
Sales Count Manager for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-sales-count-managerDisplay sold item count for each product in WooCommerce, customize the counter, and add social share buttons for better engagement.
Is Sales Count Manager for WooCommerce Safe to Use in 2026?
Mostly Safe
Score 78/100Sales Count Manager for WooCommerce is generally safe to use. 1 past CVE were resolved.
The static analysis for 'wc-sales-count-manager' v2.6 shows a generally good security posture in terms of attack surface and SQL handling. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with protection checks indicates a limited external entry point into the plugin's core functionalities. Furthermore, all identified SQL queries utilize prepared statements, which is a strong defense against SQL injection vulnerabilities. However, a significant concern arises from the output escaping results, where 100% of the single identified output is not properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is displayed without sanitization.
The vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, which, while dated and potentially patched in this version, raises a flag. The fact that a CVE exists for this plugin, even if marked as patched in the history for this specific version, warrants caution. The consistent presence of XSS as a vulnerability type suggests a recurring weakness in how user input is handled when rendered in the frontend or admin panels. While the current version shows no critical or high severity taint flows and a minimal attack surface, the unescaped output combined with the historical XSS vulnerability indicates a moderate to high risk of XSS if an attacker can inject malicious scripts through input fields that are subsequently displayed without proper escaping. The presence of only one capability check is also a minor concern, implying that some administrative functions might not be sufficiently protected.
In conclusion, 'wc-sales-count-manager' v2.6 demonstrates strengths in its limited attack surface and secure SQL practices. However, the critical lack of output escaping for all identified outputs and the historical pattern of XSS vulnerabilities represent significant weaknesses. These issues, coupled with a minimal capability check, elevate the overall risk profile. Users should be aware of the potential for XSS, and developers should prioritize implementing robust output escaping mechanisms across all dynamic content.
Key Concerns
- Unescaped output found
- Unpatched CVE history (medium severity XSS)
- Only one capability check
Sales Count Manager for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sales Count Manager for WooCommerce <= 2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Sales Count Manager for WooCommerce Release Timeline
Sales Count Manager for WooCommerce Code Analysis
Output Escaping
Sales Count Manager for WooCommerce Attack Surface
WordPress Hooks 11
Maintenance & Trust
Sales Count Manager for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Sales Count Manager for WooCommerce Alternatives
Sales Count Manager for WooCommerce Developer Profile
21 plugins · 30K total installs
How We Detect Sales Count Manager for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-sales-count-manager/css/admin-style.css/wp-content/plugins/wc-sales-count-manager/css/colorpicker.css/wp-content/plugins/wc-sales-count-manager/js/admin-script.jsHTML / DOM Fingerprints
wcscm-toolbar-pagewcscm_menu_item_classwcscm-tab-linkswcscm-settingwcscm-tabcolor-fielddata-default-colorjQuery