Product Customer List for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-product-customer-list

Display a list of customers who bought a specific product at the bottom of the product edit page in WooCommerce and send them e-mails.

9K active installs v3.1.8 PHP + WP 5.0+ Updated Jan 27, 2025
admin-order-listcustomer-listproduct-specificwho-boughtwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Product Customer List for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Product Customer List for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "wc-product-customer-list" v3.1.8 demonstrates a generally strong security posture due to its adherence to several WordPress security best practices. The absence of known CVEs, critical taint flows, and raw SQL queries is highly encouraging. All identified SQL queries utilize prepared statements, a critical safeguard against SQL injection. Furthermore, the plugin incorporates nonce and capability checks, which are essential for protecting entry points.

However, a significant concern arises from the output escaping. With only 3% of observed outputs properly escaped, the plugin presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data, if not properly sanitized before being displayed, could be injected and executed by an attacker within the user's browser.

While the vulnerability history is clean, suggesting good development practices to date, the glaring issue with output escaping requires immediate attention. The plugin has a limited attack surface with no unprotected entry points, which is positive. The bundled libraries, DataTables v1.10.24 and Freemius v1.0, while not critically outdated, are worth monitoring for known vulnerabilities in future analysis.

Key Concerns

  • Poor output escaping (3% proper)
  • Bundled outdated library: DataTables v1.10.24
  • Bundled outdated library: Freemius v1.0
Vulnerabilities
None known

Product Customer List for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Product Customer List for WooCommerce Release Timeline

v3.1.8Current
v3.1.7
v3.1.6
v3.1.5
v3.1.4
v3.1.3
v3.1.2
v3.1.1
v3.1.0
v3.0.9
v3.0.8
v3.0.7
v3.0.6
v3.0.5
v3.0.4
v3.0.3
v3.0.2
v3.0.1
v3.0.0
v2.9.3
Code Analysis
Analyzed Mar 16, 2026

Product Customer List for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
31
1 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

DataTables1.10.24Freemius1.0

SQL Query Safety

100% prepared4 total queries

Output Escaping

3% escaped32 total outputs
Attack Surface

Product Customer List for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_process_order_itemsadmin\wpcl-api.php:24

Shortcodes 1

[customer_list] views\legacy\shortcodes-2-6.php:53
WordPress Hooks 10
actionplugins_loadedfunctions.php:35
actionload-post.phpviews\legacy\table-customer-list-2-6.php:11
actionadd_meta_boxesviews\legacy\table-customer-list-2-6.php:13
actionbefore_woocommerce_initwc-product-customer-list.php:28
filterconnect_urlwc-product-customer-list.php:78
filterafter_skip_urlwc-product-customer-list.php:79
filterafter_connect_urlwc-product-customer-list.php:80
filterafter_pending_connect_urlwc-product-customer-list.php:81
actionadmin_noticeswc-product-customer-list.php:144
actionplugins_loadedwc-product-customer-list.php:148
Maintenance & Trust

Product Customer List for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 27, 2025
PHP min version
Downloads281K

Community Trust

Rating98/100
Number of ratings75
Active installs9K
Developer Profile

Product Customer List for WooCommerce Developer Profile

ggwicz

3 plugins · 9K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Product Customer List for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-product-customer-list/css/wpcl-style.css/wp-content/plugins/wc-product-customer-list/js/wpcl-script.js
Script Paths
/wp-content/plugins/wc-product-customer-list/js/wpcl-script.js
Version Parameters
wc-product-customer-list/css/wpcl-style.css?ver=wc-product-customer-list/js/wpcl-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpcl-customer-list-table
HTML Comments
<!-- Wpcl_Data_Compilation --><!-- Wpcl_Display --><!-- Wpcl_Admin --><!-- Wpcl_Settings -->+6 more
Data Attributes
data-wpcl-product-id
JS Globals
wpcl_ajax_object
REST Endpoints
/wp-json/wpcl/v1/products/
Shortcode Output
<table class="wpcl-customer-list-table">
FAQ

Frequently Asked Questions about Product Customer List for WooCommerce