
Stock Message Security & Risk Analysis
wordpress.org/plugins/stock-messageWooCommerce plugin which allows you to add literal messages insted of "Out Of Stock" and "In Stock" messages.
Is Stock Message Safe to Use in 2026?
Use With Caution
Score 63/100Stock Message has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The stock-message plugin v1.1.0 exhibits a mixed security posture. While it demonstrates strengths in limiting its attack surface with zero identified entry points and using prepared statements for all SQL queries, significant concerns arise from its output escaping and vulnerability history. The static analysis reveals that 100% of output operations are not properly escaped, posing a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, a medium severity Cross-Site Request Forgery (CSRF) vulnerability remains unpatched, indicating a potential for malicious actions against users.
While the taint analysis found no critical or high severity flows, the presence of a flow with unsanitized paths is a red flag. The plugin's history of known vulnerabilities, particularly the ongoing unpatched CSRF issue, suggests a pattern of security oversights. Although the plugin is relatively clean in terms of direct code execution risks and SQL injection, the unescaped output and the existing unpatched vulnerability significantly detract from its overall security. Users should exercise caution and prioritize patching.
In conclusion, the stock-message plugin v1.1.0 has some good security practices, like a small attack surface and secure SQL handling. However, the critical lack of output escaping and the unaddressed CSRF vulnerability represent substantial risks that need immediate attention. The potential for XSS due to unescaped output is a primary concern, amplified by the existing known vulnerability.
Key Concerns
- Unpatched CVE (Medium Severity)
- 100% Output Escaping Missing
- Flows with unsanitized paths
Stock Message Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Stock Message <= 1.1.0 - Cross-Site Request Forgery
Stock Message Code Analysis
Output Escaping
Data Flow Analysis
Stock Message Attack Surface
WordPress Hooks 4
Maintenance & Trust
Stock Message Maintenance & Trust
Maintenance Signals
Community Trust
Stock Message Alternatives
MoreConvert Wishlist for WooCommerce
smart-wishlist-for-more-convert
Free: WooCommerce Wishlist, Email automation, Elementor and Premium: Back-in-Stock Notifier, Save For Later, Multi-lists, reports, Email Marketing
Restock Notifier For WooCommerce
restock-notifier-for-woocommerce
Notify customers via email when out-of-stock WooCommerce products are restocked. Simple, smart, and fully automated.
Stock Availability Alert for WooCommerce
stock-availability-alert-for-woocommerce
Inform customers when out-of-stock WooCommerce products return to stock. "Notify Me" functionality and automatic email reminders.
Notification WooCommerce
notification-woocommerce
The easy and ultimate solution for notifiaction that lets your customer set notification for product availablity and/or discount.
Stock Notifier Pro For WooCommerce
stock-notifier-pro-for-woocommerce
Never lose a sale due to an out-of-stock product again. Automatically notify your customers when their favorite items are back in stock and recover lo …
Stock Message Developer Profile
6 plugins · 110 total installs
How We Detect Stock Message
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stock-message/woocommerce-custom-stock-message/css/style.css/wp-content/plugins/stock-message/woocommerce-custom-stock-message/bootstrap-3.3.5/css/bootstrap.min.css/wp-content/plugins/stock-message/woocommerce-custom-stock-message/bootstrap-3.3.5/css/bootstrap.min.jsHTML / DOM Fingerprints
wcoos-instockwcoos-amountwcoos-comming-soon