
Advanced Product Information for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-advanced-product-informationMakes your product page informative with additional info, such as: Review, Stock, Sales, Countdown, Coupon, Social Proof, Rank and more.
Is Advanced Product Information for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Advanced Product Information for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "woo-advanced-product-information" v1.1.7 exhibits a generally good security posture. The static analysis reveals a small attack surface with all identified entry points having appropriate authentication and permission checks. The code also demonstrates strong practices in SQL query execution, exclusively using prepared statements, and a high percentage of properly escaped output, significantly reducing the risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of dangerous functions and file operations further bolsters its security. However, the presence of two external HTTP requests warrants careful monitoring, as these could potentially be leveraged in supply chain attacks or if the external endpoints are compromised. The plugin's vulnerability history shows one medium-severity CVE, which is currently unpatched. While it's good that there are no critical or high-severity vulnerabilities and the medium one is not actively unpatched, the existence of a past vulnerability, particularly an XSS type, suggests that vigilance is still required. The fact that the last vulnerability was in 2025 implies the data might be future-dated or a placeholder, but if accurate, it highlights the need for timely patching of any discovered vulnerabilities.
In conclusion, the plugin has strong foundational security practices, particularly in input validation and output encoding. The limited attack surface and reliance on prepared statements are commendable. The main areas for attention are the external HTTP requests, which represent an indirect attack vector, and the historical medium-severity vulnerability. Although no unpatched vulnerabilities are currently listed, the past incident means users should be prepared to update promptly if new vulnerabilities are discovered. Overall, it's a relatively secure plugin, but not without areas that require ongoing diligence from both the developer and the users.
Key Concerns
- Medium severity CVE present
- External HTTP requests found
Advanced Product Information for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Advanced Product Information for WooCommerce <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced Product Information for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced Product Information for WooCommerce Attack Surface
AJAX Handlers 3
Shortcodes 2
WordPress Hooks 69
Maintenance & Trust
Advanced Product Information for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Product Information for WooCommerce Alternatives
Weight Based Shipping for WooCommerce
weight-based-shipping-for-woocommerce
Weight Based Shipping is a flexible and widely-used solution to calculate shipping costs based on the total cart weight and value.
Advanced Free Shipping for WooCommerce
woocommerce-advanced-free-shipping
Advanced Free Shipping for WooCommerce is an plugin which allows you to set up advanced free shipping conditions.
Modern Cart – WooCommerce Side Cart & Popup Cart
modern-cart
Modern Cart gives your store a side cart and free shipping bar so shoppers stay on the page, spend more to unlock rewards, and check out in seconds.
HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce
hurrytimer
Create unlimited urgency and scarcity countdown timers for WordPress and WooCommerce to boost conversions and sales instantly.
WC Hide Shipping Methods
wc-hide-shipping-methods
This plugin automatically hides all other shipping methods when "Free Shipping" is available, while allowing you to retain "Local Picku …
Advanced Product Information for WooCommerce Developer Profile
58 plugins · 167K total installs
How We Detect Advanced Product Information for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-advanced-product-information/assets/css/woo-advanced-product-information.css/wp-content/plugins/woo-advanced-product-information/assets/js/woo-advanced-product-information.js/wp-content/plugins/woo-advanced-product-information/assets/css/woo-advanced-product-information-responsive.css/wp-content/plugins/woo-advanced-product-information/assets/css/woo-advanced-product-information-backend.css/wp-content/plugins/woo-advanced-product-information/assets/js/woo-advanced-product-information-backend.js/wp-content/plugins/woo-advanced-product-information/assets/js/woo-advanced-product-information.jswoo-advanced-product-information/assets/css/woo-advanced-product-information.css?ver=woo-advanced-product-information/assets/js/woo-advanced-product-information.js?ver=woo-advanced-product-information/assets/css/woo-advanced-product-information-responsive.css?ver=woo-advanced-product-information/assets/css/woo-advanced-product-information-backend.css?ver=woo-advanced-product-information/assets/js/woo-advanced-product-information-backend.js?ver=HTML / DOM Fingerprints
wapi_product_reviewwapi_product_instockwapi_product_shippingwapi_product_salewapi_product_countdownwapi_product_recentwapi_product_rankwapi_product_payment+3 moredata-wapi-settingswapi_params[wapi_icon id=[wapinfo_badges id=