Shop Page Manager for eCommerce Security & Risk Analysis

wordpress.org/plugins/shop-page-manager-for-woocommerce

Adds additional functionality to the default eCommerce Shop pages and allows for rules to be set hiding the display of both categories and products

0 active installs v3.1.0 PHP 7.0+ WP 5.0.0+ Updated Unknown
categoryplpshopzamartz
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shop Page Manager for eCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Shop Page Manager for eCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "shop-page-manager-for-woocommerce" plugin v3.1.0 presents a mixed security posture. While it has no recorded vulnerabilities in its history and doesn't appear to bundle outdated libraries or perform file operations, the static analysis reveals significant concerns. A large portion of its attack surface, specifically 7 out of 9 AJAX handlers, lack proper authentication checks. This is a critical oversight that could allow unauthenticated users to trigger potentially sensitive actions within the plugin. Additionally, the low percentage of properly escaped output (8%) indicates a high risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without sanitization.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • No capability checks found
  • SQL queries with no mention of prepared statements
Vulnerabilities
None known

Shop Page Manager for eCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Shop Page Manager for eCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
84
7 escaped
Nonce Checks
7
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

50% prepared2 total queries

Output Escaping

8% escaped91 total outputs
Attack Surface
7 unprotected

Shop Page Manager for eCommerce Attack Surface

Entry Points9
Unprotected7

AJAX Handlers 9

authwp_ajax_woo_shop_manager_get_form_section_ajaxadmin\class-wp-shop-page-manager-woo-settings.php:96
authwp_ajax_woo_shop_manager_product_variationadmin\class-wp-shop-page-manager-woo-settings.php:97
authwp_ajax_woo_shop_manager_coupon_is_appliedadmin\class-wp-shop-page-manager-woo-settings.php:98
authwp_ajax_woo_shop_manager_get_custom_select2_ajaxadmin\class-wp-shop-page-manager-woo-settings.php:99
authwp_ajax_woo_shop_manager_get_network_api_status_ajaxadmin\class-zamartz-network-admin-addons.php:79
authwp_ajax_woo_shop_manager_network_addon_form_data_ajaxadmin\class-zamartz-network-admin-addons.php:82
authwp_ajax_zamartz_review_now_ajaxadmin\class-zamartz-network-admin-addons.php:85
authwp_ajax_wp_zamartz_admin_event_tracker_ajaxadmin\zamartz\class-wp-woo-main-zamartz-admin.php:103
authwp_ajax_wp_zamartz_admin_general_form_data_ajaxadmin\zamartz\class-wp-woo-main-zamartz-admin.php:106
WordPress Hooks 46
actioncustomize_controls_enqueue_scriptsadmin\class-wp-shop-page-manager-woo-customizer.php:47
actioncustomize_registeradmin\class-wp-shop-page-manager-woo-customizer.php:50
actioncustomize_save_zamartz_shop_page_manager_rulesetsadmin\class-wp-shop-page-manager-woo-customizer.php:103
filterwoocommerce_get_sections_productsadmin\class-wp-shop-page-manager-woo-settings.php:87
filterwoocommerce_get_settings_productsadmin\class-wp-shop-page-manager-woo-settings.php:88
filterposts_whereadmin\class-wp-shop-page-manager-woo-settings.php:92
actionadmin_footeradmin\class-wp-shop-page-manager-woo-settings.php:103
filterzamartz_dashboard_accordion_informationadmin\class-zamartz-admin-addons.php:86
filterzamartz_dashboard_accordion_settingsadmin\class-zamartz-admin-addons.php:89
filterzamartz_settings_subnavadmin\class-zamartz-admin-addons.php:92
actionzamartz_admin_addon_informationadmin\class-zamartz-admin-addons.php:95
actionzamartz_admin_addon_settingsadmin\class-zamartz-admin-addons.php:98
filtercron_schedulesadmin\class-zamartz-admin-addons.php:113
actionzamartz_api_cron_schedule_twice_monthlyadmin\class-zamartz-admin-addons.php:116
filtercron_schedulesadmin\class-zamartz-admin-addons.php:119
actionzamartz_api_cron_schedule_admin_noticeadmin\class-zamartz-admin-addons.php:122
actionadmin_noticesadmin\class-zamartz-admin-addons.php:125
filterzamartz_plugin_statusadmin\class-zamartz-admin-status.php:44
filterzamartz_network_dashboard_accordion_informationadmin\class-zamartz-network-admin-addons.php:64
filterzamartz_network_dashboard_accordion_settingsadmin\class-zamartz-network-admin-addons.php:67
filterzamartz_network_dashboard_active_addons_site_listadmin\class-zamartz-network-admin-addons.php:70
actionzamartz_network_addon_settingsadmin\class-zamartz-network-admin-addons.php:73
actionzamartz_network_addon_informationadmin\class-zamartz-network-admin-addons.php:76
filterzamartz_network_is_remove_adsadmin\class-zamartz-network-admin-addons.php:88
actionadmin_enqueue_scriptsadmin\zamartz\class-wp-woo-main-zamartz-admin.php:59
actionadmin_enqueue_scriptsadmin\zamartz\class-wp-woo-main-zamartz-admin.php:60
actionadmin_menuadmin\zamartz\class-wp-woo-main-zamartz-admin.php:89
actionnetwork_admin_menuadmin\zamartz\class-wp-woo-main-zamartz-admin.php:92
actionadmin_noticesadmin\zamartz\class-wp-woo-main-zamartz-admin.php:99
filterzamartz_is_remove_adsadmin\zamartz\helper\trait-zamartz-general.php:227
filterwp_feed_cache_transient_lifetimeadmin\zamartz\helper\trait-zamartz-rss-methods.php:107
actionupdate_option_woocommerce_default_catalog_orderbyincludes\class-wp-shop-page-manager-woo.php:136
filterplugins_loadedincludes\class-wp-shop-page-manager-woo.php:150
filterplugins_loadedincludes\class-wp-shop-page-manager-woo.php:151
actionnetwork_admin_noticesincludes\class-wp-shop-page-manager-woo.php:155
actionadmin_noticesincludes\class-wp-shop-page-manager-woo.php:157
actionplugins_loadedincludes\class-wp-shop-page-manager-woo.php:282
actionadmin_enqueue_scriptsincludes\class-wp-shop-page-manager-woo.php:297
actionadmin_enqueue_scriptsincludes\class-wp-shop-page-manager-woo.php:298
actionwp_enqueue_scriptsincludes\class-wp-shop-page-manager-woo.php:313
actionwp_enqueue_scriptsincludes\class-wp-shop-page-manager-woo.php:314
actionadmin_initincludes\class-wp-shop-page-manager-woo.php:411
actionwoocommerce_product_querypublic\class-wp-shop-page-manager-woo-front.php:74
actioncustomize_preview_initpublic\class-wp-shop-page-manager-woo-front.php:75
filterposts_clausespublic\class-wp-shop-page-manager-woo-front.php:560
filterwoocommerce_product_subcategories_argspublic\class-wp-shop-page-manager-woo-front.php:655
Maintenance & Trust

