
Holiday for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-holidayAdds a link to your WooCommerce menu "Holiday for WooCommerce" which allows you to disable the WooCommerce purchasing options but keep the p …
Is Holiday for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Holiday for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-holiday" v1.1 plugin exhibits a generally positive security posture based on the static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong indicator of good coding practices. Furthermore, the lack of known CVEs and a clean vulnerability history suggest a well-maintained and secure plugin over time.
However, a significant concern arises from the complete absence of nonce checks and capability checks. While the static analysis reports zero entry points, this does not guarantee future security. If any new entry points are introduced or existing ones are not properly secured in future versions, the lack of these fundamental WordPress security mechanisms could expose the plugin to significant risks, such as Cross-Site Request Forgery (CSRF) and unauthorized privilege escalation.
Additionally, a notable portion of output (43%) is not properly escaped. This represents a potential Cross-Site Scripting (XSS) vulnerability if user-supplied data is ever reflected in the output without adequate sanitization. While the current attack surface appears minimal, a balanced conclusion is that while the plugin demonstrates good underlying code hygiene, the lack of essential security checks and incomplete output escaping present latent risks that require attention.
Key Concerns
- Missing nonce checks
- Missing capability checks
- High percentage of unescaped output
Holiday for WooCommerce Security Vulnerabilities
Holiday for WooCommerce Code Analysis
Output Escaping
Holiday for WooCommerce Attack Surface
WordPress Hooks 6
Maintenance & Trust
Holiday for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Holiday for WooCommerce Alternatives
Holy Day Off
holy-day-off
The #1 Shabbat & Jewish holiday plugin for WordPress. Automatically close your WooCommerce store on schedule. Set your city once, rest every week.
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution
shopengine
WooCommerce builder for Elementor and Gutenberg. It offers product templates, product sliders, shopping cart, quick view, Woo wishlist, product filter …
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
woo-product-feed-pro
Most popular WooCommerce product feed plugin supporting Google shopping feed, meta/facebook feed, bing product feed & more.
Menu Cart for WooCommerce
woocommerce-menu-bar-cart
Automatically displays a shopping cart in your menu bar. Works with WooCommerce and Easy Digital Downloads (EDD)
Holiday for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect Holiday for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wc_widename="WCH_settings[WCH-field-1-1]"name="WCH_settings[WCH-field-1-2]"