
Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Security & Risk Analysis
wordpress.org/plugins/webd-woocommerce-advanced-reporting-statisticsA comprehensive WordPress Plugin for Advanced WooCommerce Reporting, Product Sales Report, Statistics, Analytics & Forecasting Tool for Orders, Pr …
Is Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Safe to Use in 2026?
Generally Safe
Score 93/100Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "webd-woocommerce-advanced-reporting-statistics" plugin, version 4.1.5, exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and avoiding file operations, several significant concerns are present. The static analysis reveals a substantial attack surface with 10 AJAX handlers, one of which lacks authentication checks, creating a direct entry point for potential unauthorized access. Furthermore, only 65% of output is properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of any nonce checks on AJAX handlers is particularly worrying, as this is a fundamental WordPress security mechanism for preventing CSRF attacks.
The plugin's vulnerability history is a significant red flag, with two known CVEs, including a high-severity SQL Injection vulnerability and another related to information exposure. The fact that these vulnerabilities have existed in the past, even if currently patched, suggests a recurring pattern of security weaknesses in the codebase. The last vulnerability being in 2026, implies that the provided historical data might be predictive or the last reported vulnerability was in the past and the system is projecting future vulnerability discovery for that date.
In conclusion, despite some positive security implementations like secure SQL practices, the identified lack of authentication on an AJAX handler, incomplete output escaping, missing nonce checks, and a history of high-severity vulnerabilities collectively contribute to a moderate to high-risk assessment. The plugin's attack surface needs to be hardened, and a thorough review of its output sanitization is crucial to mitigate existing and potential future risks.
Key Concerns
- AJAX handler without authentication check
- Only 65% of output properly escaped
- No nonce checks on AJAX handlers
- One high severity historical vulnerability
- One medium severity historical vulnerability
Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting <= 4.1.3 - Unauthenticated SQL Injection
Advanced WooCommerce Product Sales Reporting <= 4.1.2 - Unauthenticated Information Exposure
Advanced WooCommerce Product Sales Reporting <= 4.1.1 - Unauthenticated SQL Injection
Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Release Timeline
Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Attack Surface
AJAX Handlers 10
WordPress Hooks 10
Maintenance & Trust
Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Alternatives
Ninjalytics: Sales Reports & Order Export for WooCommerce and EDD
product-sales-report-for-woocommerce
Create sales reports and order exports for WooCommerce with product analytics, order fulfillment data, filtering, charts, and 15+ templates.
Sales Report for WooCommerce
sales-report-for-woocommerce
Sales Report for WooCommerce generates daily, weekly and monthly sales report
REPORTiT – Advanced Reporting for WooCommerce
ithemelandco-woo-report
Stop guessing. Grow your sales with powerful, easy-to-understand reports and analytics for WooCommerce.
WooReports — Advanced Reporting for WooCommerce
wc-reports-lite
Free sales reports for WooCommerce — 11 report modules including orders, products, stock, tax, coupons and payment gateways. No API key needed.
Metrilo – WooCommerce Growth Platform
metrilo-woocommerce-integration
Ecommerce Analytics and behaviour-driven customer engagement tools for ecommerce brands.
Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Developer Profile
64 plugins · 137K total installs
How We Detect Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/css/backend.css/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/css/jquery-ui.css/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/js/chart.js/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/js/backend.js/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/css/font-awesome.min.css/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/js/chart.js/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/js/backend.jswebd-woocommerce-reporting-statistics/css/backend.css?v=bvcwebd-woocommerce-reporting-statistics/js/backend.js?v=bvcHTML / DOM Fingerprints
webdWoocommerceReportingStatistics<!-- google_translate_element -->webdWoocommerceReportingStatisticswebdWoocommerceReportingStatistics[adStats]