
Recently Purchased Products For Woo Security & Risk Analysis
wordpress.org/plugins/recently-purchased-products-for-wooDisplay Recently Purchased Products For Woocommerce using Widget and Shortcode
Is Recently Purchased Products For Woo Safe to Use in 2026?
Generally Safe
Score 99/100Recently Purchased Products For Woo has a strong security track record. Known vulnerabilities have been patched promptly.
The 'recently-purchased-products-for-woo' plugin v1.1.8 exhibits a generally good security posture based on the static analysis. The plugin effectively utilizes prepared statements for all SQL queries and has a high rate of properly escaped output, minimizing common web vulnerabilities. The absence of dangerous functions, file operations, external HTTP requests, and a lack of critical or high-severity taint flows are positive indicators. The attack surface is also minimal, with no unprotected entry points identified.
However, a significant concern arises from the plugin's vulnerability history, which includes one known CVE. Although currently unpatched CVEs are zero, the presence of a past medium-severity vulnerability, specifically Cross-site Scripting (XSS), suggests potential areas where input validation or output sanitization might be insufficient in certain contexts. The fact that the last vulnerability was recorded in early 2025 could indicate a recurring issue or a recent fix that hasn't yet been fully tested in real-world scenarios, but the data shows it's unpatched. The lack of any nonce checks or capability checks for its entry points, while currently not leading to identified vulnerabilities, represents a potential oversight that could be exploited in future versions or in combination with other weaknesses.
In conclusion, the plugin demonstrates good coding practices regarding data handling and output escaping. The minimal attack surface and lack of identified critical issues in the static analysis are strengths. The primary weakness lies in its vulnerability history, particularly the past XSS vulnerability, and the absence of explicit nonce and capability checks on its entry points. While the current version appears to be secure against newly discovered threats, the historical pattern warrants careful monitoring and consideration for future updates.
Key Concerns
- Past medium severity vulnerability (XSS)
- No nonce checks on entry points
- No capability checks on entry points
Recently Purchased Products For Woo Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Recently Purchased Products For Woo <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via view Parameter
Recently Purchased Products For Woo Code Analysis
Output Escaping
Recently Purchased Products For Woo Attack Surface
Shortcodes 2
WordPress Hooks 8
Maintenance & Trust
Recently Purchased Products For Woo Maintenance & Trust
Maintenance Signals
Community Trust
Recently Purchased Products For Woo Alternatives
Customer Recent Orders History for WooCommerce
recent-orders-widget-for-woocommerce
Display the customer's recent order list on the frontend in WooCommerce.
Sales Notifications for WooCommerce – Recent Sales Popup
wc-live-sale-notifications
Sales Notifications for WooCommerce - Recent Sales Popup boosts sales by showing recent orders in a popup with customer and product details.
Invoices by Customer
invoices-by-customer-347
Obtain a list of invoices by quarter and year for customers who exceed a certain amount.
Popify – Sales Popups & Social Proof
popify-sales-pop-ups
Popify is the all-in-one tool for creating trust-driven sales and social proof popups that increase engagement and grow conversions.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Recently Purchased Products For Woo Developer Profile
4 plugins · 2K total installs
How We Detect Recently Purchased Products For Woo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recently-purchased-products-for-woo/includes/widget/css/rppw-widget.css/wp-content/plugins/recently-purchased-products-for-woo/includes/widget/js/rppw-widget.js/wp-content/plugins/recently-purchased-products-for-woo/includes/widget/js/rppw-widget.jsrecently-purchased-products-for-woo/includes/widget/css/rppw-widget.css?ver=recently-purchased-products-for-woo/includes/widget/js/rppw-widget.js?ver=HTML / DOM Fingerprints
rppw-widget-contentdata-rppw-post_typedata-rppw-posts_per_pagedata-rppw-orderbydata-rppw-orderdata-rppw-titledata-rppw-description+4 morerppw_widget_ajax_object[recently_purchased_products]