
Subaccounts for WooCommerce Security & Risk Analysis
wordpress.org/plugins/subaccounts-for-woocommerceThe best subaccount management plugin for WooCommerce. Easily allow customers to create subaccounts or add users to their company accounts.
Is Subaccounts for WooCommerce Safe to Use in 2026?
Generally Safe
Score 97/100Subaccounts for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The 'subaccounts-for-woocommerce' plugin, version 1.9.3, demonstrates several positive security practices. The static analysis shows a complete absence of unprotected entry points (AJAX handlers, REST API routes, shortcodes) and a strong reliance on prepared statements for all SQL queries. Additionally, the presence of numerous nonce and capability checks suggests an awareness of common WordPress security vulnerabilities.
However, there are areas for improvement. While taint analysis found no critical or high-severity issues, a notable 24% of output operations are not properly escaped. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully during output. The plugin also bundles Freemius v1.0, an older version, which might contain known vulnerabilities.
The plugin's vulnerability history, with two known CVEs including a high and a medium severity issue, is a significant concern. While currently unpatched CVEs are reported as zero, the types of past vulnerabilities (Authorization Bypass and XSS) are serious and indicate a pattern that warrants vigilance. The presence of these past vulnerabilities, despite current good practices in the analyzed code, suggests that historical security issues have existed, and ongoing review and patching are crucial.
Key Concerns
- Significant percentage of unescaped output
- Bundled outdated library (Freemius v1.0)
- Past high severity vulnerability
- Past medium severity vulnerability
Subaccounts for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Subaccounts for WooCommerce <= 1.6.6 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover
Subaccounts for WooCommerce <= 1.6.0 - Reflected Cross-Site Scripting
Subaccounts for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Subaccounts for WooCommerce Attack Surface
AJAX Handlers 4
Shortcodes 4
WordPress Hooks 69
Maintenance & Trust
Subaccounts for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Subaccounts for WooCommerce Alternatives
User Switching
user-switching
Instant switching between user accounts in WordPress and WooCommerce.
B2BKing — Ultimate WooCommerce B2B and Wholesale Solution — Dynamic Pricing, Wholesale Order Form & More
b2bking-wholesale-for-woocommerce
B2BKing is the complete solution for running a Wholesale, B2B or B2B + B2C hybrid store with WooCommerce.
Admin Bar User Switching
admin-bar-user-switching
Extends the excellent User Switching plugin by John Blackbourn by adding a User Switching to the admin bar for quick and easy user switching.
Authors Widget
authors
Authors Widget shows the list or cloud of the authors in the sidemenu.
Whols – Wholesale Prices and B2B Store Solution for WooCommerce
whols
WooCommerce Wholesale plugin for WooCommerce wholesale pricing. It is a b2b plugin for WooCommerce. WooCommerce B2B or B2B + B2C hybrid Store Solution
Subaccounts for WooCommerce Developer Profile
1 plugin · 200 total installs
How We Detect Subaccounts for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subaccounts-for-woocommerce/assets/css/admin-style.css/wp-content/plugins/subaccounts-for-woocommerce/assets/css/public-style.css/wp-content/plugins/subaccounts-for-woocommerce/assets/js/admin-script.js/wp-content/plugins/subaccounts-for-woocommerce/assets/js/public-script.js/wp-content/plugins/subaccounts-for-woocommerce/freemius/start.phpsubaccounts-for-woocommerce/assets/css/admin-style.css?ver=subaccounts-for-woocommerce/assets/css/public-style.css?ver=subaccounts-for-woocommerce/assets/js/admin-script.js?ver=subaccounts-for-woocommerce/assets/js/public-script.js?ver=HTML / DOM Fingerprints
sfwc-admin-wrapsfwc-tabs-navsfwc-tabs-contentsfwc-subaccount-list-tablesfwc-subaccount-details-sectionsfwc-parent-account-infosfwc-add-subaccount-formsfwc-subaccount-roles-select+1 more<!-- Begin Subaccounts for WooCommerce Admin --><!-- Subaccounts for WooCommerce :: Main Admin Wrapper --><!-- Subaccounts for WooCommerce :: Tabs Navigation --><!-- Subaccounts for WooCommerce :: Tab Content -->+6 moredata-sfwc-tabdata-sfwc-subaccount-iddata-sfwc-user-idsfwc_admin_paramssfwc_public_paramsSubaccountsForWooCommercesfwc_localize/wp-json/sfwc/v1/subaccounts/wp-json/sfwc/v1/subaccounts/(?P<id>[\d]+)/wp-json/sfwc/v1/permissions/wp-json/sfwc/v1/users[sfwc_subaccount_dashboard][sfwc_subaccount_login][sfwc_subaccount_list]