Premmerce WooCommerce Customers Manager Security & Risk Analysis

wordpress.org/plugins/woo-customers-manager

This plugin extends the standard user list and the edit user page in WordPress and adds the customer data from WooCommerce.

800 active installs v1.1.15 PHP 5.6+ WP 4.8+ Updated Feb 19, 2026
customerscustomers-managerwoocommerce-customers
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 6, 2026
Safety Verdict

Is Premmerce WooCommerce Customers Manager Safe to Use in 2026?

Generally Safe

Score 99/100

Premmerce WooCommerce Customers Manager has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 6, 2026Updated 1mo ago
Risk Assessment

The "woo-customers-manager" v1.1.15 plugin presents a mixed security profile. On the positive side, the static analysis indicates a minimal attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication or permission checks. Furthermore, the code uses prepared statements for all its SQL queries, which is a strong defense against SQL injection vulnerabilities. However, a significant concern is the relatively low percentage of properly escaped output (55%). This leaves a substantial portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks, especially if user-supplied data is not sufficiently sanitized before being displayed. The vulnerability history shows a single known CVE, which is no longer unpatched, and it was an XSS vulnerability. While the plugin has addressed past issues, the pattern of XSS vulnerabilities, combined with the current findings of unescaped output, suggests that improper output neutralization remains a recurring theme for this plugin.

Key Concerns

  • Significant amount of unescaped output
  • Bundled Freemius library may be outdated
  • Past XSS vulnerability history
Vulnerabilities
1

Premmerce WooCommerce Customers Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-13369medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Premmerce WooCommerce Customers Manager <= 1.1.14 - Reflected Cross-Site Scripting

Jan 6, 2026 Patched in 1.1.15 (50d)
Code Analysis
Analyzed Mar 16, 2026

Premmerce WooCommerce Customers Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

55% escaped38 total outputs
Attack Surface

Premmerce WooCommerce Customers Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filtermanage_users_columnssrc\Admin\Admin.php:30
filtermanage_users_custom_columnsrc\Admin\Admin.php:31
filterpre_get_userssrc\Admin\Admin.php:32
actionmanage_users_extra_tablenavsrc\Admin\Admin.php:34
actionadmin_initsrc\Admin\Admin.php:36
actionshow_user_profilesrc\Admin\Admin.php:43
actionedit_user_profilesrc\Admin\Admin.php:44
actioninitsrc\ExtendedUsersPlugin.php:37
actionadmin_initsrc\ExtendedUsersPlugin.php:38
Maintenance & Trust

Premmerce WooCommerce Customers Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version5.6
Downloads28K

Community Trust

Rating86/100
Number of ratings4
Active installs800
Developer Profile

Premmerce WooCommerce Customers Manager Developer Profile

Premmerce

14 plugins · 60K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
416 days
View full developer profile
Detection Fingerprints

How We Detect Premmerce WooCommerce Customers Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-customers-manager/admin/css/premmerce-extended-users.css
Version Parameters
woo-customers-manager/style.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-wcm-customer-id
FAQ

Frequently Asked Questions about Premmerce WooCommerce Customers Manager