Virtual Shop For Woocommecre Security & Risk Analysis

wordpress.org/plugins/virtual-shop-for-woocommecre

This plugin will connect woocommerce with vrshop. providing product information and cart processing. Payment is made on the website.

10 active installs v0.1.1 PHP 5.4+ WP 4.0+ Updated Mar 17, 2018
virtual-realityvrwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Virtual Shop For Woocommecre Safe to Use in 2026?

Generally Safe

Score 85/100

Virtual Shop For Woocommecre has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The virtual-shop-for-woocommecre plugin exhibits a mixed security posture. While it has no recorded vulnerabilities and a relatively small attack surface with no immediately obvious unprotected entry points, the static analysis reveals significant concerns regarding its code quality and data handling. The complete absence of prepared statements for all SQL queries is a major red flag, suggesting a high risk of SQL injection vulnerabilities. Furthermore, taint analysis indicates three high-severity flows with unsanitized paths, which could lead to various injection attacks if not properly handled. The plugin also lacks capability checks, meaning that sensitive actions could potentially be performed by unauthenticated or low-privileged users.

Key Concerns

  • No SQL prepared statements used
  • High severity taint flows found
  • No capability checks
  • Less than ideal output escaping
Vulnerabilities
None known

Virtual Shop For Woocommecre Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Virtual Shop For Woocommecre Code Analysis

Dangerous Functions
0
Raw SQL Queries
11
0 prepared
Unescaped Output
13
21 escaped
Nonce Checks
4
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared11 total queries

Output Escaping

62% escaped34 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
wc_vrshop_main_page (wc_virtual_shop.php:85)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Virtual Shop For Woocommecre Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wc_vr_shop] wc_virtual_shop.php:40
WordPress Hooks 3
actioninitwc_virtual_shop.php:43
actioninitwc_virtual_shop.php:44
actionwoocommerce_checkout_update_order_metawc_virtual_shop.php:45
Maintenance & Trust

Virtual Shop For Woocommecre Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedMar 17, 2018
PHP min version5.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Virtual Shop For Woocommecre Developer Profile

eewann

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Virtual Shop For Woocommecre

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/virtual-shop-for-woocommecre/css/wc_vrshop_main.css/wp-content/plugins/virtual-shop-for-woocommecre/js/wc_vrshop_main.js
Script Paths
/wp-content/plugins/virtual-shop-for-woocommecre/js/wc_vrshop_main.js
Version Parameters
virtual-shop-for-woocommecre/css/wc_vrshop_main.css?ver=virtual-shop-for-woocommecre/js/wc_vrshop_main.js?ver=

HTML / DOM Fingerprints

CSS Classes
woocommerce
HTML Comments
<!--tr> <th>Product Processor URL</th> <td>'.htmlentities(get_permalink()).'</td> </tr--><!--tr> <th>Cart Processor URL</th> <td>'.htmlentities(get_permalink()).'</td> </tr-->
Data Attributes
name="wc_vr_shop_shop_key"name="vr_shop_update_nonce"name="wc_vr_shop_copy_page_template"name="vr_shop_ctemplate_nonce"name="create_session"
Shortcode Output
<div class="woocommerce">
FAQ

Frequently Asked Questions about Virtual Shop For Woocommecre