Related Products Manager for WooCommerce Security & Risk Analysis

wordpress.org/plugins/related-products-manager-woocommerce

The plugin lets you customize the associated products in WooCommerce. You can change displayed WooCommerce related products number, columns, order, re …

1K active installs v1.6.5 PHP + WP 4.8+ Updated Dec 19, 2025
managerproductsrelatedrelated-productswoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 19, 2025
Safety Verdict

Is Related Products Manager for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Related Products Manager for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 19, 2025Updated 3mo ago
Risk Assessment

The 'related-products-manager-woocommerce' plugin v1.6.5 exhibits a generally strong security posture based on the provided static analysis. The absence of critical or high severity taint flows, alongside the use of prepared statements for all SQL queries and a high percentage of properly escaped output, are positive indicators. The plugin also demonstrates good practice with a reasonable number of nonce and capability checks, contributing to a reduced attack surface. However, the presence of one past medium severity Cross-Site Scripting (XSS) vulnerability, even though currently patched, warrants caution. This history suggests a potential for input sanitization issues that could be reintroduced in future versions or if similar patterns exist within the code that were not flagged by the static analysis tools.

While the current code appears to be relatively secure, the past XSS vulnerability is the most significant concern. It implies that the plugin has had issues with improper input neutralization, and vigilance is required to ensure this doesn't re-emerge. The limited attack surface is a positive aspect, with only one shortcode as an entry point. The lack of unauthenticated AJAX handlers or REST API routes further bolsters its security. Overall, the plugin is well-developed from a security perspective, but the historical vulnerability necessitates ongoing monitoring.

Key Concerns

  • Past medium XSS vulnerability
Vulnerabilities
1

Related Products Manager for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-50045medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Related Products Manager for WooCommerce <= 1.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 19, 2025 Patched in 1.6.3 (37d)
Code Analysis
Analyzed Mar 16, 2026

Related Products Manager for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
13
151 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

92% escaped164 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<class-prowc-related-products-manager-settings-per-product> (includes\settings\class-prowc-related-products-manager-settings-per-product.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Related Products Manager for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[related_product_manager_card_layout] widgets\related-product-manager-wpbakery-widget.php:329
WordPress Hooks 38
filterwoocommerce_related_products_argsincludes\class-prowc-related-products-manager-core.php:67
filterwoocommerce_output_related_products_argsincludes\class-prowc-related-products-manager-core.php:68
filterwoocommerce_get_related_product_tag_termsincludes\class-prowc-related-products-manager-core.php:70
filterwoocommerce_product_related_posts_queryincludes\class-prowc-related-products-manager-core.php:73
filterwoocommerce_product_related_posts_force_displayincludes\class-prowc-related-products-manager-core.php:74
filterwoocommerce_output_related_products_argsincludes\class-prowc-related-products-manager-core.php:76
filterwoocommerce_related_products_columnsincludes\class-prowc-related-products-manager-core.php:80
filterwoocommerce_product_related_posts_relate_by_categoryincludes\class-prowc-related-products-manager-core.php:84
filterwoocommerce_product_related_posts_relate_by_categoryincludes\class-prowc-related-products-manager-core.php:86
filterwoocommerce_product_related_posts_relate_by_tagincludes\class-prowc-related-products-manager-core.php:91
filterwoocommerce_product_related_posts_relate_by_tagincludes\class-prowc-related-products-manager-core.php:93
actioninitincludes\class-prowc-related-products-manager-core.php:98
filterwoocommerce_related_productsincludes\class-prowc-related-products-manager-core.php:99
filterwoocommerce_related_productsincludes\class-prowc-related-products-manager-core.php:104
filterwoocommerce_related_productsincludes\class-prowc-related-products-manager-core.php:109
filterwoocommerce_product_related_posts_relate_by_categoryincludes\class-prowc-related-products-manager-core.php:441
filterwoocommerce_product_related_posts_relate_by_tagincludes\class-prowc-related-products-manager-core.php:442
actionadmin_initincludes\settings\class-prowc-related-products-manager-settings-general.php:28
actionadd_meta_boxesincludes\settings\class-prowc-related-products-manager-settings-per-product.php:26
actionsave_post_productincludes\settings\class-prowc-related-products-manager-settings-per-product.php:27
filterwoocommerce_get_sections_prowc_related_products_managerincludes\settings\class-prowc-related-products-manager-settings-section.php:24
actionadmin_noticesincludes\settings\class-prowc-settings-related-products-manager.php:71
actioninitrelated-products-manager-for-woocommerce.php:117
actionwp_enqueue_scriptsrelated-products-manager-for-woocommerce.php:118
actioninitrelated-products-manager-for-woocommerce.php:119
actionbefore_woocommerce_initrelated-products-manager-for-woocommerce.php:120
filterwoocommerce_get_settings_pagesrelated-products-manager-for-woocommerce.php:142
actionadmin_initrelated-products-manager-for-woocommerce.php:149
actionadmin_enqueue_scriptsrelated-products-manager-for-woocommerce.php:152
actionadmin_initrelated-products-manager-for-woocommerce.php:153
actionadmin_initrelated-products-manager-for-woocommerce.php:154
actionadmin_initrelated-products-manager-for-woocommerce.php:155
actionadmin_noticesrelated-products-manager-for-woocommerce.php:156
actionadmin_noticesrelated-products-manager-for-woocommerce.php:157
actionplugins_loadedrelated-products-manager-for-woocommerce.php:158
actionadmin_noticesrelated-products-manager-for-woocommerce.php:163
actionbefore_woocommerce_initrelated-products-manager-for-woocommerce.php:541
actionelementor/initwidgets\elementor-helper.php:14
Maintenance & Trust

Related Products Manager for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 19, 2025
PHP min version
Downloads42K

Community Trust

Rating92/100
Number of ratings19
Active installs1K
Developer Profile

Related Products Manager for WooCommerce Developer Profile

ProWCPlugins

3 plugins · 2K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
22 days
View full developer profile
Detection Fingerprints

How We Detect Related Products Manager for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/related-products-manager-woocommerce/includes/css/related-products.css
Version Parameters
/wp-content/plugins/related-products-manager-woocommerce/includes/css/related-products.css?ver=1.0

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Related Products Manager for WooCommerce