Woo Product Remover Security & Risk Analysis

wordpress.org/plugins/woo-product-remover

Woo Product Remover allows you to remove all woocommerce products from your site. It cleans up your database from products and product variations

2K active installs v1.1.0 PHP + WP 4.3+ Updated Mar 20, 2017
delete-productsproduct-removerproductsremove-productswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Woo Product Remover Safe to Use in 2026?

Generally Safe

Score 85/100

Woo Product Remover has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "woo-product-remover" plugin v1.1.0 exhibits a generally good security posture regarding its attack surface and vulnerability history. Static analysis reveals no direct entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication. Furthermore, there are no known critical or high-severity vulnerabilities recorded for this plugin, and no unpatched CVEs exist. This suggests a level of diligence in maintaining the plugin's security over time.

However, the code analysis does highlight significant concerns, particularly with SQL queries and output escaping. All six SQL queries are executed without prepared statements, which is a critical vulnerability that can lead to SQL injection. Additionally, none of the two identified output operations are properly escaped, leaving the plugin susceptible to cross-site scripting (XSS) attacks. While taint analysis shows no identified flows, this could be due to the limited scope of the analysis or the nature of the code paths. The presence of nonce and capability checks is a positive sign, but it does not mitigate the risks posed by unescaped output and vulnerable SQL execution.

In conclusion, while the plugin benefits from a clean vulnerability history and a minimal attack surface, the identified SQL injection and XSS vulnerabilities are severe. The lack of prepared statements for all SQL queries and the complete absence of output escaping represent critical security flaws that require immediate attention. These issues overshadow the plugin's strengths in other areas and demand remediation to ensure user data and site integrity.

Key Concerns

  • Raw SQL queries without prepared statements
  • Unescaped output susceptible to XSS
Vulnerabilities
None known

Woo Product Remover Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Woo Product Remover Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared6 total queries

Output Escaping

0% escaped2 total outputs
Attack Surface

Woo Product Remover Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menuwoo-product-remover.php:12
Maintenance & Trust

Woo Product Remover Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMar 20, 2017
PHP min version
Downloads31K

Community Trust

Rating100/100
Number of ratings18
Active installs2K
Developer Profile

Woo Product Remover Developer Profile

mcfarhat

1 plugin · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Woo Product Remover

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
Data Attributes
id="delete_process"name="delete_process"id="chckbx_cats"name="chckbx_cats"
Shortcode Output
<h2>Woo Product Remover</h2><p>This is as simple as it gets! Just click the button below to remove all woocommerce products.</p><p>Please be cautious as this action is irreversible!</p><p><input type="checkbox" name="chckbx_cats" id="chckbx_cats" value="chckbx_cats">Also remove related categories, tags, and taxonomies</p>
FAQ

Frequently Asked Questions about Woo Product Remover