TyresAddict – Tyre Custom Metadata for WooCommerce Security & Risk Analysis

wordpress.org/plugins/tyresaddict-woo-tyre-custom-metadata

Create custom tyre (size specification, season, vehicle, etc) and wheel metadata via MetaBox for WooCommerce Products. Show on product pages, edit.

100 active installs v2.3.1 PHP 7.4+ WP 4.7+ Updated Feb 9, 2026
auto-partsautomotivecustom-fieldsecommercetyres
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TyresAddict – Tyre Custom Metadata for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

TyresAddict – Tyre Custom Metadata for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "tyresaddict-woo-tyre-custom-metadata" v2.3.1 presents a mixed security profile. On the positive side, the static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all detected SQL queries utilize prepared statements, and there are no indications of file operations or external HTTP requests, which are common vectors for exploits. The absence of known vulnerabilities in its history is also a strong positive indicator.

However, a significant concern arises from the output escaping. The analysis shows that 100% of the 29 identified outputs are not properly escaped. This means that any data displayed by the plugin, if it originates from user input or an untrusted source, could potentially be vulnerable to Cross-Site Scripting (XSS) attacks. Additionally, the plugin lacks nonce checks, which are crucial for preventing Cross-Site Request Forgery (CSRF) attacks, especially if any user interaction is processed. The single capability check is a positive sign but doesn't mitigate the lack of nonce checks.

In conclusion, while the plugin demonstrates good practices in minimizing its attack surface and handling database interactions securely, the complete lack of output escaping represents a critical weakness. The absence of nonce checks also contributes to potential security risks. The vulnerability history is currently clean, but the identified code-level issues could lead to vulnerabilities if not addressed. Users should be cautious due to the unescaped output.

Key Concerns

  • Outputs are not properly escaped
  • No nonce checks implemented
Vulnerabilities
None known

TyresAddict – Tyre Custom Metadata for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TyresAddict – Tyre Custom Metadata for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
29
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

0% escaped29 total outputs
Attack Surface

TyresAddict – Tyre Custom Metadata for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_menuincludes\FeatureProMenu.php:20
actionadmin_menuincludes\FeatureProMenu.php:37
filterrwmb_meta_boxesincludes\FeatureTyres.php:20
actionadd_meta_boxesincludes\FeatureTyres.php:21
filterrwmb_meta_boxesincludes\FeatureWheels.php:20
actionadd_meta_boxesincludes\FeatureWheels.php:21
actionadmin_menuincludes\PageOptions.php:30
actionadmin_initincludes\PageOptions.php:31
actionadmin_enqueue_scriptsincludes\Plugin.php:109
actionwp_enqueue_scriptsincludes\Plugin.php:129
actionwoocommerce_product_meta_endincludes\Plugin.php:132
filterwoocommerce_display_product_attributesincludes\Plugin.php:135
actionplugins_loadedtyresaddict-woo-tyre-custom-metadata.php:44
filterplugin_action_linkstyresaddict-woo-tyre-custom-metadata.php:62
Maintenance & Trust

TyresAddict – Tyre Custom Metadata for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version7.4
Downloads10K

Community Trust

Rating74/100
Number of ratings3
Active installs100
Developer Profile

TyresAddict – Tyre Custom Metadata for WooCommerce Developer Profile

TyresAddict

5 plugins · 370 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TyresAddict – Tyre Custom Metadata for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tyresaddict-woo-tyre-custom-metadata/public/css/tcm-admin.css
Version Parameters
tyresaddict-woo-tyre-custom-metadata/public/css/tcm-admin.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about TyresAddict – Tyre Custom Metadata for WooCommerce