List Products By Category Widget for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-products-by-category

Display a list of all the products in a WooCommerce product category with this handy widget.

1K active installs v1.3.0 PHP 5.6+ WP 4.9+ Updated Nov 8, 2020
categoriesfilterproductswidgetwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is List Products By Category Widget for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

List Products By Category Widget for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "woo-products-by-category" plugin v1.3.0 exhibits a generally positive security posture based on the static analysis. The absence of known vulnerabilities and CVEs in its history is a significant strength. Furthermore, the code analysis reveals no critical security signals such as dangerous functions, raw SQL queries, file operations, or external HTTP requests. The taint analysis also shows no identified flows, indicating no immediate concerns with data sanitization for untrusted input being used in sensitive operations.

However, there are areas that warrant attention. The most prominent concern is the very low percentage of properly escaped output (9%). This suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, as untrusted data displayed on the frontend may not be properly sanitized, allowing attackers to inject malicious scripts. While the attack surface appears to be zero in terms of AJAX handlers, REST API routes, shortcodes, and cron events, this could also indicate a very limited functionality, or that the analysis might not have fully captured all potential entry points. The lack of nonce checks and capability checks, even with a seemingly zero attack surface, is a potential weakness if any input handling were to be introduced or overlooked in the analysis.

In conclusion, the plugin benefits from a clean vulnerability history and a lack of exploitable code patterns in several key areas. The primary weakness lies in the inadequate output escaping, presenting a significant risk of XSS. While the current attack surface seems minimal, the absence of security checks for potential entry points could become a liability if the plugin evolves or if the analysis has missed any.

Key Concerns

  • Low percentage of properly escaped output
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

List Products By Category Widget for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

List Products By Category Widget for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
49
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

9% escaped54 total outputs
Attack Surface

List Products By Category Widget for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptswcpbc.php:36
actionwidgets_initwidget\wcpbc-widget.php:401
Maintenance & Trust

List Products By Category Widget for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 8, 2020
PHP min version5.6
Downloads18K

Community Trust

Rating100/100
Number of ratings5
Active installs1K
Developer Profile

List Products By Category Widget for WooCommerce Developer Profile

Blaze Concepts

6 plugins · 2K total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect List Products By Category Widget for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-products-by-category/public/wcpbc-styles.css
Version Parameters
woo-products-by-category/public/wcpbc-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
wcpbc-widget-list
FAQ

Frequently Asked Questions about List Products By Category Widget for WooCommerce