Text Attributes for WooCommerce Security & Risk Analysis

wordpress.org/plugins/text-attributes-for-woocommerce

Allows you to type attribute values in the input field instead of choosing from the drop-down list.

300 active installs v1.0.3 PHP 5.2.4+ WP 4.7+ Updated Jun 4, 2020
attributeattribute-typeproduct-attributestext-attributewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Text Attributes for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Text Attributes for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The security posture of the "text-attributes-for-woocommerce" v1.0.3 plugin appears to be strong based on the provided static analysis and vulnerability history. The absence of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) significantly limits the plugin's attack surface, and crucially, there are no unprotected entry points. The code signals also indicate good practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of properly escaped output. The lack of file operations and external HTTP requests further reduces potential risks.

The taint analysis results showing zero flows with unsanitized paths or critical/high severity issues are reassuring. The vulnerability history is also entirely clear, with no known CVEs, which suggests a history of secure development or diligent patching by the developers. The plugin demonstrates a commitment to secure coding by avoiding common pitfalls.

Overall, this plugin exhibits a very good security profile. The most notable strengths are the minimal attack surface and the absence of known vulnerabilities or risky code patterns identified in the static analysis. While there are no specific immediate risks highlighted by the data, the only minor area for consideration is the 18% of output that is not properly escaped, which could theoretically lead to certain types of cross-site scripting (XSS) vulnerabilities if the unescaped content originates from untrusted sources. However, without specific flows identified, this is a minor concern in an otherwise robustly secured plugin.

Key Concerns

  • Some output not properly escaped
Vulnerabilities
None known

Text Attributes for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Text Attributes for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped11 total outputs
Attack Surface

Text Attributes for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitincludes\class-text-attributes-for-woocommerce.php:102
actionadmin_enqueue_scriptsincludes\class-text-attributes-for-woocommerce.php:116
filterproduct_attributes_type_selectorincludes\class-text-attributes-for-woocommerce.php:117
actionwoocommerce_product_option_termsincludes\class-text-attributes-for-woocommerce.php:118
actionplugins_loadedtext-attributes-for-woocommerce.php:43
Maintenance & Trust

Text Attributes for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 4, 2020
PHP min version5.2.4
Downloads4K

Community Trust

Rating100/100
Number of ratings4
Active installs300
Developer Profile

Text Attributes for WooCommerce Developer Profile

Andrei Zobnin

1 plugin · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Text Attributes for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/text-attributes-for-woocommerce/js/text-attributes-for-woocommerce-admin.js
Script Paths
/wp-content/plugins/text-attributes-for-woocommerce/js/text-attributes-for-woocommerce-admin.js
Version Parameters
text-attributes-for-woocommerce/js/text-attributes-for-woocommerce-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Text Attributes for WooCommerce