Automated Stock Update Triggers for WooCommerce Security & Risk Analysis

wordpress.org/plugins/stock-triggers-for-woocommerce

Automatic product stock increase/decrease actions for WooCommerce.

80 active installs v1.8.2 PHP + WP 4.4+ Updated Sep 9, 2025
stockwoo-commercewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Automated Stock Update Triggers for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Automated Stock Update Triggers for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'stock-triggers-for-woocommerce' plugin version 1.8.2 presents a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code employs prepared statements for all SQL queries, mitigating risks of SQL injection. However, there are specific areas that warrant attention. The taint analysis revealed two flows with unsanitized paths, although they are not flagged as critical or high severity. More concerning is the output escaping; while there are a limited number of outputs, 40% of them are not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. Despite the lack of direct critical vulnerabilities found in this analysis, the presence of unsanitized paths and unescaped output suggests potential weaknesses that could be exploited, especially if combined with other factors not immediately apparent in this snapshot. Overall, the plugin demonstrates good practices in some critical areas like SQL handling, but requires improvement in output sanitization and a review of the identified unsanitized paths.

Key Concerns

  • Unescaped output found (40% of 5)
  • Taint flows with unsanitized paths (2)
Vulnerabilities
None known

Automated Stock Update Triggers for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Automated Stock Update Triggers for WooCommerce Release Timeline

v1.8.2Current
v1.8.1
v1.8.0
v1.7.3
v1.7.2
v1.7.1
v1.7.0
v1.6.7
v1.6.6
v1.6.5
v1.6.4
v1.6.3
v1.6.2
v1.6.1
v1.6.0
v1.5.3
v1.5.2
v1.5.1
v1.5.0
v1.4.0
Code Analysis
Analyzed Mar 16, 2026

Automated Stock Update Triggers for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped5 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
bulk_actions_notice (includes\class-alg-wc-stock-triggers-admin.php:208)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Automated Stock Update Triggers for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionwoocommerce_before_save_order_itemsincludes\class-alg-wc-stock-triggers-admin.php:43
actionwoocommerce_before_save_order_itemincludes\class-alg-wc-stock-triggers-admin.php:44
actionwoocommerce_saved_order_itemsincludes\class-alg-wc-stock-triggers-admin.php:45
actionwoocommerce_ajax_order_items_addedincludes\class-alg-wc-stock-triggers-admin.php:50
filterbulk_actions-edit-shop_orderincludes\class-alg-wc-stock-triggers-admin.php:55
filterbulk_actions-woocommerce_page_wc-ordersincludes\class-alg-wc-stock-triggers-admin.php:56
filterhandle_bulk_actions-edit-shop_orderincludes\class-alg-wc-stock-triggers-admin.php:57
filterhandle_bulk_actions-woocommerce_page_wc-ordersincludes\class-alg-wc-stock-triggers-admin.php:58
actionadmin_noticesincludes\class-alg-wc-stock-triggers-admin.php:59
actionwoocommerce_reduce_order_stockincludes\class-alg-wc-stock-triggers-admin.php:64
actionwoocommerce_restore_order_stockincludes\class-alg-wc-stock-triggers-admin.php:65
actioninitincludes\class-alg-wc-stock-triggers-core.php:42
actioninitincludes\class-alg-wc-stock-triggers.php:78
actionbefore_woocommerce_initincludes\class-alg-wc-stock-triggers.php:81
actioninitincludes\class-alg-wc-stock-triggers.php:163
actioninitincludes\class-alg-wc-stock-triggers.php:169
filterwoocommerce_get_settings_pagesincludes\class-alg-wc-stock-triggers.php:175
actionadmin_initincludes\class-alg-wc-stock-triggers.php:182
filterwoocommerce_get_sections_alg_wc_stock_triggersincludes\settings\class-alg-wc-stock-triggers-settings-section.php:40
actionadmin_noticesincludes\settings\class-alg-wc-stock-triggers-settings.php:83
actionplugins_loadedstock-triggers-for-woocommerce.php:58
Maintenance & Trust

Automated Stock Update Triggers for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 9, 2025
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings6
Active installs80
Developer Profile

Automated Stock Update Triggers for WooCommerce Developer Profile

WPFactory

64 plugins · 137K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
94 days
View full developer profile
Detection Fingerprints

How We Detect Automated Stock Update Triggers for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stock-triggers-for-woocommerce/assets/css/stock-triggers-for-woocommerce-admin.css/wp-content/plugins/stock-triggers-for-woocommerce/assets/js/stock-triggers-for-woocommerce-admin.js
Version Parameters
/wp-content/plugins/stock-triggers-for-woocommerce/assets/css/stock-triggers-for-woocommerce-admin.css?ver=/wp-content/plugins/stock-triggers-for-woocommerce/assets/js/stock-triggers-for-woocommerce-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
alg-wc-stock-triggers-debug-log
HTML Comments
<!-- Begin: Algolicous - Stock Triggers for WooCommerce --><!-- End: Algolicous - Stock Triggers for WooCommerce --><!-- alg_wc_stock_triggers_debug_log -->
Data Attributes
data-alg-wc-stock-triggers-debug-log
JS Globals
alg_wc_stock_triggers_debug_logalg_wc_stock_triggers_debug_log_json
FAQ

Frequently Asked Questions about Automated Stock Update Triggers for WooCommerce