SKU for WooCommerce Bookings Security & Risk Analysis

wordpress.org/plugins/sku-for-woocommerce-bookings

This plugin adds SKUs to your WooCommerce bookings products and also makes it searchable in your site.

10 active installs v1.4 PHP 7.4+ WP 6.0+ Updated Sep 18, 2025
add-sku-to-bookingsbooking-skuskuwoocommercewoocommerce-bookings
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SKU for WooCommerce Bookings Safe to Use in 2026?

Generally Safe

Score 100/100

SKU for WooCommerce Bookings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The static analysis of the "sku-for-woocommerce-bookings" plugin v1.4 indicates a generally positive security posture in several key areas. The plugin demonstrates good practices by avoiding dangerous functions, utilizing prepared statements exclusively for its SQL queries, and properly escaping all identified output. Furthermore, the absence of file operations, external HTTP requests, and a clean vulnerability history (zero CVEs) are all strong indicators of a well-developed and secure plugin.

However, there are significant concerns arising from the taint analysis. Two identified flows with unsanitized paths, classified as high severity, are critical security flaws that require immediate attention. The lack of capability checks and nonce checks on what are implied to be potential entry points (despite the static analysis reporting 0 unprotected entry points overall) also present a potential blind spot. While the plugin has a history free of known vulnerabilities, the presence of high-severity taint flows suggests that undiscovered vulnerabilities could exist, or that the testing methodologies might have missed certain attack vectors.

In conclusion, while the plugin exhibits commendable security practices in many aspects, the high-severity taint analysis results are a major red flag. These unsanitized flows represent a clear and present danger. The plugin's history of no known vulnerabilities is a positive sign, but it should not breed complacency. Addressing the identified taint flows is paramount to ensuring the plugin's security.

Key Concerns

  • High severity taint flows (unsanitized paths)
  • No capability checks found
  • No nonce checks found
  • Bundled library (Freemius v1.0) potentially outdated
Vulnerabilities
None known

SKU for WooCommerce Bookings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SKU for WooCommerce Bookings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped7 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
product_search_booking_and_regular_sku (sku-search-for-wc-bookings.php:4)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SKU for WooCommerce Bookings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filterinitsku-for-wc-bookings.php:53
filterwoocommerce_product_data_tabssku-for-wc-bookings.php:64
filterwoocommerce_product_data_panelssku-for-wc-bookings.php:80
actionwoocommerce_single_product_summarysku-for-wc-bookings.php:108
actionwoocommerce_admin_process_product_objectsku-for-wc-bookings.php:119
filtermanage_edit-product_columnssku-for-wc-bookings.php:139
actionmanage_product_posts_custom_columnsku-for-wc-bookings.php:149
filterwoocommerce_cart_item_namesku-for-wc-bookings.php:164
actionwoocommerce_admin_order_item_valuessku-for-wc-bookings.php:182
actionwoocommerce_admin_order_item_headerssku-for-wc-bookings.php:188
filterposts_searchsku-search-for-wc-bookings.php:3
Maintenance & Trust

SKU for WooCommerce Bookings Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 18, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

SKU for WooCommerce Bookings Developer Profile

theorcawp

10 plugins · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SKU for WooCommerce Bookings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sku-for-woocommerce-bookings/assets/css/frontend.css/wp-content/plugins/sku-for-woocommerce-bookings/assets/js/frontend.js/wp-content/plugins/sku-for-woocommerce-bookings/assets/css/admin.css/wp-content/plugins/sku-for-woocommerce-bookings/assets/js/admin.js
Version Parameters
sku-for-woocommerce-bookings/assets/css/frontend.css?ver=sku-for-woocommerce-bookings/assets/js/frontend.js?ver=sku-for-woocommerce-bookings/assets/css/admin.css?ver=sku-for-woocommerce-bookings/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
booking_skushow_if_bookingproduct-sku
Data Attributes
data-sort="your-sort-option"
FAQ

Frequently Asked Questions about SKU for WooCommerce Bookings