SuperPlus for WooCommerce Security & Risk Analysis

wordpress.org/plugins/superplus-for-woocommerce

Multi-step checkout for WooCommerce — no bloat, no conflicts. Only the features you enable are loaded.

0 active installs v1.0.1 PHP 7.0+ WP 4.7+ Updated Unknown
checkout-customizationcheckout-stepsmulti-step-checkoutstep-checkoutwoocommerce-checkout
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SuperPlus for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

SuperPlus for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "superplus-for-woocommerce" v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. A notable strength is the absence of any recorded CVEs, indicating a history of responsible development or limited exposure to publicly known vulnerabilities. Furthermore, the plugin demonstrates good security practices with all SQL queries utilizing prepared statements and a healthy number of nonce and capability checks across its entry points.

However, there are a few areas for concern. While the attack surface is relatively small with only 4 entry points, the fact that 0 are marked as unprotected is positive. The primary area for improvement lies in output escaping, where only 71% of outputs are properly escaped. This leaves a significant portion (29%) of outputs potentially vulnerable to cross-site scripting (XSS) attacks if malicious data is injected through available entry points. The lack of taint analysis results is also worth noting; while it could mean no issues were found, it might also suggest that the analysis itself was incomplete or limited in scope.

In conclusion, the plugin is built on a solid foundation with regard to data handling (SQL) and authentication mechanisms. The absence of critical vulnerabilities in its history is reassuring. The most immediate risk stems from the unescaped output, which requires attention to mitigate potential XSS vulnerabilities. Further investigation into the limitations of the taint analysis might also be beneficial.

Key Concerns

  • Unescaped output detected (29%)
Vulnerabilities
None known

SuperPlus for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SuperPlus for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
146
358 escaped
Nonce Checks
8
Capability Checks
16
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped504 total outputs
Attack Surface

SuperPlus for WooCommerce Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 2

authwp_ajax_sp_wsv_dismiss_comunidad_alert1.0.1\includes\admin\class-sp-wsv-admin.php:26
authwp_ajax_sp_wsv_dismiss_comunidad_alertincludes\admin\class-sp-wsv-admin.php:26

Shortcodes 2

[sp_wsv_checkout] 1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:36
[sp_wsv_checkout] includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:36
WordPress Hooks 52
actionadmin_menu1.0.1\includes\admin\class-sp-wsv-admin.php:22
actionadmin_enqueue_scripts1.0.1\includes\admin\class-sp-wsv-admin.php:23
actionadmin_post_sp_wsv_save_modules1.0.1\includes\admin\class-sp-wsv-admin.php:24
filterredirect_location1.0.1\includes\admin\class-sp-wsv-admin.php:28
filterallowed_redirect_hosts1.0.1\includes\admin\class-sp-wsv-admin.php:316
filterplugin_row_meta1.0.1\includes\admin\class-sp-wsv-plugin-meta.php:23
actioninit1.0.1\includes\class-sp-wsv-plugin.php:43
actioninit1.0.1\includes\class-sp-wsv-plugin.php:44
actionadmin_notices1.0.1\includes\class-sp-wsv-plugin.php:48
filterwoocommerce_enqueue_styles1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:41
filterbody_class1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:42
actionwoocommerce_before_checkout_form1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:43
actionsp_wsv_simple_header_after_logo1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:44
actionwoocommerce_thankyou1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:45
filtertemplate_include1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:48
filterwoocommerce_locate_template1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:49
actionwoocommerce_checkout_before_customer_details1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:51
actionwoocommerce_checkout_after_order_review1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:52
filterwoocommerce_update_order_review_fragments1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:55
actionwp_enqueue_scripts1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:56
actionadmin_init1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:59
actionadmin_init1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:60
actionadmin_enqueue_scripts1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:61
actionwp1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:63
filterwoocommerce_is_checkout1.0.1\includes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:232
actionplugins_loaded1.0.1\superplus-for-woocommerce.php:49
actionadmin_menuincludes\admin\class-sp-wsv-admin.php:22
actionadmin_enqueue_scriptsincludes\admin\class-sp-wsv-admin.php:23
actionadmin_post_sp_wsv_save_modulesincludes\admin\class-sp-wsv-admin.php:24
filterredirect_locationincludes\admin\class-sp-wsv-admin.php:28
filterallowed_redirect_hostsincludes\admin\class-sp-wsv-admin.php:316
filterplugin_row_metaincludes\admin\class-sp-wsv-plugin-meta.php:23
actioninitincludes\class-sp-wsv-plugin.php:43
actioninitincludes\class-sp-wsv-plugin.php:44
actionadmin_noticesincludes\class-sp-wsv-plugin.php:48
filterwoocommerce_enqueue_stylesincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:41
filterbody_classincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:42
actionwoocommerce_before_checkout_formincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:43
actionsp_wsv_simple_header_after_logoincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:44
actionwoocommerce_thankyouincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:45
filtertemplate_includeincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:48
filterwoocommerce_locate_templateincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:49
actionwoocommerce_checkout_before_customer_detailsincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:51
actionwoocommerce_checkout_after_order_reviewincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:52
filterwoocommerce_update_order_review_fragmentsincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:55
actionwp_enqueue_scriptsincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:56
actionadmin_initincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:59
actionadmin_initincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:60
actionadmin_enqueue_scriptsincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:61
actionwpincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:63
filterwoocommerce_is_checkoutincludes\modules\checkout-steps\class-sp-wsv-module-checkout-steps.php:232
actionplugins_loadedsuperplus-for-woocommerce.php:49
Maintenance & Trust

SuperPlus for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.0
Downloads111

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SuperPlus for WooCommerce Developer Profile

agenciasp

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SuperPlus for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/superplus-for-woocommerce/assets/css/sp-wsv-admin.css/wp-content/plugins/superplus-for-woocommerce/assets/js/sp-wsv-admin.js/wp-content/plugins/superplus-for-woocommerce/assets/js/sp-wsv-select2.js/wp-content/plugins/superplus-for-woocommerce/assets/css/sp-wsv-select2.css

HTML / DOM Fingerprints

CSS Classes
sp-wsv-pro-btnsp_wsv_comunidad_dismissedsp-wsv-notice
HTML Comments
<!-- Global Settings --><!-- Modules Settings --><!-- Settings Tabs --><!-- Module Settings Area -->+1 more
Data Attributes
data-dismiss-noncedata-dismiss-action
JS Globals
SP_WSV_Adminsp_wsv_admin_params
FAQ

Frequently Asked Questions about SuperPlus for WooCommerce