
TyresAddict – Tyre Custom Metadata for WooCommerce Security & Risk Analysis
wordpress.org/plugins/tyresaddict-woo-tyre-custom-metadataCreate custom tyre (size specification, season, vehicle, etc) and wheel metadata via MetaBox for WooCommerce Products. Show on product pages, edit.
Is TyresAddict – Tyre Custom Metadata for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100TyresAddict – Tyre Custom Metadata for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "tyresaddict-woo-tyre-custom-metadata" v2.3.1 presents a mixed security profile. On the positive side, the static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all detected SQL queries utilize prepared statements, and there are no indications of file operations or external HTTP requests, which are common vectors for exploits. The absence of known vulnerabilities in its history is also a strong positive indicator.
However, a significant concern arises from the output escaping. The analysis shows that 100% of the 29 identified outputs are not properly escaped. This means that any data displayed by the plugin, if it originates from user input or an untrusted source, could potentially be vulnerable to Cross-Site Scripting (XSS) attacks. Additionally, the plugin lacks nonce checks, which are crucial for preventing Cross-Site Request Forgery (CSRF) attacks, especially if any user interaction is processed. The single capability check is a positive sign but doesn't mitigate the lack of nonce checks.
In conclusion, while the plugin demonstrates good practices in minimizing its attack surface and handling database interactions securely, the complete lack of output escaping represents a critical weakness. The absence of nonce checks also contributes to potential security risks. The vulnerability history is currently clean, but the identified code-level issues could lead to vulnerabilities if not addressed. Users should be cautious due to the unescaped output.
Key Concerns
- Outputs are not properly escaped
- No nonce checks implemented
TyresAddict – Tyre Custom Metadata for WooCommerce Security Vulnerabilities
TyresAddict – Tyre Custom Metadata for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
TyresAddict – Tyre Custom Metadata for WooCommerce Attack Surface
WordPress Hooks 14
Maintenance & Trust
TyresAddict – Tyre Custom Metadata for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
TyresAddict – Tyre Custom Metadata for WooCommerce Alternatives
TyresAddict – Tyre Product Filter for WooCommerce
tyresaddict-woo-tyre-product-filter
Tyre Product Filter help shoppers find tyres on WooCommerce shop. Filter tyres by size, season, car type and tyre brand.
YMM Product Filter for Woo – Year Make Model search
tyresaddict-ymm-product-filter
Filter and search products using Year Make Model. Finder widgets for pages with Elementor support, import/export YMM data.
WooCommerce
woocommerce
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
TyresAddict – Tyre Custom Metadata for WooCommerce Developer Profile
5 plugins · 370 total installs
How We Detect TyresAddict – Tyre Custom Metadata for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tyresaddict-woo-tyre-custom-metadata/public/css/tcm-admin.csstyresaddict-woo-tyre-custom-metadata/public/css/tcm-admin.css?ver=