Sales Count Manager for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-sales-count-manager

Display sold item count for each product in WooCommerce, customize the counter, and add social share buttons for better engagement.

400 active installs v2.6 PHP + WP 6.0+ Updated Jan 9, 2026
woocommerce-inventory-trackerwoocommerce-product-saleswoocommerce-sales-counterwoocommerce-sales-statisticswoocommerce-sold-items
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Sales Count Manager for WooCommerce Safe to Use in 2026?

Mostly Safe

Score 78/100

Sales Count Manager for WooCommerce is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 4mo ago
Risk Assessment

The static analysis for 'wc-sales-count-manager' v2.6 shows a generally good security posture in terms of attack surface and SQL handling. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with protection checks indicates a limited external entry point into the plugin's core functionalities. Furthermore, all identified SQL queries utilize prepared statements, which is a strong defense against SQL injection vulnerabilities. However, a significant concern arises from the output escaping results, where 100% of the single identified output is not properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is displayed without sanitization.

The vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, which, while dated and potentially patched in this version, raises a flag. The fact that a CVE exists for this plugin, even if marked as patched in the history for this specific version, warrants caution. The consistent presence of XSS as a vulnerability type suggests a recurring weakness in how user input is handled when rendered in the frontend or admin panels. While the current version shows no critical or high severity taint flows and a minimal attack surface, the unescaped output combined with the historical XSS vulnerability indicates a moderate to high risk of XSS if an attacker can inject malicious scripts through input fields that are subsequently displayed without proper escaping. The presence of only one capability check is also a minor concern, implying that some administrative functions might not be sufficiently protected.

In conclusion, 'wc-sales-count-manager' v2.6 demonstrates strengths in its limited attack surface and secure SQL practices. However, the critical lack of output escaping for all identified outputs and the historical pattern of XSS vulnerabilities represent significant weaknesses. These issues, coupled with a minimal capability check, elevate the overall risk profile. Users should be aware of the potential for XSS, and developers should prioritize implementing robust output escaping mechanisms across all dynamic content.

Key Concerns

  • Unescaped output found
  • Unpatched CVE history (medium severity XSS)
  • Only one capability check
Vulnerabilities
1 published

Sales Count Manager for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-57904medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Sales Count Manager for WooCommerce <= 2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
Version History

Sales Count Manager for WooCommerce Release Timeline

v2.6Current1 CVE
v2.51 CVE
v2.41 CVE
v2.31 CVE
v2.21 CVE
v2.01 CVE
v1.91 CVE
v1.81 CVE
v1.71 CVE
v1.61 CVE
v1.51 CVE
v1.41 CVE
v1.31 CVE
v1.21 CVE
v1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Sales Count Manager for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Sales Count Manager for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_initwc-sales-count-manager.php:33
actionadmin_menuwc-sales-count-manager.php:34
actionadmin_footerwc-sales-count-manager.php:37
actionadmin_bar_menuwc-sales-count-manager.php:44
actionadmin_enqueue_scriptswc-sales-count-manager.php:46
filterwoocommerce_after_single_productwc-scm-class.php:23
filterwoocommerce_after_single_product_summarywc-scm-class.php:29
actionwp_footerwc-scm-class.php:31
actionwoocommerce_single_product_summarywc-scm-class.php:35
actionwoocommerce_after_shop_loop_item_titlewc-scm-class.php:39
actionwoocommerce_order_status_cancelledwc-scm-class.php:42
Maintenance & Trust

Sales Count Manager for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 9, 2026
PHP min version
Downloads19K

Community Trust

Rating100/100
Number of ratings8
Active installs400
Developer Profile

Sales Count Manager for WooCommerce Developer Profile

WP-EXPERTS.IN

21 plugins · 30K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
347 days
View full developer profile
Detection Fingerprints

How We Detect Sales Count Manager for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-sales-count-manager/css/admin-style.css/wp-content/plugins/wc-sales-count-manager/css/colorpicker.css/wp-content/plugins/wc-sales-count-manager/js/admin-script.js

HTML / DOM Fingerprints

CSS Classes
wcscm-toolbar-pagewcscm_menu_item_classwcscm-tab-linkswcscm-settingwcscm-tabcolor-field
Data Attributes
data-default-color
JS Globals
jQuery
FAQ

Frequently Asked Questions about Sales Count Manager for WooCommerce