Shop Page Manager for eCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.0
Last updatedUnknown
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Shop Page Manager for eCommerce Developer Profile

zamartz

3 plugins · 80 total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
186 days
View full developer profile
Detection Fingerprints

How We Detect Shop Page Manager for eCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shop-page-manager-for-woocommerce/admin/css/wp-shop-page-manager-woo-admin.css/wp-content/plugins/shop-page-manager-for-woocommerce/admin/js/wp-shop-page-manager-woo-admin.js/wp-content/plugins/shop-page-manager-for-woocommerce/admin/js/wp-shop-page-manager-woo-customizer.js
Script Paths
/wp-content/plugins/shop-page-manager-for-woocommerce/admin/js/wp-shop-page-manager-woo-admin.js/wp-content/plugins/shop-page-manager-for-woocommerce/admin/js/wp-shop-page-manager-woo-customizer.js
Version Parameters
wp-shop-page-manager-for-woocommerce/admin/css/wp-shop-page-manager-woo-admin.css?ver=wp-shop-page-manager-for-woocommerce/admin/js/wp-shop-page-manager-woo-admin.js?ver=wp-shop-page-manager-for-woocommerce/admin/js/wp-shop-page-manager-woo-customizer.js?ver=

HTML / DOM Fingerprints

JS Globals
zamartz_customizer_localized_object
FAQ

Frequently Asked Questions about Shop Page Manager for eCommerce