RockOn Woo Variations Table Security & Risk Analysis

wordpress.org/plugins/rockon-woo-variations-table

Simple plugin. Show variations product in table format using shortcode.

0 active installs v6.0 PHP + WP 3.6+ Updated Dec 6, 2020
rockonshortcodetablevariationswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RockOn Woo Variations Table Safe to Use in 2026?

Generally Safe

Score 85/100

RockOn Woo Variations Table has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "rockon-woo-variations-table" v6.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests. All SQL queries are secured with prepared statements, and there are no known vulnerabilities (CVEs) associated with this plugin. However, significant concerns arise from its attack surface. Two AJAX handlers are exposed without any authentication checks, presenting a direct pathway for unauthorized actions. Furthermore, the taint analysis indicates two unsanitized paths, suggesting potential for injection vulnerabilities if user-supplied data is not properly handled, though no critical or high severity issues were flagged. The lack of nonce checks on AJAX handlers is a critical oversight, as it allows for Cross-Site Request Forgery (CSRF) attacks.

The plugin's vulnerability history is clean, which is a positive indicator. This suggests that the developers may be responsive to security issues or that the plugin has not been a target for exploitation. However, the presence of unprotected entry points and potential unsanitized data flows are inherent risks that could be exploited by attackers, even without a known vulnerability history. The limited output escaping on some outputs also contributes to a potential for cross-site scripting (XSS) vulnerabilities.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths (Taint Analysis)
  • Unescaped output (60% escaped)
  • No nonce checks on AJAX handlers
Vulnerabilities
None known

RockOn Woo Variations Table Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

RockOn Woo Variations Table Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped5 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
check_choosed_var (ron-woo-variations-table.php:59)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

RockOn Woo Variations Table Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_check_choosed_varron-woo-variations-table.php:57
noprivwp_ajax_check_choosed_varron-woo-variations-table.php:58

Shortcodes 1

[rovartable] ron-woo-variations-table.php:34
WordPress Hooks 2
actionwp_enqueue_scriptsron-woo-variations-table.php:225
actionwp_headron-woo-variations-table.php:233
Maintenance & Trust

RockOn Woo Variations Table Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedDec 6, 2020
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

RockOn Woo Variations Table Developer Profile

Vikas Sharma

6 plugins · 3K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RockOn Woo Variations Table

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rockon-woo-variations-table/assets/css/rwvt_style.css
Version Parameters
rockon-woo-variations-table/assets/css/rwvt_style.css?ver=

HTML / DOM Fingerprints

CSS Classes
ron-woo-table-sectionro-loader-row-hoverrow-2evenoddvalue
Data Attributes
id="ron-att-name-id="ron-attr-data-attribute_name="attribute_id="add-cart-
JS Globals
ron_woo_variations_tableron_woo_find_matching_product_variationcheck_choosed_varron_woo_variable_add_to_cartrwvt_enqueue_stylesrwvt_head_scripts+1 more
REST Endpoints
/wp-json/wp/v2/check_choosed_var
Shortcode Output
[rovartable
FAQ

Frequently Asked Questions about RockOn Woo Variations Table