
Show All Products Shortcode for Woocommerce Security & Risk Analysis
wordpress.org/plugins/show-all-products-shortcode-for-woocommerceNo frills. Adds an [all_products] shortcode to list all woocommerce products on one page
Is Show All Products Shortcode for Woocommerce Safe to Use in 2026?
Generally Safe
Score 85/100Show All Products Shortcode for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "show-all-products-shortcode-for-woocommerce" v1.0 plugin exhibits a mixed security posture. On the positive side, the static analysis indicates a clean bill of health regarding dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests. There are also no known CVEs associated with this plugin, which suggests a good track record of security. However, a significant concern arises from the output escaping analysis, where 100% of the outputs are not properly escaped. This leaves the plugin susceptible to Cross-Site Scripting (XSS) attacks, especially since the single shortcode presents an entry point that is not protected by capability checks or nonce verification.
The absence of taint analysis flows is not necessarily an indicator of security but rather a limitation of the analysis performed, meaning vulnerabilities might exist but were not detected by the tool. The lack of nonce and capability checks on the identified shortcode is a critical weakness. While the plugin doesn't have a history of vulnerabilities, this could be due to its limited attack surface or simply an oversight in past security reviews. The primary risk identified is the potential for XSS vulnerabilities due to unescaped output via the shortcode, coupled with a lack of input validation and authorization checks.
In conclusion, while the plugin scores well on many common security metrics like SQL injection and lack of dangerous functions, the critical issue of unescaped output for its sole shortcode presents a tangible risk. This, combined with the missing authorization and nonce checks, means the plugin is vulnerable to XSS. Users should exercise caution and consider this vulnerability when evaluating the security of their WordPress sites. The lack of a vulnerability history is positive but doesn't negate the immediate risks identified in the code.
Key Concerns
- Unescaped output detected
- Shortcode without capability checks
- Shortcode without nonce checks
Show All Products Shortcode for Woocommerce Security Vulnerabilities
Show All Products Shortcode for Woocommerce Code Analysis
Output Escaping
Show All Products Shortcode for Woocommerce Attack Surface
Shortcodes 1
Maintenance & Trust
Show All Products Shortcode for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Show All Products Shortcode for Woocommerce Alternatives
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
WooCommerce Grid / List toggle
woocommerce-grid-list-toggle
Adds a grid/list view toggle to product archives
Emalls Extraction API – Official
emalls-extraction-api-official
این پلاگین جهت دریافت تمامی محصولات فروشگاههای وردپرسی که از پلاگین ووکامرس استفاده میکنند، توسعه یافته است.
WooSwipe WooCommerce Gallery
wooswipe
A WooCommerce gallery plugin built using PhotoSwipe from Dmitry Semenov and Slick carousel.
Widgets for WooCommerce Products on Elementor
woo-products-widgets-for-elementor
Woo Products widget is a plugin that allows adding WooCommerce Products and Categories into stylish grid and listing layouts to the pages built with E …
Show All Products Shortcode for Woocommerce Developer Profile
6 plugins · 2K total installs
How We Detect Show All Products Shortcode for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
woocommercecolumns-[all_products]