Recently Purchased Products For Woo Security & Risk Analysis

wordpress.org/plugins/recently-purchased-products-for-woo

Display Recently Purchased Products For Woocommerce using Widget and Shortcode

70 active installs v1.1.8 PHP 7.4+ WP 5.8+ Updated Aug 21, 2025
last-purchasespurchasesrecent-ordersrecent-purchaseswoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEMar 4, 2025
Safety Verdict

Is Recently Purchased Products For Woo Safe to Use in 2026?

Generally Safe

Score 99/100

Recently Purchased Products For Woo has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 4, 2025Updated 7mo ago
Risk Assessment

The 'recently-purchased-products-for-woo' plugin v1.1.8 exhibits a generally good security posture based on the static analysis. The plugin effectively utilizes prepared statements for all SQL queries and has a high rate of properly escaped output, minimizing common web vulnerabilities. The absence of dangerous functions, file operations, external HTTP requests, and a lack of critical or high-severity taint flows are positive indicators. The attack surface is also minimal, with no unprotected entry points identified.

However, a significant concern arises from the plugin's vulnerability history, which includes one known CVE. Although currently unpatched CVEs are zero, the presence of a past medium-severity vulnerability, specifically Cross-site Scripting (XSS), suggests potential areas where input validation or output sanitization might be insufficient in certain contexts. The fact that the last vulnerability was recorded in early 2025 could indicate a recurring issue or a recent fix that hasn't yet been fully tested in real-world scenarios, but the data shows it's unpatched. The lack of any nonce checks or capability checks for its entry points, while currently not leading to identified vulnerabilities, represents a potential oversight that could be exploited in future versions or in combination with other weaknesses.

In conclusion, the plugin demonstrates good coding practices regarding data handling and output escaping. The minimal attack surface and lack of identified critical issues in the static analysis are strengths. The primary weakness lies in its vulnerability history, particularly the past XSS vulnerability, and the absence of explicit nonce and capability checks on its entry points. While the current version appears to be secure against newly discovered threats, the historical pattern warrants careful monitoring and consideration for future updates.

Key Concerns

  • Past medium severity vulnerability (XSS)
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
1

Recently Purchased Products For Woo Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-1008medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Recently Purchased Products For Woo <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via view Parameter

Mar 4, 2025 Patched in 1.1.4 (3d)
Code Analysis
Analyzed Mar 16, 2026

Recently Purchased Products For Woo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
206 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped213 total outputs
Attack Surface

Recently Purchased Products For Woo Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[recently_purchased_products] includes\class-rppw-public.php:585
[recently_purchased_products_slider] includes\class-rppw-public.php:587
WordPress Hooks 8
actionwp_enqueue_scriptsincludes\class-rppw-scripts.php:86
actionadmin_enqueue_scriptsincludes\class-rppw-scripts.php:89
actionwidgets_initincludes\widget\class-rppw-widget.php:452
actionadmin_noticesrecently-purchased-products-for-woo.php:171
actionplugins_loadedrecently-purchased-products-for-woo.php:175
actionelementor/widgets/registerrecently-purchased-products-for-woo.php:207
actionadmin_noticesrecently-purchased-products-for-woo.php:225
actionadmin_initrecently-purchased-products-for-woo.php:243
Maintenance & Trust

Recently Purchased Products For Woo Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 21, 2025
PHP min version7.4
Downloads5K

Community Trust

Rating80/100
Number of ratings4
Active installs70
Developer Profile

Recently Purchased Products For Woo Developer Profile

World Web Technology

4 plugins · 2K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Recently Purchased Products For Woo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/recently-purchased-products-for-woo/includes/widget/css/rppw-widget.css/wp-content/plugins/recently-purchased-products-for-woo/includes/widget/js/rppw-widget.js
Script Paths
/wp-content/plugins/recently-purchased-products-for-woo/includes/widget/js/rppw-widget.js
Version Parameters
recently-purchased-products-for-woo/includes/widget/css/rppw-widget.css?ver=recently-purchased-products-for-woo/includes/widget/js/rppw-widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
rppw-widget-content
Data Attributes
data-rppw-post_typedata-rppw-posts_per_pagedata-rppw-orderbydata-rppw-orderdata-rppw-titledata-rppw-description+4 more
JS Globals
rppw_widget_ajax_object
Shortcode Output
[recently_purchased_products]
FAQ

Frequently Asked Questions about Recently Purchased Products For Woo