Product Category Showcase for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-category-showcase

Showcase WooCommerce product categories in sliders, grids, or blocks with styling control, responsive layouts, and shortcode support

1K active installs v2.3.0 PHP 7.4+ WP 5.2+ Updated Mar 11, 2026
sliderwoocommercewoocommerce-categorywoocommerce-category-showcasewoocommerce-category-slider
99
A · Safe
CVEs total2
Unpatched0
Last CVEDec 16, 2022
Safety Verdict

Is Product Category Showcase for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Product Category Showcase for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Dec 16, 2022Updated 23d ago
Risk Assessment

The wc-category-showcase plugin v2.3.0 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, file operations, and external HTTP requests is commendable. The plugin also demonstrates excellent practice in its SQL query handling, utilizing prepared statements exclusively. Furthermore, the high percentage of properly escaped output significantly reduces the risk of XSS vulnerabilities. The presence of numerous nonce and capability checks, while not explicitly detailed for uncovered areas, suggests an effort towards securing entry points.

Key Concerns

  • 2 medium severity CVEs known
  • 0 capability checks on entry points
  • Some output unescaped (3%)
Vulnerabilities
2

Product Category Showcase for WooCommerce Security Vulnerabilities

CVEs by Year

2 CVEs in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

Appsero <= 1.2.1 - Missing Authorization

Dec 16, 2022 Patched in 2.0.0 (699d)
CVE-2022-47150medium · 4.3Cross-Site Request Forgery (CSRF)

Appsero <= 1.2.0 - Cross-Site Request Forgery

Dec 14, 2022 Patched in 2.0.0 (701d)
Code Analysis
Analyzed Mar 16, 2026

Product Category Showcase for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
1234 escaped
Nonce Checks
8
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped1266 total outputs
Attack Surface

Product Category Showcase for WooCommerce Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 3

authwp_ajax_wc_category_showcase_search_categoriesincludes\Admin\Admin.php:29
authwp_ajax_wc_category_showcase_get_category_detailsincludes\Admin\Admin.php:30
authwp_ajax_wc_category_showcase_get_additional_category_detailsincludes\Admin\Admin.php:31

Shortcodes 1

[wccs_showcase] includes\Shortcodes\Shortcodes.php:24
WordPress Hooks 18
actionadmin_initincludes\Admin\Admin.php:23
filterwoocommerce_screen_idsincludes\Admin\Admin.php:24
actionadmin_enqueue_scriptsincludes\Admin\Admin.php:25
filteradmin_footer_textincludes\Admin\Admin.php:26
filterupdate_footerincludes\Admin\Admin.php:27
actionadmin_post_wcc_showcase_add_category_showcaseincludes\Admin\Admin.php:28
actionadmin_menuincludes\Admin\Menus.php:31
actionwc_category_showcase_settings_export-importincludes\Admin\Menus.php:32
actionwc_category_showcase_list-tableincludes\Admin\Menus.php:33
actionadmin_initincludes\Admin\Notices.php:20
actioninitincludes\Installer.php:29
actionwccs_migrate_dataincludes\Installer.php:32
actionplugins_loadedincludes\Plugin.php:61
actionbefore_woocommerce_initincludes\Plugin.php:63
actionwp_enqueue_scriptsincludes\Plugin.php:64
actionadmin_noticesincludes\Plugin.php:68
actioninitincludes\PostTypes.php:22
actionwp_enqueue_scriptsincludes\Shortcodes\Shortcodes.php:23

Scheduled Events 1

wccs_migrate_data
Maintenance & Trust

Product Category Showcase for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4
Downloads49K

Community Trust

Rating100/100
Number of ratings5
Active installs1K
Developer Profile

Product Category Showcase for WooCommerce Developer Profile

PluginEver

12 plugins · 14K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
317 days
View full developer profile
Detection Fingerprints

How We Detect Product Category Showcase for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-category-showcase/fonts/fontawesome/fontawesome-icons.css/wp-content/plugins/wc-category-showcase/fonts/happy-icons/happy-icons.css/wp-content/plugins/wc-category-showcase/styles/admin.css/wp-content/plugins/wc-category-showcase/styles/tailwind.css/wp-content/plugins/wc-category-showcase/styles/vendor.css/wp-content/plugins/wc-category-showcase/scripts/admin.js/wp-content/plugins/wc-category-showcase/scripts/vendor.js
Script Paths
/wp-content/plugins/wc-category-showcase/scripts/admin.js/wp-content/plugins/wc-category-showcase/scripts/vendor.js
Version Parameters
wc-category-showcase/styles/tailwind.css?ver=wc-category-showcase/fonts/fontawesome/fontawesome-icons.css?ver=wc-category-showcase/fonts/happy-icons/happy-icons.css?ver=wc-category-showcase/styles/vendor.css?ver=wc-category-showcase/scripts/vendor.js?ver=wc-category-showcase/styles/admin.css?ver=wc-category-showcase/scripts/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wccs_showcase
HTML Comments
Start output buffering.Add the plugin screens to the WooCommerce screens.This will load the WooCommerce admin styles and scripts.Open documentation in new tab.
Data Attributes
data-wccs-showcase-id
JS Globals
wcc_showcase_admin_js_vars
REST Endpoints
/wp-json/wc-category-showcase/v1/admin/search-categories/wp-json/wc-category-showcase/v1/admin/category-details/wp-json/wc-category-showcase/v1/admin/additional-category-details
Shortcode Output
[category_showcase]
FAQ

Frequently Asked Questions about Product Category Showcase for WooCommerce