Toply Return Risk Predictor Security & Risk Analysis

wordpress.org/plugins/toply-return-risk-predictor

Identify high-risk customers for WooCommerce stores using historical order analysis.

0 active installs v1.0.2 PHP 7.4+ WP 5.0+ Updated Apr 7, 2026
blacklistcash-on-deliveryfraud-preventionreturnswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Toply Return Risk Predictor Safe to Use in 2026?

Generally Safe

Score 100/100

Toply Return Risk Predictor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'toply-return-risk-predictor' plugin v1.0.2 exhibits a strong adherence to secure coding practices in its static analysis. The complete absence of dangerous functions, 100% use of prepared statements for SQL queries, and 100% properly escaped output are significant strengths. Furthermore, the lack of file operations and external HTTP requests reduces the plugin's exposure to common attack vectors. The attack surface is currently zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, which is an excellent security posture. However, the taint analysis reveals two flows with unsanitized paths, flagged with high severity. While there are no known CVEs or recorded vulnerabilities in its history, these high-severity taint flows represent a potential, albeit theoretical, risk that should be investigated. The plugin's vulnerability history is clean, suggesting a well-maintained codebase, but the identified taint flows indicate that the code's security might not be as robust as initially suggested by the absence of other issues. Overall, the plugin has a good foundation but requires attention to the identified taint flow concerns.

Key Concerns

  • High severity taint flow with unsanitized path
  • High severity taint flow with unsanitized path
Vulnerabilities
None known

Toply Return Risk Predictor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Toply Return Risk Predictor Release Timeline

v1.0.2Current
v1.0.1
Code Analysis
Analyzed Apr 16, 2026

Toply Return Risk Predictor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
0
47 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared10 total queries

Output Escaping

100% escaped47 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
render_dashboard (toply-return-risk-predictor.php:192)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Toply Return Risk Predictor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedtoply-return-risk-predictor.php:43
actionadmin_menutoply-return-risk-predictor.php:44
actionadmin_enqueue_scriptstoply-return-risk-predictor.php:45
filtermanage_edit-shop_order_columnstoply-return-risk-predictor.php:46
actionmanage_shop_order_posts_custom_columntoply-return-risk-predictor.php:47
Maintenance & Trust

Toply Return Risk Predictor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 7, 2026
PHP min version7.4
Downloads77

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Toply Return Risk Predictor Developer Profile

TonioWeb

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Toply Return Risk Predictor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
/toply-return-risk-predictor/style.css?ver=1.0.2

HTML / DOM Fingerprints

CSS Classes
rs-wraprs-headerrs-bannerrs-info-boxrs-cardrs-gridrs-stat-labelrs-stat-val+6 more
FAQ

Frequently Asked Questions about Toply Return Risk Predictor