Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Security & Risk Analysis

wordpress.org/plugins/webd-woocommerce-advanced-reporting-statistics

A comprehensive WordPress Plugin for Advanced WooCommerce Reporting, Product Sales Report, Statistics, Analytics & Forecasting Tool for Orders, Pr …

400 active installs v4.1.5 PHP 5.2.4+ WP 3.0.1+ Updated Feb 9, 2026
analyticsreportingsales-reportwoocommerce-saleswoocommerce-statistics
93
A · Safe
CVEs total3
Unpatched0
Last CVEMar 18, 2026
Safety Verdict

Is Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Safe to Use in 2026?

Generally Safe

Score 93/100

Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Mar 18, 2026Updated 3mo ago
Risk Assessment

The "webd-woocommerce-advanced-reporting-statistics" plugin, version 4.1.5, exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and avoiding file operations, several significant concerns are present. The static analysis reveals a substantial attack surface with 10 AJAX handlers, one of which lacks authentication checks, creating a direct entry point for potential unauthorized access. Furthermore, only 65% of output is properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of any nonce checks on AJAX handlers is particularly worrying, as this is a fundamental WordPress security mechanism for preventing CSRF attacks.

The plugin's vulnerability history is a significant red flag, with two known CVEs, including a high-severity SQL Injection vulnerability and another related to information exposure. The fact that these vulnerabilities have existed in the past, even if currently patched, suggests a recurring pattern of security weaknesses in the codebase. The last vulnerability being in 2026, implies that the provided historical data might be predictive or the last reported vulnerability was in the past and the system is projecting future vulnerability discovery for that date.

In conclusion, despite some positive security implementations like secure SQL practices, the identified lack of authentication on an AJAX handler, incomplete output escaping, missing nonce checks, and a history of high-severity vulnerabilities collectively contribute to a moderate to high-risk assessment. The plugin's attack surface needs to be hardened, and a thorough review of its output sanitization is crucial to mitigate existing and potential future risks.

Key Concerns

  • AJAX handler without authentication check
  • Only 65% of output properly escaped
  • No nonce checks on AJAX handlers
  • One high severity historical vulnerability
  • One medium severity historical vulnerability
Vulnerabilities
3 published

Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
2 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

High
2
Medium
1

3 total CVEs

CVE-2026-24993high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting <= 4.1.3 - Unauthenticated SQL Injection

Mar 18, 2026 Patched in 4.1.4 (9d)
CVE-2026-24992medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Advanced WooCommerce Product Sales Reporting <= 4.1.2 - Unauthenticated Information Exposure

Jan 23, 2026 Patched in 4.1.3 (11d)
CVE-2025-31553high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advanced WooCommerce Product Sales Reporting <= 4.1.1 - Unauthenticated SQL Injection

Mar 31, 2025 Patched in 4.1.2 (283d)
Code Analysis
Analyzed Mar 16, 2026

Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
17 prepared
Unescaped Output
47
86 escaped
Nonce Checks
0
Capability Checks
10
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared17 total queries

Output Escaping

65% escaped133 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
display_orders_by_period (helper-class.php:167)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Attack Surface

Entry Points10
Unprotected1

AJAX Handlers 10

authwp_ajax_getOrdershelper-class.php:108
authwp_ajax_get_ordershelper-class.php:109
authwp_ajax_get_customershelper-class.php:110
authwp_ajax_get_countrieshelper-class.php:111
authwp_ajax_get_paymentshelper-class.php:112
authwp_ajax_get_couponshelper-class.php:113
authwp_ajax_get_productshelper-class.php:114
authwp_ajax_get_categorieshelper-class.php:115
authwp_ajax_display_orders_by_periodhelper-class.php:116
authwp_ajax_stat_extensionswebd-woocommerce-reporting-statistics.php:88
WordPress Hooks 10
actioninitincludes\class-wpfactory-wc-ars.php:65
actionbefore_woocommerce_initincludes\class-wpfactory-wc-ars.php:68
actioninitincludes\class-wpfactory-wc-ars.php:129
filteradmin_menuincludes\class-wpfactory-wc-ars.php:132
actionplugins_loadedwebd-woocommerce-reporting-statistics.php:40
actionadmin_enqueue_scriptswebd-woocommerce-reporting-statistics.php:73
actionwpfactory_wc_ars_output_settingswebd-woocommerce-reporting-statistics.php:75
actionadmin_initwebd-woocommerce-reporting-statistics.php:79
actionadmin_footerwebd-woocommerce-reporting-statistics.php:85
filtercodecabin_deactivate_feedback_form_pluginswebd-woocommerce-reporting-statistics.php:92
Maintenance & Trust

Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version5.2.4
Downloads16K

Community Trust

Rating52/100
Number of ratings8
Active installs400
Developer Profile

Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting Developer Profile

WPFactory

64 plugins · 137K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
94 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/css/backend.css/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/css/jquery-ui.css/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/js/chart.js/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/js/backend.js/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/css/font-awesome.min.css
Script Paths
/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/js/chart.js/wp-content/plugins/webd-woocommerce-advanced-reporting-statistics/js/backend.js
Version Parameters
webd-woocommerce-reporting-statistics/css/backend.css?v=bvcwebd-woocommerce-reporting-statistics/js/backend.js?v=bvc

HTML / DOM Fingerprints

CSS Classes
webdWoocommerceReportingStatistics
HTML Comments
<!-- google_translate_element -->
Data Attributes
webdWoocommerceReportingStatistics
JS Globals
webdWoocommerceReportingStatistics
Shortcode Output
[adStats]
FAQ

Frequently Asked Questions about Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting