
Customers by Product Purchase Security & Risk Analysis
wordpress.org/plugins/woo-customers-by-product-purchaseFind out which customers has bought your "X" product.
Is Customers by Product Purchase Safe to Use in 2026?
Generally Safe
Score 85/100Customers by Product Purchase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-customers-by-product-purchase" plugin v0.1 exhibits a mixed security posture. While the static analysis reveals no apparent direct entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected, and all SQL queries are prepared, there are significant concerns. The extremely low percentage of properly escaped output (15%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis identified one flow with an unsanitized path classified as high severity, indicating a potential pathway for malicious data to be processed without adequate cleaning. The absence of nonce and capability checks across the board is a critical oversight, as it leaves any potential entry points, even if currently zero, vulnerable to unauthorized actions. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign, suggesting it has historically been free of known exploits. However, this history is limited, especially for an early version like 0.1, and does not negate the risks identified in the current code analysis.
Key Concerns
- High percentage of unescaped output
- High severity taint flow with unsanitized path
- Zero nonce checks present
- Zero capability checks present
Customers by Product Purchase Security Vulnerabilities
Customers by Product Purchase Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Customers by Product Purchase Attack Surface
WordPress Hooks 2
Maintenance & Trust
Customers by Product Purchase Maintenance & Trust
Maintenance Signals
Community Trust
Customers by Product Purchase Alternatives
Simplified Content
simplified-content
A plugin which generates alternative 'simplified' content for a given set of browsers. Useful legacy browser support and intranet systems.
reBusted!
rebusted
Force browsers to load the most recent file if modified.
SQL Buddy – Database Management Made Easy
sql-buddy
Your one-stop solution for easy WordPress database management
WP Mobile Detect
wp-mobile-detect
WP Mobile Detect by Jesse Friedman creates an easy way for the User Admin to control when content is shown or hid based on visitor device or operating …
Mobile Detect
tinywp-mobile-detect
Fine-tunes wp_is_mobile function by excluding tablets (ex: iPad), from being detected as mobile! Uses MobileDetect PHP Library from mobiledetect.net!
Customers by Product Purchase Developer Profile
9 plugins · 370 total installs
How We Detect Customers by Product Purchase
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-customers-by-product-purchase/assets/css/style.css/wp-content/plugins/woo-customers-by-product-purchase/assets/js/custom.js/wp-content/plugins/woo-customers-by-product-purchase/assets/js/custom.jswoo-customers-by-product-purchase/assets/css/style.css?ver=woo-customers-by-product-purchase/assets/js/custom.js?ver=