Repeat Customer for WooCommerce Security & Risk Analysis

wordpress.org/plugins/repeat-customer-for-woocommerce

See customer order history, lifetime value, and purchase patterns directly on the WooCommerce order edit screen.

0 active installs v1.1.0 PHP 7.4+ WP 6.0+ Updated Apr 15, 2026
customer-historycustomersorder-managementrepeat-customerswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Repeat Customer for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Repeat Customer for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'repeat-customer-for-woocommerce' v1.1.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified vulnerabilities, CVEs, or critical taint flows is highly encouraging. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of output escaping. The attack surface appears to be minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper authorization or permission checks. There are no file operations or external HTTP requests, further reducing potential attack vectors.

However, a notable concern is the complete absence of nonce checks and capability checks. While the current analysis shows no immediate exploitable paths, this lack of fundamental security mechanisms leaves the plugin vulnerable to potential future attacks if any entry points are discovered or introduced, or if underlying WordPress core functions change. The lack of taint analysis flows analyzed also means that while no issues were found, this doesn't definitively prove the absence of all potential taint vulnerabilities; it simply means none were detected by the analysis performed.

In conclusion, the plugin is currently in a very good security state with no known issues and good coding practices in place for SQL and output handling. The primary weakness lies in the missing nonce and capability checks, which are crucial for robust security and represent a potential future risk. Addressing these missing checks would significantly enhance the plugin's overall security.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
Vulnerabilities
None known

Repeat Customer for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Repeat Customer for WooCommerce Release Timeline

v1.1.0Current
Code Analysis
Analyzed Apr 16, 2026

Repeat Customer for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
4
31 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

89% escaped35 total outputs
Attack Surface

Repeat Customer for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadd_meta_boxesincludes/class-rc4wc-metabox.php:31
actionadmin_enqueue_scriptsincludes/class-rc4wc-metabox.php:32
actionwoocommerce_order_status_changedincludes/class-rc4wc-metabox.php:33
actionwoocommerce_order_refundedincludes/class-rc4wc-metabox.php:34
filtermanage_woocommerce_page_wc-orders_columnsincludes/class-rc4wc-orders-column.php:31
actionmanage_woocommerce_page_wc-orders_custom_columnincludes/class-rc4wc-orders-column.php:32
filtermanage_edit-shop_order_columnsincludes/class-rc4wc-orders-column.php:35
actionmanage_shop_order_posts_custom_columnincludes/class-rc4wc-orders-column.php:36
filterwoocommerce_get_sections_advancedincludes/class-rc4wc-settings.php:31
filterwoocommerce_get_settings_advancedincludes/class-rc4wc-settings.php:32
actionadmin_noticesrepeat-customer.php:58
actionbefore_woocommerce_initrepeat-customer.php:83
actionplugins_loadedrepeat-customer.php:90
Maintenance & Trust

Repeat Customer for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 15, 2026
PHP min version7.4
Downloads0

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Repeat Customer for WooCommerce Developer Profile

smartfact

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Repeat Customer for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/repeat-customer-for-woocommerce/assets/css/admin-metabox.css/wp-content/plugins/repeat-customer-for-woocommerce/assets/js/admin-metabox.js
Script Paths
/wp-content/plugins/repeat-customer-for-woocommerce/assets/js/admin-metabox.js
Version Parameters
repeat-customer-for-woocommerce/assets/css/admin-metabox.css?ver=repeat-customer-for-woocommerce/assets/js/admin-metabox.js?ver=

HTML / DOM Fingerprints

CSS Classes
rc4wc-noticerc4wc-guest-noticerc4wc-match-labelrc4wc-match-label--softrc4wc-postcode-disclaimerrc4wc-metricsrc4wc-metrics--soft
HTML Comments
Order edit screen metabox.Displays customer metrics, order history timeline, match confidence labels,and OrderBadger upsell CTA in the sidebar of the WooCommerce order edit screen.Compatible with both HPOS and legacy order storage.+5 more
Data Attributes
data-order-id
FAQ

Frequently Asked Questions about Repeat Customer for WooCommerce