WP e-Commerce – Store Toolkit Security & Risk Analysis

wordpress.org/plugins/store-toolkit-for-wp-e-commerce

This is a legacy Plugin, please see WP e-Commerce - Store Toolkit for the latest release.

10 active installs v1.0 PHP + WP 2.9.2+ Updated May 12, 2014
carte-commerceecommerceshopwp-e-commerce
83
B · Generally Safe
CVEs total1
Unpatched0
Last CVEFeb 15, 2016
Safety Verdict

Is WP e-Commerce – Store Toolkit Safe to Use in 2026?

Mostly Safe

Score 83/100

WP e-Commerce – Store Toolkit is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVELast CVE: Feb 15, 2016Updated 11yr ago
Risk Assessment

The static analysis of store-toolkit-for-wp-e-commerce v1.0 reveals an exceptionally clean codebase with no apparent vulnerabilities in its attack surface, dangerous functions, SQL queries, output escaping, file operations, or external HTTP requests. The absence of any identified taint flows further strengthens this perception. However, a significant concern arises from the plugin's vulnerability history, which lists one critical CVE related to missing authorization. While this vulnerability is currently marked as unpatched, the lack of specific details about its impact or exploitability within this data set makes it difficult to fully assess the current risk. The historical presence of a critical authorization issue, even if resolved in later versions (which is implied by 'currently unpatched: 0'), suggests a past weakness that could potentially resurface or indicate that authorization checks are an area requiring careful attention for this plugin.

Overall, the plugin exhibits good coding practices in its current version, demonstrating a strong adherence to security principles in its static code. The minimal attack surface and absence of common vulnerabilities are positive indicators. Nevertheless, the single critical CVE in its history, particularly a 'Missing Authorization' type, represents a potential weakness. While the 'currently unpatched: 0' suggests it may be fixed in later versions, the historical context warrants a cautious approach. The ideal scenario would involve confirmation that this specific CVE was addressed and that no similar authorization issues exist in the analyzed version, v1.0. For v1.0 specifically, the static analysis is excellent, but the historical context cannot be entirely ignored.

Key Concerns

  • Critical CVE in vulnerability history
Vulnerabilities
1

WP e-Commerce – Store Toolkit Security Vulnerabilities

CVEs by Year

1 CVE in 2016
2016
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

WP e-Commerce – Store Toolkit <= 2.0.1 - Missing Authorization

Feb 15, 2016 Patched in 2.0.2 (2899d)
Code Analysis
Analyzed Mar 17, 2026

WP e-Commerce – Store Toolkit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP e-Commerce – Store Toolkit Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

WP e-Commerce – Store Toolkit Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedMay 12, 2014
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP e-Commerce – Store Toolkit Developer Profile

Tom de Visser

7 plugins · 160 total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
2899 days
View full developer profile
Detection Fingerprints

How We Detect WP e-Commerce – Store Toolkit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/store-toolkit-for-wp-e-commerce/style.css/wp-content/plugins/store-toolkit-for-wp-e-commerce/js/store-toolkit.js
Script Paths
/wp-content/plugins/store-toolkit-for-wp-e-commerce/js/store-toolkit.js
Version Parameters
store-toolkit-for-wp-e-commerce/style.css?ver=store-toolkit-for-wp-e-commerce/js/store-toolkit.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP e-Commerce – Store Toolkit