ShopAnalytics Lite – WooCommerce Sales & Customer Reports Security & Risk Analysis

wordpress.org/plugins/shopanalytics-lite-customer-sales-insights

Instant, lightweight WooCommerce reporting. Track revenue, orders, top customers, and export to CSV. Fast insights for shop owners.

0 active installs v1.0.0 PHP + WP 6.0+ Updated Sep 21, 2025
analyticscustomer-insightsreportssaleswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ShopAnalytics Lite – WooCommerce Sales & Customer Reports Safe to Use in 2026?

Generally Safe

Score 100/100

ShopAnalytics Lite – WooCommerce Sales & Customer Reports has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "shopanalytics-lite-customer-sales-insights" plugin v1.0.0 exhibits a generally strong security posture based on this static analysis. The absence of known CVEs, critical taint flows, and a clean vulnerability history are significant strengths. The plugin also demonstrates good practices by using prepared statements for the vast majority of its SQL queries and implementing nonce and capability checks.

However, there are areas for improvement. The most notable concern is the relatively low percentage of properly escaped output (47%). This indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. While the static analysis did not detect any critical taint flows, the unsanitized path identified in the taint analysis warrants further investigation, as it could be a precursor to more severe issues if not handled correctly. The plugin also has one cron event, and while no specific security implications are detailed, the functionality of cron events should always be reviewed for potential vulnerabilities.

In conclusion, the plugin is in good shape with a lack of critical vulnerabilities and a history of responsible development. The primary area to focus on for future development is improving output escaping to mitigate XSS risks. The single unsanitized taint flow should be carefully examined to ensure it doesn't lead to exploitable issues.

Key Concerns

  • Low percentage of properly escaped output
  • Flow with unsanitized paths found in taint analysis
Vulnerabilities
None known

ShopAnalytics Lite – WooCommerce Sales & Customer Reports Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ShopAnalytics Lite – WooCommerce Sales & Customer Reports Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
20 prepared
Unescaped Output
117
105 escaped
Nonce Checks
9
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

87% prepared23 total queries

Output Escaping

47% escaped222 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

7 flows1 with unsanitized paths
render_customers (includes\class-admin-ui.php:1360)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ShopAnalytics Lite – WooCommerce Sales & Customer Reports Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuincludes\class-admin-ui.php:12
actionadmin_initincludes\class-admin-ui.php:13
actionadmin_enqueue_scriptsincludes\class-admin-ui.php:14
actionshopanalytics_custom_daily_log_cleanup_hookincludes\class-admin-ui.php:15
actionplugins_loadedincludes\init.php:7
actionadmin_noticesincludes\init.php:24
actionadmin_initincludes\init.php:52
actionadmin_menuincludes\init.php:100
actionadmin_enqueue_scriptsshopanalytics-lite-customer-sales-insights.php:83

Scheduled Events 1

shopanalytics_custom_daily_log_cleanup_hook
Maintenance & Trust

ShopAnalytics Lite – WooCommerce Sales & Customer Reports Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedSep 21, 2025
PHP min version
Downloads155

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ShopAnalytics Lite – WooCommerce Sales & Customer Reports Developer Profile

Maidul

10 plugins · 1K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
126 days
View full developer profile
Detection Fingerprints

How We Detect ShopAnalytics Lite – WooCommerce Sales & Customer Reports

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shopanalytics-lite-customer-sales-insights/assets/js/chart.min.js/wp-content/plugins/shopanalytics-lite-customer-sales-insights/assets/js/admin.js/wp-content/plugins/shopanalytics-lite-customer-sales-insights/assets/css/admin.css
Script Paths
/wp-content/plugins/shopanalytics-lite-customer-sales-insights/assets/js/chart.min.js/wp-content/plugins/shopanalytics-lite-customer-sales-insights/assets/js/admin.js
Version Parameters
shopanalytics-lite-customer-sales-insights/assets/js/chart.min.js?ver=4.5.0shopanalytics-lite-customer-sales-insights/assets/js/admin.js?ver=1.0.0shopanalytics-lite-customer-sales-insights/assets/css/admin.css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
shopanalytics-reports-wrap
Data Attributes
data-chartjs-labelsdata-chartjs-datadata-chartjs-typedata-chartjs-options
JS Globals
shopanalytics_ajax_object
FAQ

Frequently Asked Questions about ShopAnalytics Lite – WooCommerce Sales & Customer Reports