filterwoocommerce_checkout_cart_item_visibleincludes\classes\Cart\WooCommerce.php:43
filterwoocommerce_get_item_dataincludes\classes\Cart\WooCommerce.php:44
actionwoocommerce_before_calculate_totalsincludes\classes\Cart\WooCommerce.php:45
actionwoocommerce_after_cart_item_quantity_updateincludes\classes\Cart\WooCommerce.php:48
actionwoocommerce_remove_cart_itemincludes\classes\Cart\WooCommerce.php:51
actionwoocommerce_cart_item_removedincludes\classes\Cart\WooCommerce.php:52
actionwoocommerce_before_cart_item_quantity_zeroincludes\classes\Cart\WooCommerce.php:53
actionwoocommerce_before_cart_item_quantity_zeroincludes\classes\Cart\WooCommerce.php:54
actionwoocommerce_restore_cart_itemincludes\classes\Cart\WooCommerce.php:55
actionwoocommerce_cart_item_restoredincludes\classes\Cart\WooCommerce.php:56
filterwcpw_remove_main_cart_reflected_productsincludes\classes\Cart\WooCommerce.php:131
actionwpincludes\classes\Cart.php:74
actioninitincludes\classes\Core.php:100
actionplugins_loadedincludes\classes\Core.php:101
actionbefore_woocommerce_initincludes\classes\Core.php:102
actionplugins_loadedincludes\classes\Core.php:103
actionwcpw_beforeincludes\classes\Core.php:106
actionadmin_noticesincludes\classes\Core.php:180
filterwoocommerce_hidden_order_itemmetaincludes\classes\Entities\Order.php:26
filterwoocommerce_admin_order_item_thumbnailincludes\classes\Entities\Order.php:27
actionwoocommerce_checkout_create_order_line_itemincludes\classes\Entities\Order.php:30
actionwoocommerce_checkout_update_order_metaincludes\classes\Entities\Order.php:31
filterwoocommerce_order_item_visibleincludes\classes\Entities\Order.php:34
filterwoocommerce_order_item_thumbnailincludes\classes\Entities\Order.php:35
filterwoocommerce_order_formatted_line_subtotalincludes\classes\Entities\Order.php:36
filterwoocommerce_order_item_get_formatted_meta_dataincludes\classes\Entities\Order.php:37
actioninitincludes\classes\Entities\Traits\PostType.php:35
actionplugins_loadedincludes\classes\Entities\Traits\PostType.php:36
actionadmin_enqueue_scriptsincludes\classes\Entities\Wizard\Admin.php:78
actionadmin_footerincludes\classes\Entities\Wizard\Admin.php:79
actionadmin_noticesincludes\classes\Entities\Wizard\Admin.php:80
actionwcpw_beforeincludes\classes\Entities\Wizard.php:50
actionwcpw_before_outputincludes\classes\Entities\Wizard.php:51
actionwcpw_after_outputincludes\classes\Entities\Wizard.php:52
actionplugins_loadedincludes\classes\Entities\WizardStep.php:49
actionwp_loadedincludes\classes\Form.php:80
actionwcpw_before_add_all_to_main_cartincludes\classes\Form.php:81
actionwcpw_after_add_all_to_main_cartincludes\classes\Form.php:82
actionwcpw_form_products_requestincludes\classes\Form.php:83
filteradmin_noticesproducts-wizard-lite-for-woocommerce.php:77
Maintenance & Trust

Products Wizard Lite for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version7.4
Downloads995

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Products Wizard Lite for WooCommerce Developer Profile

Alex Troll

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Products Wizard Lite for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/products-wizard-lite-for-woocommerce/assets/admin/scss/app.css/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/advanced-data-table.js/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/data-table.js/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/hooks.js/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/multi-select.js/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/shared-editor-modal.js/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/thumbnail.js
Script Paths
/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/shared-editor-modal.js/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/advanced-data-table.js/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/data-table.js/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/multi-select.js/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/thumbnail.js/wp-content/plugins/products-wizard-lite-for-woocommerce/src/admin/js/hooks.js
Version Parameters
products-wizard-lite-for-woocommerce/assets/admin/scss/app.css?ver=products-wizard-lite-for-woocommerce/src/admin/js/shared-editor-modal.js?ver=products-wizard-lite-for-woocommerce/src/admin/js/advanced-data-table.js?ver=products-wizard-lite-for-woocommerce/src/admin/js/data-table.js?ver=products-wizard-lite-for-woocommerce/src/admin/js/multi-select.js?ver=products-wizard-lite-for-woocommerce/src/admin/js/thumbnail.js?ver=products-wizard-lite-for-woocommerce/src/admin/js/hooks.js?ver=

HTML / DOM Fingerprints

CSS Classes
wcpw-app
JS Globals
WC_PRODUCTS_WIZARD_VERSIONWC_PRODUCTS_WIZARD_DEBUGWC_PRODUCTS_WIZARD_ROOT_FILEWC_PRODUCTS_WIZARD_THEME_TEMPLATES_DIRWC_PRODUCTS_WIZARD_PLUGIN_PATHWC_PRODUCTS_WIZARD_PLUGIN_URL+3 more
FAQ

Frequently Asked Questions about Products Wizard Lite for WooCommerce