
Customer Bought Items Security & Risk Analysis
wordpress.org/plugins/woo-bought-productsUse the [boughtproduct] shortcode to display a list of products purchased by the current logged-in user.
Is Customer Bought Items Safe to Use in 2026?
Generally Safe
Score 100/100Customer Bought Items has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-bought-products" v1.3 plugin exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and demonstrates good practices by avoiding dangerous functions, performing file operations, making external HTTP requests, and exclusively using prepared statements for SQL queries. The attack surface is also relatively small with only one shortcode and no AJAX handlers or REST API routes, further reducing potential entry points.
However, there are significant concerns. The plugin lacks any nonces or capability checks, leaving its single shortcode vulnerable to unauthorized execution if an attacker can trigger it. Furthermore, the taint analysis revealed two flows with unsanitized paths, indicating potential for path traversal or similar vulnerabilities, even though they were not classified as critical or high severity in this analysis. The output escaping is also a major weakness, with a substantial 83% of outputs not being properly escaped, leading to a high risk of Cross-Site Scripting (XSS) vulnerabilities.
In conclusion, while the plugin benefits from a clean vulnerability history and the absence of known critical code injection risks like raw SQL queries, the lack of authorization checks and particularly the widespread unescaped output present substantial security risks. The unsanitized paths from the taint analysis, though not explicitly detailed as exploitable, add another layer of concern. Mitigation for XSS and authorization bypass should be a priority.
Key Concerns
- Unescaped output (high percentage)
- Taint flow with unsanitized path (x2)
- No nonce checks on entry points
- No capability checks on entry points
Customer Bought Items Security Vulnerabilities
Customer Bought Items Release Timeline
Customer Bought Items Code Analysis
Output Escaping
Data Flow Analysis
Customer Bought Items Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Customer Bought Items Maintenance & Trust
Maintenance Signals
Community Trust
Customer Bought Items Alternatives
WCFM – Frontend Manager for WooCommerce
wc-frontend-manager
Professional frontend dashboard for WooCommerce and multivendor marketplaces. Supports WCFM Marketplace, Dokan, WC Vendors, WC Product Vendors.
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
Product Customer List for WooCommerce
wc-product-customer-list
Display a list of customers who bought a specific product at the bottom of the product edit page in WooCommerce and send them e-mails.
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Product Visibility by User Role for WooCommerce
product-visibility-by-user-role-for-woocommerce
Display WooCommerce products by customer's user role.
Customer Bought Items Developer Profile
9 plugins · 3K total installs
How We Detect Customer Bought Items
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-bought-products/assets/css/rbrurls.cssHTML / DOM Fingerprints
brplbrpl_paginationname="yboprol_options_name[pagination]"name="yboprol_options_name[owncss]"name="yboprol_options_name[image]"name="yboprol_options_name[productlist]"<div class="brpl" ><ul class="brpl_pagination" >