States Manager for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-states-manager

Manage states/regions for multiple countries in WooCommerce checkout and shipping options.

10 active installs v1.0.1 PHP 7.2+ WP 5.0+ Updated Nov 18, 2024
checkoutregionsshippingstates-managerstates-manager-woocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is States Manager for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

States Manager for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "wc-states-manager" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface and no apparent entry points for external interaction. Furthermore, the code adheres to excellent security practices, with all SQL queries using prepared statements, 100% of output properly escaped, no dangerous functions, no file operations, and no external HTTP requests. The presence of nonce and capability checks further reinforces its secure design.

The taint analysis shows no flows with unsanitized paths, indicating no critical or high severity issues in that regard. The vulnerability history is also clean, with no known CVEs recorded. This lack of historical vulnerabilities and the robust static analysis results suggest a well-developed and securely coded plugin. The primary strength lies in its minimal attack surface and diligent adherence to secure coding principles. The only area for potential minor concern, although not explicitly flagged as a vulnerability in the provided data, would be the single nonce check and single capability check; a more comprehensive set might be expected for certain functionalities, though with zero attack surface, this is largely theoretical.

In conclusion, the "wc-states-manager" v1.0.1 plugin appears to be very secure. The static analysis reveals no immediate threats, and the absence of any historical vulnerabilities further bolsters this assessment. The plugin demonstrates a commitment to secure coding practices, making it a low-risk option for users. No deductions are warranted based on the provided data as all indicators point towards a secure implementation.

Vulnerabilities
None known

States Manager for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

States Manager for WooCommerce Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

States Manager for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
28 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped28 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
wcstates_setting_page (wc-states-manager.php:301)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

States Manager for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_noticeswc-states-manager.php:44
actionbefore_woocommerce_initwc-states-manager.php:51
actionadmin_menuwc-states-manager.php:88
actionadmin_enqueue_scriptswc-states-manager.php:89
actioninitwc-states-manager.php:94
filterwoocommerce_stateswc-states-manager.php:96
actionplugins_loadedwc-states-manager.php:110
filterwoocommerce_stateswc-states-manager.php:431
actioninitwc-states-manager.php:434
Maintenance & Trust

States Manager for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 18, 2024
PHP min version7.2
Downloads832

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

States Manager for WooCommerce Developer Profile

Muhammd Usman Ramzan

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect States Manager for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-states-manager/assets/js/admin.js/wp-content/plugins/wc-states-manager/assets/css/admin.css
Script Paths
/wp-content/plugins/wc-states-manager/assets/js/admin.js
Version Parameters
wc-states-manager/assets/js/admin.js?ver=wc-states-manager/assets/css/admin.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-nonce="wcstates-admin-nonce"data-ajaxUrl="admin-ajax.php"
JS Globals
wcstatesAdmin
FAQ

Frequently Asked Questions about States Manager for WooCommerce