Reco For Woocommerce Security & Risk Analysis

wordpress.org/plugins/reco-for-woocommerce

Sync WooCommerce orders with external product review service Reco.se and display high-quality rating widgets across your shop.

10 active installs v1.0.6 PHP 7.4+ WP 5.8+ Updated Apr 15, 2026
ecommerceproduct-reviewsratingsreviewswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Reco For Woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Reco For Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "reco-for-woocommerce" v1.0.6 plugin exhibits a generally strong security posture with several good practices evident. The code demonstrates excellent adherence to secure coding standards, with 100% of SQL queries using prepared statements and 99% of output being properly escaped, significantly mitigating risks of SQL injection and Cross-Site Scripting (XSS). The absence of any recorded vulnerabilities (CVEs) or dangerous functions is also a positive indicator. However, there are specific areas of concern within the static analysis. The plugin exposes 3 REST API routes without permission callbacks, creating potential unauthorized access vectors. Furthermore, 2 flows were identified with unsanitized paths in the taint analysis, which, while not critically or highly severe in this instance, warrants attention as it indicates potential for insecure file handling or path traversal if input is not strictly validated. The plugin also has a moderate attack surface with 14 entry points, 3 of which are unprotected.

Key Concerns

  • REST API routes without permission callbacks
  • Flows with unsanitized paths
  • Unprotected entry points
Vulnerabilities
None known

Reco For Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Reco For Woocommerce Release Timeline

v1.0.6Current
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Reco For Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
2
211 escaped
Nonce Checks
7
Capability Checks
7
File Operations
0
External Requests
10
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

99% escaped213 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
reco_handle_toggle_visibility_ajax (includes/settings-page.php:510)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Reco For Woocommerce Attack Surface

Entry Points14
Unprotected3

AJAX Handlers 6

authwp_ajax_reco_fetch_reviewsincludes/settings-page.php:475
authwp_ajax_reco_toggle_review_visibilityincludes/settings-page.php:508
authwp_ajax_reco_get_store_settingsincludes/settings-page.php:536
authwp_ajax_reco_test_connectionincludes/settings-page.php:592
authwp_ajax_reco_bulk_sync_ordersincludes/settings-page.php:652
authwp_ajax_reco_get_sync_statusincludes/settings-page.php:711

REST API Routes 3

GET/wp-json/reco/v1/rating/(?P<id>\d+)proxy/routes.php:6
GET/wp-json/reco/v1/rating-distribution/(?P<id>\d+)proxy/routes.php:11
GET/wp-json/reco/v1/reviews/(?P<id>\d+)proxy/routes.php:16

Shortcodes 5

[reco-rating] reco-for-woocommerce.php:41
[reco-rating-small] reco-for-woocommerce.php:44
[reco-rating-distribution] reco-for-woocommerce.php:47
[reco-reviews-list] reco-for-woocommerce.php:48
[reco-reviews-title] reco-for-woocommerce.php:49
WordPress Hooks 20
actionwoocommerce_new_orderincludes/order-sync.php:4
actionwoocommerce_update_orderincludes/order-sync.php:5
actionreco_sync_order_backgroundincludes/order-sync.php:6
actionadmin_initincludes/settings-page.php:83
actionadmin_menuincludes/settings-page.php:133
actionrest_api_initproxy/routes.php:5
actioninitreco-for-woocommerce.php:40
actionwp_enqueue_scriptsreco-for-woocommerce.php:53
filterthe_contentreco-for-woocommerce.php:64
filterwoocommerce_short_descriptionreco-for-woocommerce.php:65
filterwoocommerce_product_tabsreco-for-woocommerce.php:68
actionadmin_enqueue_scriptsreco-for-woocommerce.php:94
filterwoocommerce_structured_data_productreco-for-woocommerce.php:156
actionadmin_initreco-for-woocommerce.php:281
actionwp_enqueue_scriptsreco-for-woocommerce.php:315
actionwp_enqueue_scriptsreco-for-woocommerce.php:329
actionwoocommerce_after_shop_loop_item_titlereco-for-woocommerce.php:355
actionwoocommerce_before_shop_loop_item_titlereco-for-woocommerce.php:359
actionwoocommerce_after_shop_loop_itemreco-for-woocommerce.php:363
actionwoocommerce_before_shop_loop_itemreco-for-woocommerce.php:367
Maintenance & Trust

Reco For Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 15, 2026
PHP min version7.4
Downloads371

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Reco For Woocommerce Developer Profile

recotrust

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Reco For Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reco-for-woocommerce/assets/css/reco-rating.css
Script Paths
/wp-content/plugins/reco-for-woocommerce/assets/js/color-picker-init.js/wp-content/plugins/reco-for-woocommerce/assets/js/admin-settings.js
Version Parameters
reco-for-woocommerce/assets/css/reco-rating.css?ver=reco-for-woocommerce/assets/js/color-picker-init.js?ver=reco-for-woocommerce/assets/js/admin-settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
reco-rating-distribution-containerreco-rating-containerreco-rating-averagereco-rating-starsreco-rating-stars-wrapreco-rating-small-containerreco-reviews-list-containerreco-reviews-tab-content
Data Attributes
data-reco-product-iddata-reco-widget-settings
JS Globals
recoAdminSettings
Shortcode Output
[reco-rating][reco-rating-small][reco-rating-distribution][reco-reviews-list]
FAQ

Frequently Asked Questions about Reco For Woocommerce