Public Woo Api Security & Risk Analysis

wordpress.org/plugins/public-woo-api

Allows to fetch WooCommerce products, categories, tags, variations and reviews without authentication.

70 active installs v1.1.3 PHP 5.6+ WP 4.8+ Updated Apr 4, 2022
progressive-web-appspwareactwoocommerce-rest-api
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Public Woo Api Safe to Use in 2026?

Generally Safe

Score 85/100

Public Woo Api has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The 'public-woo-api' plugin v1.1.3 presents a generally good security posture based on the provided static analysis. The absence of any identified CVEs, unpatched vulnerabilities, or common vulnerability types in its history suggests a history of responsible development and maintenance. Furthermore, the static analysis shows no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, no external HTTP requests, and no identified taint flows. This indicates a low risk of common web application vulnerabilities such as SQL injection, local file inclusion, or remote code execution through these avenues.

Key Concerns

  • Half of output operations are not properly escaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Public Woo Api Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Public Woo Api Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped12 total outputs
Attack Surface

Public Woo Api Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionrest_api_initincludes\class-public-woo-api-endpoints.php:35
actionadmin_noticesincludes\class-public-woo-api.php:81
actionplugins_loadedincludes\class-public-woo-api.php:153
actionadmin_enqueue_scriptsincludes\class-public-woo-api.php:169
actionadmin_enqueue_scriptsincludes\class-public-woo-api.php:170
actionadmin_menuincludes\class-public-woo-api.php:172
actionadmin_initincludes\class-public-woo-api.php:173
actionrest_api_inittrunk\includes\class-public-woo-api-endpoints.php:35
actionadmin_noticestrunk\includes\class-public-woo-api.php:81
actionplugins_loadedtrunk\includes\class-public-woo-api.php:153
actionadmin_enqueue_scriptstrunk\includes\class-public-woo-api.php:169
actionadmin_enqueue_scriptstrunk\includes\class-public-woo-api.php:170
actionadmin_menutrunk\includes\class-public-woo-api.php:172
actionadmin_inittrunk\includes\class-public-woo-api.php:173
Maintenance & Trust

Public Woo Api Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedApr 4, 2022
PHP min version5.6
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs70
Developer Profile

Public Woo Api Developer Profile

Michael

1 plugin · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Public Woo Api

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/public-woo-api/admin/css/public-woo-api-admin.css/wp-content/plugins/public-woo-api/admin/js/public-woo-api-admin.js
Version Parameters
public-woo-api-admin.css?ver=public-woo-api-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Public Woo Api