
ShopCred – WooCommerce Builder with Products Grid & Carousel Block Security & Risk Analysis
wordpress.org/plugins/shopcredShopCred - The Best Gutenberg Blocks Collection for WooCommerce with WooCommerce Builder
Is ShopCred – WooCommerce Builder with Products Grid & Carousel Block Safe to Use in 2026?
Mostly Safe
Score 71/100ShopCred – WooCommerce Builder with Products Grid & Carousel Block is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The shopcred plugin exhibits a mixed security posture. While it avoids dangerous functions and file operations, significant concerns arise from its handling of entry points and data sanitization. A substantial portion of its AJAX handlers (4 out of 10) and one REST API route lack proper authentication or permission checks, creating a large attack surface for unauthorized access or manipulation. The static analysis reveals that 3 SQL queries are not using prepared statements, and a concerning 42% of outputs are not properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. The presence of two unsanitized taint flows, although not classified as critical or high severity in this analysis, warrants attention as they could potentially be exploited. The vulnerability history, including one unpatched medium severity CVE related to XSS, further reinforces these concerns and suggests a pattern of input sanitization weaknesses. Despite a relatively low number of total entry points, the lack of robust security checks on several of them, coupled with the history of XSS, indicates a need for immediate improvement to mitigate potential risks.
Key Concerns
- Unpatched CVE: 1 medium
- SQL queries not using prepared statements
- Low percentage of output escaping
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Flows with unsanitized paths
ShopCred – WooCommerce Builder with Products Grid & Carousel Block Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ShopCred <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
ShopCred – WooCommerce Builder with Products Grid & Carousel Block Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ShopCred – WooCommerce Builder with Products Grid & Carousel Block Attack Surface
AJAX Handlers 10
REST API Routes 1
WordPress Hooks 75
Maintenance & Trust
ShopCred – WooCommerce Builder with Products Grid & Carousel Block Maintenance & Trust
Maintenance Signals
Community Trust
ShopCred – WooCommerce Builder with Products Grid & Carousel Block Alternatives
Choose Your Best Selling Products
choose-your-best-selling-products
A WordPress plugin to display top selling products with flexible settings for manual or automated product selection.
GTG Product Blocks
gtg-product-blocks
This GTG Product Block is one of the most powerful plugin for Gutenberg that is compatible with WooCommerce to display your products on posts and page …
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
essential-blocks
Gutenberg block editor with AI. 70+ Gutenberg blocks, patterns, WooCommerce blocks, post grid, gallery, menu with Gutenberg block library.
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
woolentor-addons
ShopLentor – More than a WooCommerce builder. A complete growth plugin to boost conversions, UX, and sales for your store.
Greenshift – animation and page builder blocks
greenshift-animation-and-page-builder-blocks
More than 20 special blocks for Gutenberg to build complex pages and animations with highest possible web vitals score.
ShopCred – WooCommerce Builder with Products Grid & Carousel Block Developer Profile
2 plugins · 60 total installs
How We Detect ShopCred – WooCommerce Builder with Products Grid & Carousel Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shopcred/admin/assets/css/admin-notice.css/wp-content/plugins/shopcred/admin/assets/css/admin-style.css/wp-content/plugins/shopcred/admin/assets/js/admin-script.js/wp-content/plugins/shopcred/includes/base.php/wp-content/plugins/shopcred/admin/assets/js/admin-script.jsver=1.2.8HTML / DOM Fingerprints
spc-admin-cssspc-notice-cssspc_admin_object/wp-json/custom/v1/check-shopcred-pro