
Better Customer List for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-better-customer-listThis plugin will no longer be maintained. This functionality can now be achieved by using the built-in WooCommerce Analytics.
Is Better Customer List for WooCommerce Safe to Use in 2026?
Mostly Safe
Score 71/100Better Customer List for WooCommerce is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "woo-better-customer-list" plugin version 1.2.3 exhibits a mixed security posture. While it avoids dangerous functions and external HTTP requests, and has a decent percentage of properly escaped output, significant concerns arise from its attack surface and vulnerability history. The plugin exposes two AJAX handlers without any authentication or capability checks, creating a direct entry point for unauthenticated attackers. Furthermore, a taint analysis revealed one flow with an unsanitized path, which could potentially lead to vulnerabilities if exploited, though it's not classified as critical or high severity. The plugin's history of known vulnerabilities, including an unpatched medium severity Cross-Site Scripting (XSS) issue from 2025, is a major red flag. The recurring nature of such vulnerabilities suggests a lack of robust secure coding practices within the development process, particularly in input validation and output sanitization.
Key Concerns
- Unprotected AJAX handlers
- Flow with unsanitized path
- Unpatched CVE (Medium severity XSS)
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
- SQL query not using prepared statements
- Improperly escaped output
Better Customer List for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Better Customer List for WooCommerce <= 1.2.3 - Reflected Cross-Site Scripting
Better Customer List for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Better Customer List for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
Better Customer List for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Better Customer List for WooCommerce Alternatives
WP Mechanic
wp-mechanic
WP Mechanic is a combination of WordPress and Android Playstore Applications. Experience a set of hybrid software applications.
Product Customer List for WooCommerce
wc-product-customer-list
Display a list of customers who bought a specific product at the bottom of the product edit page in WooCommerce and send them e-mails.
Fraud Prevention For WooCommerce and EDD
woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers
It will Prevent fake orders and Blacklist fraud customers of your store.
Blacklist Manager – WooCommerce Anti-Fraud & Checkout Verification & Spam Prevention
wc-blacklist-manager
Anti-fraud, checkout verification and spam prevention plugin for WooCommerce and WordPress forms.
PiWeb Export Customers Users & Guest customer to CSV for WooCommerce
export-woocommerce-customer-list
Export WooCommerce customer list CSV, export WooCommerce guest customer list CSV, export WordPress users CSV, Product Customer List for WooCommerce
Better Customer List for WooCommerce Developer Profile
6 plugins · 2K total installs
How We Detect Better Customer List for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-better-customer-list/js/ajax-load.jsHTML / DOM Fingerprints
wc-settings-tab-blz-bclWC_Settings_Tab_BLZ_BCL_general_sectionWC_Settings_Tab_BLZ_BCL_cus_statusWC_Settings_Tab_BLZ_BCL_general_endblz_bcl_ajax_object