Stock Export and Import for WooCommerce Security & Risk Analysis

wordpress.org/plugins/stock-export-and-import-for-woocommerce

Export and import stock statuses and quantities for WooCommerce products in Comma-Separated Values (CSV) format.

300 active installs v1.0.7 PHP + WP 4.0+ Updated Aug 12, 2024
inventoryreportreportingstockwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Stock Export and Import for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Stock Export and Import for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'stock-export-and-import-for-woocommerce' version 1.0.7 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of identified CVEs, unpatched vulnerabilities, and particularly the lack of critical or high-severity issues in taint analysis are positive indicators. The code also demonstrates good practices like using prepared statements for all SQL queries and performing some nonce and capability checks.

However, there are areas for improvement. The low percentage of properly escaped output (20%) is a significant concern, suggesting potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sufficient sanitization. While the attack surface appears small and protected, this could be misleading if the analysis didn't cover all potential entry points or if the existing entry points have insufficient checks. The presence of file operations without explicit mention of sanitization also warrants careful review, as it could lead to path traversal or other file manipulation vulnerabilities.

In conclusion, while the plugin has a clean vulnerability history and uses some secure coding practices, the unescaped output and file operations present the most immediate risks that need to be addressed. Further investigation into the output handling and file operation contexts is recommended to ensure user data is adequately protected.

Key Concerns

  • Low percentage of properly escaped output
  • Presence of file operations
Vulnerabilities
None known

Stock Export and Import for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Stock Export and Import for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
1 escaped
Nonce Checks
2
Capability Checks
1
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped5 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
hm_wcsxi_on_init (stock-export-and-import-for-woocommerce.php:207)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Stock Export and Import for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionbefore_woocommerce_initstock-export-and-import-for-woocommerce.php:47
actionadmin_menustock-export-and-import-for-woocommerce.php:49
actioninitstock-export-and-import-for-woocommerce.php:206
filternocache_headersstock-export-and-import-for-woocommerce.php:218
Maintenance & Trust

Stock Export and Import for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 12, 2024
PHP min version
Downloads12K

Community Trust

Rating78/100
Number of ratings7
Active installs300
Developer Profile

Stock Export and Import for WooCommerce Developer Profile

WP Zone

21 plugins · 40K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
124 days
View full developer profile
Detection Fingerprints

How We Detect Stock Export and Import for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
HTML Comments
Copyright (C) 2024 WP ZoneThis program is free software: you can redistribute and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+3 more
Data Attributes
id="hm_wcsxi_field_cat"name="cat"id="hm_wcsxi_field_orderby"name="orderby"name="orderdir"name="include_header"+1 more
FAQ

Frequently Asked Questions about Stock Export and Import for WooCommerce