Shopwarden – Automated WooCommerce monitoring & testing Security & Risk Analysis

wordpress.org/plugins/shopwarden

Make sure your WooCommerce store is fully operational. Shopwarden automatically monitors your store's uptime, important user flows and Wordpress …

40 active installs v1.0.12 PHP 7.0+ WP 5.6+ Updated Feb 11, 2025
monitoringtestingwoocommerce
90
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 17, 2025
Safety Verdict

Is Shopwarden – Automated WooCommerce monitoring & testing Safe to Use in 2026?

Generally Safe

Score 90/100

Shopwarden – Automated WooCommerce monitoring & testing has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 17, 2025Updated 1yr ago
Risk Assessment

The "shopwarden" plugin v1.0.12 exhibits a mixed security posture. While it demonstrates good practices like a low attack surface and a relatively low percentage of SQL queries without prepared statements, and includes nonce and capability checks, there are significant areas for concern. The static analysis reveals that a concerning percentage of outputs are not properly escaped, and there is a flow with an unsanitized path, although it is not classified as critical or high severity. This suggests potential for vulnerabilities that could be exploited.

The vulnerability history is particularly worrying. The plugin has a known high-severity CVE related to Cross-Site Request Forgery (CSRF), and although it is currently patched, the existence of such a vulnerability indicates a past lapse in secure coding practices. The frequency and type of past vulnerabilities, particularly CSRF, point to a pattern of potentially insecure handling of user input and state management that requires ongoing vigilance.

In conclusion, while the current version shows some improvements in secure coding by reducing the attack surface and implementing checks, the history of a high-severity CSRF vulnerability and the presence of unsanitized flows and unescaped outputs warrant a cautious approach. Continuous auditing and rigorous testing are recommended to ensure these weaknesses are addressed and do not re-emerge in future versions.

Key Concerns

  • High severity CVE in history
  • Flows with unsanitized paths
  • Low output escaping percentage
  • External HTTP requests
Vulnerabilities
1 published

Shopwarden – Automated WooCommerce monitoring & testing Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-13315high · 8.8Cross-Site Request Forgery (CSRF)

Shopwarden – Automated WooCommerce monitoring & testing <= 1.0.11 - Cross-Site Request Forgery to Arbitrary Options Update

Feb 17, 2025 Patched in 1.0.12 (1d)
Version History

Shopwarden – Automated WooCommerce monitoring & testing Release Timeline

v1.0.12Current
v1.0.111 CVE
v1.0.101 CVE
v1.0.91 CVE
v1.0.81 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Shopwarden – Automated WooCommerce monitoring & testing Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
13
11 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

46% escaped24 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
initAdminPage (shopwarden.php:71)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Shopwarden – Automated WooCommerce monitoring & testing Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionplugins_loadedshopwarden.php:26
actioninitshopwarden.php:27
actionadmin_initshopwarden.php:28
actionadmin_initshopwarden.php:32
actionadmin_menushopwarden.php:41
filterwoocommerce_webhook_should_delivershopwarden.php:46
filterwoocommerce_email_recipient_new_ordershopwarden.php:47
actionshopwarden_delete_orders_actionshopwarden.php:48
filterwoocommerce_payment_gatewaysshopwarden.php:787
actionwoocommerce_update_options_payment_gateways_shopwardenshopwarden.php:867

Scheduled Events 1

shopwarden_delete_orders_action
Maintenance & Trust

Shopwarden – Automated WooCommerce monitoring & testing Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 11, 2025
PHP min version7.0
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

Shopwarden – Automated WooCommerce monitoring & testing Developer Profile

shopwarden

1 plugin · 40 total installs

93
trust score
Avg Security Score
90/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Shopwarden – Automated WooCommerce monitoring & testing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shopwarden/assets/css/main.css/wp-content/plugins/shopwarden/assets/js/main.js
Script Paths
/wp-content/plugins/shopwarden/assets/js/main.js
Version Parameters
shopwarden/assets/css/main.css?ver=shopwarden/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
wppd-ui-toggle
Data Attributes
data-plugin-name="shopwarden"
FAQ

Frequently Asked Questions about Shopwarden – Automated WooCommerce monitoring & testing