WooReports — Advanced Reporting for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-reports-lite

Free sales reports for WooCommerce — 11 report modules including orders, products, stock, tax, coupons and payment gateways. No API key needed.

60 active installs v3.0.0 PHP 7.4+ WP 6.0+ Updated Apr 3, 2026
sales-reportstock-reportwoocommerce-analyticswoocommerce-reportingwoocommerce-reports
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 15, 2025
Safety Verdict

Is WooReports — Advanced Reporting for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

WooReports — Advanced Reporting for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 15, 2025Updated 1mo ago
Risk Assessment

The "wc-reports-lite" v1.0.0 plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by largely utilizing prepared statements for SQL queries and avoiding file operations or external HTTP requests. The limited attack surface with zero unprotected entry points is also a positive indicator. However, significant concerns arise from the low rate of proper output escaping (46%), indicating a potential for cross-site scripting (XSS) vulnerabilities if not all outputs are adequately sanitized. The presence of two unsanitized paths in the taint analysis, even without a critical or high severity classification, warrants attention as these could be entry points for malicious data. The vulnerability history reveals a past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, and critically, one unpatched CVE. This pattern suggests a history of security weaknesses that, while not always critical, require diligent maintenance and patching.

Key Concerns

  • Unpatched CVE present
  • Low percentage of properly escaped output
  • Taint flow with unsanitized path
  • Past CSRF vulnerability
Vulnerabilities
1 published

WooReports — Advanced Reporting for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62957medium · 4.3Cross-Site Request Forgery (CSRF)

NikanWP WooCommerce Reporting <= 1.0.0 - Cross-Site Request Forgery

Oct 15, 2025 Patched in 3.0.0 (183d)
Version History

WooReports — Advanced Reporting for WooCommerce Release Timeline

v3.0.0Current
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

WooReports — Advanced Reporting for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
24 prepared
Unescaped Output
106
89 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

96% prepared25 total queries

Output Escaping

46% escaped195 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wcrl_settingsFieldsGeneral (includes\admin-pages\wcrl-settings.php:20)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WooReports — Advanced Reporting for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadd_meta_boxesincludes\admin-pages\wcrl-overview.php:11
actionadmin_enqueue_scriptsincludes\class-wcrl-admin-assets.php:12
actionadmin_menuincludes\class-wcrl-admin-menus.php:18
filterset-screen-optionincludes\class-wcrl-admin-menus.php:19
actioninitincludes\class-wcrl.php:36
Maintenance & Trust

WooReports — Advanced Reporting for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 3, 2026
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

WooReports — Advanced Reporting for WooCommerce Developer Profile

NikanWP

4 plugins · 90 total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
183 days
View full developer profile
Detection Fingerprints

How We Detect WooReports — Advanced Reporting for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-reports-lite/assets/css/admin-style.css/wp-content/plugins/wc-reports-lite/assets/css/admin-style-rtl.css/wp-content/plugins/wc-reports-lite/assets/css/persianDatepicker-default.css/wp-content/plugins/wc-reports-lite/assets/js/admin.js/wp-content/plugins/wc-reports-lite/assets/js/persianDatepicker.js
Script Paths
wp-content/plugins/wc-reports-lite/assets/js/admin.jswp-content/plugins/wc-reports-lite/assets/js/persianDatepicker.js
Version Parameters
wc-reports-lite/assets/css/admin-style.css?ver=wc-reports-lite/assets/css/admin-style-rtl.css?ver=wc-reports-lite/assets/css/persianDatepicker-default.css?ver=wc-reports-lite/assets/js/admin.js?ver=wc-reports-lite/assets/js/persianDatepicker.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WooReports — Advanced Reporting for WooCommerce