Ultimate WooCommerce Brands Security & Risk Analysis

wordpress.org/plugins/ultimate-woocommerce-brands

Add Brands taxonomy for products for WooCommerce plugin. Show brand name on product pages and category pages. Use widgets to display brands list.

500 active installs v2.0 PHP + WP 5.0+ Updated May 5, 2021
brandsdistributormanufacturersupplierwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate WooCommerce Brands Safe to Use in 2026?

Generally Safe

Score 85/100

Ultimate WooCommerce Brands has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "ultimate-woocommerce-brands" v2.0 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of known CVEs and historical vulnerabilities is a significant positive indicator, suggesting a mature and well-maintained codebase or a lack of previous exploitation attempts. The static analysis reveals a commendably small attack surface with no direct entry points like AJAX handlers, REST API routes, or shortcodes, and importantly, no identified unprotected entry points. Furthermore, the code uses prepared statements for all SQL queries, avoids file operations and external HTTP requests, and importantly, lacks critical taint analysis findings. However, a significant concern is the low percentage of properly escaped output (40%). This indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient sanitization before being displayed. The lack of nonce and capability checks across all identified entry points, though the total number of entry points is zero, is a theoretical weakness that could become a problem if new entry points are introduced without proper security measures. Despite the clean vulnerability history, the insufficient output escaping remains the primary actionable security concern.

Key Concerns

  • Insufficient output escaping
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

Ultimate WooCommerce Brands Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ultimate WooCommerce Brands Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped25 total outputs
Attack Surface

Ultimate WooCommerce Brands Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actioninitmgwoocommercebrands-admin.php:22
actionwoocommerce_settings_tabs_mgwoocommercebrandsmgwoocommercebrands-admin.php:24
actionwoocommerce_update_options_mgwoocommercebrandsmgwoocommercebrands-admin.php:25
filterwoocommerce_settings_tabs_arraymgwoocommercebrands-admin.php:28
actionadmin_noticesmgwoocommercebrands-admin.php:30
actioninitmgwoocommercebrands-light.php:32
actioninitmgwoocommercebrands-light.php:33
actionadmin_initmgwoocommercebrands-light.php:35
actioninitmgwoocommercebrands-light.php:36
actionwoocommerce_before_single_productmgwoocommercebrands-light.php:38
actionwoocommerce_before_shop_loop_itemmgwoocommercebrands-light.php:39
actionwidgets_initmgwoocommercebrands-light.php:40
actionplugins_loadedmgwoocommercebrands-light.php:43
filterplugin_row_metamgwoocommercebrands-light.php:46
actionwoocommerce_single_product_summarymgwoocommercebrands-light.php:195
Maintenance & Trust

Ultimate WooCommerce Brands Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 5, 2021
PHP min version
Downloads38K

Community Trust

Rating72/100
Number of ratings11
Active installs500
Developer Profile

Ultimate WooCommerce Brands Developer Profile

MagniumThemes

8 plugins · 810 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate WooCommerce Brands

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-woocommerce-brands/css/mgwoocommercebrands-admin.css/wp-content/plugins/ultimate-woocommerce-brands/js/mgwoocommercebrands.js/wp-content/plugins/ultimate-woocommerce-brands/css/mgwoocommercebrands.css
Script Paths
/wp-content/plugins/ultimate-woocommerce-brands/js/mgwoocommercebrands.js

HTML / DOM Fingerprints

CSS Classes
mg-brand-wrappermg-brand-wrapper-productmg-brand-wrapper-category
FAQ

Frequently Asked Questions about Ultimate WooCommerce Brands