WC Products by Brands Security & Risk Analysis

wordpress.org/plugins/wc-products-by-brands

If you have one of the brand plugins running, think of this as a way to show products on the page that are tied to that brand.

10 active installs v1.2 PHP + WP 3.5+ Updated Unknown
brandsstoretagswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WC Products by Brands Safe to Use in 2026?

Generally Safe

Score 100/100

WC Products by Brands has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "wc-products-by-brands" v1.2 plugin exhibits a mixed security posture. On the positive side, the static analysis indicates a lack of dangerous functions, no raw SQL queries, no file operations, no external HTTP requests, and no bundled libraries. The absence of known CVEs in its history further suggests a generally stable security record. However, there are significant concerns regarding output escaping, as 100% of observed outputs are not properly escaped. This represents a clear risk of cross-site scripting (XSS) vulnerabilities, especially given the presence of a shortcode, which can be an entry point for user-supplied data that may be rendered insecurely. The lack of nonce and capability checks on any entry points (though the attack surface is small) also means that even if there were privileged actions, they might be vulnerable to CSRF or unauthorized execution.

Key Concerns

  • Unescaped output on all observed outputs
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

WC Products by Brands Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WC Products by Brands Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

WC Products by Brands Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wc_by_brands] wc-brand-list.php:62
Maintenance & Trust

WC Products by Brands Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

WC Products by Brands Developer Profile

nwmcinc

4 plugins · 130 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WC Products by Brands

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-products-by-brands/assets/css/wc-brands.css/wp-content/plugins/wc-products-by-brands/assets/js/wc-brands.js
Script Paths
/wp-content/plugins/wc-products-by-brands/assets/js/wc-brands.js
Version Parameters
wc-products-by-brands/assets/css/wc-brands.css?ver=wc-products-by-brands/assets/js/wc-brands.js?ver=

HTML / DOM Fingerprints

CSS Classes
woocommercecolumns-4productsproduct
Data Attributes
data-quantitydata-product_skudata-product-id
Shortcode Output
<div class="woocommerce columns-4"><ul class="products"><li class="product"><a href="
FAQ

Frequently Asked Questions about WC Products by Brands