
Purchased Items Column for WooCommerce Orders Security & Risk Analysis
wordpress.org/plugins/purchased-items-column-woocommerceDisplay a "Purchased Items" column on the WooCommerce orders page.
Is Purchased Items Column for WooCommerce Orders Safe to Use in 2026?
Generally Safe
Score 100/100Purchased Items Column for WooCommerce Orders has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'purchased-items-column-woocommerce' plugin v1.9.2 demonstrates some good security practices, such as using prepared statements for all SQL queries and having no recorded vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests is also a positive sign. However, a significant concern arises from the presence of one AJAX handler that lacks proper authentication checks. This creates a potential entry point for unauthenticated users to interact with the plugin's backend functionality, which could lead to unexpected behavior or even exploitation if the handler performs sensitive operations.
While the taint analysis shows no critical or high-severity flows, the single unprotected AJAX handler remains a notable weakness. The plugin also has a single entry point that is unprotected, mirroring the concern with the AJAX handler. Coupled with a low percentage of properly escaped outputs, there's a moderate risk that improperly handled data could lead to cross-site scripting (XSS) vulnerabilities in certain scenarios. The plugin's history of no vulnerabilities is encouraging, but the identified attack surface and output escaping issues warrant attention to maintain a secure posture.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
- Single unprotected entry point
Purchased Items Column for WooCommerce Orders Security Vulnerabilities
Purchased Items Column for WooCommerce Orders Release Timeline
Purchased Items Column for WooCommerce Orders Code Analysis
Output Escaping
Purchased Items Column for WooCommerce Orders Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Purchased Items Column for WooCommerce Orders Maintenance & Trust
Maintenance Signals
Community Trust
Purchased Items Column for WooCommerce Orders Alternatives
Dashify: WooCommerce admin dashboard theme
dashify
A modern design and UI for the WooCommerce admin. Manage, search, and navigate orders faster. Make the WordPress admin dashboard ecommerce-focused.
ShoppingFeed
shopping-feed
WordPress connection Controller Plugin for ShoppingFeed - Sell on Amazon, Ebay, Google, and 1000's of international marketplaces
SunCart Data Migration from Shopify for WooCommerce
suncart-data-migration-from-shopify-for-woocommerce
Import products, collections, blog articles, pages, orders and customers from your Shopify store into WooCommerce with ease and accuracy.
Export All Posts, Products, Orders, Refunds & Users
wp-ultimate-exporter
Export any WordPress website including WooCommerce data seamlessly with our powerful export plugin. Save records as CSV, XML, or Excel file for secure …
Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers
woocommerce-exporter
Export WooCommerce products, orders, customers, categories, tags, subscriptions & more into formatted files like CSV, XML, Excel 2007, XLS, XLSX.
Purchased Items Column for WooCommerce Orders Developer Profile
10 plugins · 80K total installs
How We Detect Purchased Items Column for WooCommerce Orders
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
show_order_itemsdata-wc-orderpipdig_wc_find_products_noncepipdig_wc_find_products_ajax/wp-json/pipdig/wc/v1/products