
StoreContrl Woocommerce Security & Risk Analysis
wordpress.org/plugins/storecontrl-wp-connectionAutomatiseer eenvoudig je productvoorraad-beheer van en naar je Woocommerce webshop. Geen handmatige invoer op meerdere plekken maar alles geregeld va …
Is StoreContrl Woocommerce Safe to Use in 2026?
Generally Safe
Score 98/100StoreContrl Woocommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The storecontrl-wp-connection plugin version 4.2.9 exhibits a concerning security posture, primarily due to a significant lack of authentication checks on its entry points. With all 10 identified AJAX handlers lacking any form of authorization, this plugin presents a broad attack surface that could be exploited by unauthenticated users. While the static analysis did not identify critical or high severity taint flows, the presence of 5 flows with unsanitized paths, though not categorized as critical, warrants attention as it could indicate potential for unintended file system interactions or path traversal if not properly handled downstream. The vulnerability history, while showing no currently unpatched high-severity CVEs, does reveal a past high-severity vulnerability categorized as Improper Limitation of a Pathname to a Restricted Directory, which aligns with the taint analysis findings. This historical pattern suggests a recurring weakness in handling file paths, reinforcing the concern about the unsanitized paths found in the current analysis.
Despite these significant concerns, the plugin does show some positive aspects. The majority of SQL queries utilize prepared statements, and there is at least one instance of nonce and capability checks, indicating some awareness of WordPress security best practices. However, the overwhelming number of unprotected AJAX endpoints and the historical path traversal vulnerability significantly overshadow these strengths. The low percentage of properly escaped output also adds to the potential for cross-site scripting vulnerabilities. Overall, the plugin requires substantial security improvements, particularly regarding authentication and input validation, to mitigate the identified risks.
Key Concerns
- 10 AJAX handlers without auth checks
- 5 flows with unsanitized paths
- 13% properly escaped output
- Past high severity path traversal vuln
- 1 nonce check for 10 entry points
- 2 capability checks for 10 entry points
StoreContrl Woocommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
StoreContrl Woocommerce <= 4.1.3 - Unauthenticated Arbitrary File Download
StoreContrl Woocommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
StoreContrl Woocommerce Attack Surface
AJAX Handlers 10
WordPress Hooks 37
Scheduled Events 2
Maintenance & Trust
StoreContrl Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
StoreContrl Woocommerce Alternatives
Extendago Woocommerce
extendago-wp-connection
Extenda GO Connect, developed and maintained by Arture, makes it simple. No duplication of work, but a central place for your product management.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
StoreContrl Woocommerce Developer Profile
2 plugins · 90 total installs
How We Detect StoreContrl Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/storecontrl-wp-connection/includes/css/bootstrap-glyphicons.css/wp-content/plugins/storecontrl-wp-connection/includes/css/bootstrap-toggle.min.css/wp-content/plugins/storecontrl-wp-connection/includes/css/bootstrap.min.css/wp-content/plugins/storecontrl-wp-connection/includes/css/timepicker.css/wp-content/plugins/storecontrl-wp-connection/admin/css/storecontrl-wp-connection-admin.css<!-- StoreContrl Connect active (v[0-9.]+?) -->/wp-content/plugins/storecontrl-wp-connection/includes/js/bootstrap.min.js/wp-content/plugins/storecontrl-wp-connection/includes/js/bootstrap-toggle.min.js/wp-content/plugins/storecontrl-wp-connection/includes/js/timepicker.js/wp-content/plugins/storecontrl-wp-connection/admin/js/storecontrl-wp-connection-admin.jsstorecontrl-wp-connection/admin/css/storecontrl-wp-connection-admin.css?ver=storecontrl-wp-connection/includes/css/bootstrap-glyphicons.css?ver=storecontrl-wp-connection/includes/css/bootstrap-toggle.min.css?ver=storecontrl-wp-connection/includes/css/bootstrap.min.css?ver=storecontrl-wp-connection/includes/css/timepicker.css?ver=storecontrl-wp-connection/includes/js/bootstrap-toggle.min.js?ver=storecontrl-wp-connection/includes/js/bootstrap.min.js?ver=storecontrl-wp-connection/includes/js/timepicker.js?ver=storecontrl-wp-connection/admin/js/storecontrl-wp-connection-admin.js?ver=HTML / DOM Fingerprints
storecontrl-connect-settings-page<!-- StoreContrl Connect active (v[0-9.]*) -->data-targetdata-toggledata-urlstorecontrl_wp_connection_admin_params