
WC Subscription Report Lite Security & Risk Analysis
wordpress.org/plugins/wc-subscription-report-liteLIVE DEMO | PRO VERSION LINK
Is WC Subscription Report Lite Safe to Use in 2026?
Generally Safe
Score 85/100WC Subscription Report Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-subscription-report-lite" v1.9 plugin exhibits a mixed security posture. On one hand, the plugin demonstrates good practices by exclusively using prepared statements for all SQL queries and has no recorded vulnerability history, suggesting a generally well-maintained codebase. The attack surface is also minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks.
However, significant concerns arise from the static code analysis. The presence of `create_function` is a critical security risk, as it can lead to arbitrary code execution if user-supplied input is used within it without proper sanitization. Furthermore, the output escaping is severely lacking, with only 1% of outputs properly escaped. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface.
While the plugin has no known CVEs, the internal code quality issues, particularly the use of `create_function` and widespread unescaped output, present a substantial inherent risk. The absence of a vulnerability history might be due to the plugin not being widely targeted or extensively audited, rather than a true absence of vulnerabilities. Users should be aware of these internal weaknesses despite the clean CVE record.
Key Concerns
- Dangerous function create_function used
- Very low percentage of properly escaped output
- No nonce checks found
WC Subscription Report Lite Security Vulnerabilities
WC Subscription Report Lite Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
WC Subscription Report Lite Attack Surface
WordPress Hooks 11
Maintenance & Trust
WC Subscription Report Lite Maintenance & Trust
Maintenance Signals
Community Trust
WC Subscription Report Lite Alternatives
Metorik – Reports & Email Automation for WooCommerce
metorik-helper
The Metorik Helper helps provide your WooCommerce store with powerful analytics, reports, and tools.
Sales Report for WooCommerce
sales-report-for-woocommerce
Sales Report for WooCommerce generates daily, weekly and monthly sales report
REPORTiT – Advanced Reporting for WooCommerce
ithemelandco-woo-report
Stop guessing. Grow your sales with powerful, easy-to-understand reports and analytics for WooCommerce.
Ni WooCommerce Sales Report
ni-woocommerce-sales-report
Ni WooCommerce Sales Report Plugin - Generate Comprehensive Sales Reports for Your WooCommerce Store.
Order Reports for WooCommerce
wc-order-reports
Product sales reports for woocommerce store, order overview, order status wise performance, sales report download and show options with product item d …
WC Subscription Report Lite Developer Profile
6 plugins · 60 total installs
How We Detect WC Subscription Report Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-subscription-report-lite/assets/css/ic_commerce_lite_subscriptions.css/wp-content/plugins/wc-subscription-report-lite/assets/js/ic_commerce_lite_subscriptions.js/wp-content/plugins/wc-subscription-report-lite/assets/js/ic_commerce_lite_subscriptions.jswc-subscription-report-lite/assets/css/ic_commerce_lite_subscriptions.css?ver=wc-subscription-report-lite/assets/js/ic_commerce_lite_subscriptions.js?ver=HTML / DOM Fingerprints
ic_commerce_lite_subscriptions_reportdata-plugin-namedata-plugin-versiondata-plugin-slugic_commerce_lite_subscriptions_report_data