Totals Report for WooCommerce Security & Risk Analysis

wordpress.org/plugins/totals-report-for-woocommerce

Comprehensive product inventory reporting tool with detailed insights into your WooCommerce product catalog.

0 active installs v1.0.2 PHP 7.2+ WP 5.0+ Updated Apr 22, 2025
inventoryproductsreportstockwoocommerce-report
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Totals Report for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Totals Report for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "totals-report-for-woocommerce" plugin version 1.0.2 exhibits a strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is commendable. Furthermore, the code signals indicate a positive security focus, with no dangerous functions, all SQL queries using prepared statements, and an exceptionally high percentage of properly escaped output. The presence of nonce and capability checks, despite the limited attack surface, suggests an awareness of security best practices. Taint analysis revealing zero flows with unsanitized paths further reinforces this positive assessment.

However, a minor concern arises from the single identified file operation. While not inherently malicious, file operations can sometimes represent an attack vector if not handled with extreme care, especially if they involve user-provided input. The vulnerability history being completely clear is a significant strength, implying a history of stable and secure development. In conclusion, this plugin appears to be well-secured with robust coding practices. The minimal identified risk points towards a low likelihood of severe security vulnerabilities, though the single file operation warrants a degree of caution.

Key Concerns

  • File operation detected
Vulnerabilities
None known

Totals Report for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Totals Report for WooCommerce Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Totals Report for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
89 escaped
Nonce Checks
3
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped92 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
render_report_page (includes/class-trwc-report-admin.php:131)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Totals Report for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_noticesincludes/class-trwc-report-admin.php:65
actionadmin_menuincludes/class-trwc-report-admin.php:74
actionadmin_enqueue_scriptsincludes/class-trwc-report-admin.php:75
actionadmin_initincludes/class-trwc-report-export.php:49
actionwoocommerce_flush_cacheincludes/class-trwc-report.php:49
actionadmin_noticestotals-report-for-woocommerce.php:83
actionplugin_row_metatotals-report-for-woocommerce.php:118
actionadmin_inittotals-report-for-woocommerce.php:140
actionplugins_loadedtotals-report-for-woocommerce.php:190
actionbefore_woocommerce_inittotals-report-for-woocommerce.php:193
Maintenance & Trust

Totals Report for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 22, 2025
PHP min version7.2
Downloads270

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Totals Report for WooCommerce Developer Profile

Christoforos Aivazidis

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Totals Report for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/totals-report-for-woocommerce/assets/css/report.css/wp-content/plugins/totals-report-for-woocommerce/assets/js/report.js/wp-content/plugins/totals-report-for-woocommerce/assets/js/report-export.js
Script Paths
/wp-content/plugins/totals-report-for-woocommerce/assets/js/report.js/wp-content/plugins/totals-report-for-woocommerce/assets/js/report-export.js
Version Parameters
/wp-content/plugins/totals-report-for-woocommerce/assets/css/report.css?ver=/wp-content/plugins/totals-report-for-woocommerce/assets/js/report.js?ver=/wp-content/plugins/totals-report-for-woocommerce/assets/js/report-export.js?ver=

HTML / DOM Fingerprints

CSS Classes
trwc-report-tabletrwc-export-button
Data Attributes
data-trwc-report-filter
JS Globals
TRWC_Report_Admin
FAQ

Frequently Asked Questions about Totals Report for WooCommerce