Brands for WooCommerce Security & Risk Analysis

wordpress.org/plugins/unlimited-brands-for-woocommerce

Woocommerce Brands Plugin. You can assign poducts to brands. There\'s shortcode to display list of brands, as well as widget that provides filter …

10 active installs v2.0 PHP + WP 4.0+ Updated Dec 17, 2019
brand-taxonomyproduct-brandswoocommercewoocommerce-brandswoocommerce-brands-filter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Brands for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Brands for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "unlimited-brands-for-woocommerce" plugin version 2.0 presents a generally positive security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and any recorded vulnerabilities is a strong indicator of good development practices. Furthermore, the fact that 100% of SQL queries utilize prepared statements is excellent. However, a significant concern arises from the lack of proper output escaping, with only 30% of outputs being correctly handled. This leaves room for potential cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is being outputted directly without sufficient sanitization. The absence of nonce and capability checks, while not explicitly flagged as a risk in this data (due to zero unprotected entry points), could become a weakness if the entry points were to evolve or if specific functionalities within the shortcodes are sensitive and not adequately protected.

Despite the clean vulnerability history and the absence of critical taint flows, the low percentage of properly escaped output is the most prominent weakness. This plugin seems to be built with security in mind regarding data integrity and external interactions, but it falls short in protecting against client-side injection attacks. A balanced conclusion would note the plugin's strengths in data handling and lack of known exploits, but strongly advise addressing the output escaping issue to mitigate potential XSS risks.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Brands for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Brands for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

30% escaped30 total outputs
Attack Surface

Brands for WooCommerce Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[woo-single-brand] includes\shortcode.php:36
[woo-brands-slider] includes\shortcode.php:85
[woo-square-brands] includes\shortcode.php:130
[list-brands] includes\shortcode.php:174
WordPress Hooks 12
actionwoocommerce_product_meta_startincludes\functions.php:4
actionbrands_add_form_fieldsincludes\taxonomy-field.php:8
actioncreated_brandsincludes\taxonomy-field.php:9
actionbrands_edit_form_fieldsincludes\taxonomy-field.php:10
actionedited_brandsincludes\taxonomy-field.php:11
actionadmin_enqueue_scriptsincludes\taxonomy-field.php:12
actionadmin_footerincludes\taxonomy-field.php:13
actioninitincludes\taxonomy.php:45
actionwidgets_initincludes\widget\widget-filter-brands.php:116
actionwidgets_initincludes\widget\widget-list-brands.php:88
actionwp_enqueue_scriptsindex.php:66
actionpre_get_postsindex.php:84
Maintenance & Trust

Brands for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 17, 2019
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Brands for WooCommerce Developer Profile

Kaz Kadalashvili

3 plugins · 11K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Brands for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unlimited-brands-for-woocommerce/assets/slick/slick.js/wp-content/plugins/unlimited-brands-for-woocommerce/assets/js/main.js/wp-content/plugins/unlimited-brands-for-woocommerce/assets/slick/slick-theme.css/wp-content/plugins/unlimited-brands-for-woocommerce/assets/css/infinite-slider.css/wp-content/plugins/unlimited-brands-for-woocommerce/assets/css/style.css
Script Paths
/wp-content/plugins/unlimited-brands-for-woocommerce/assets/slick/slick.js/wp-content/plugins/unlimited-brands-for-woocommerce/assets/js/main.js

HTML / DOM Fingerprints

CSS Classes
customer-logossquare-logossquare-elementbrands-listsingle-product-brandslable-brands
Data Attributes
category-image-id
JS Globals
brandslider
Shortcode Output
[woo-single-brand][woo-brands-slider][woo-square-brands][list-brands]
FAQ

Frequently Asked Questions about Brands for WooCommerce