Woo Products Tree Security & Risk Analysis

wordpress.org/plugins/woo-products-tree

Plugin instals a widget of product navigation tree .

20 active installs v1.0 PHP + WP 4.0+ Updated Unknown
navigationproductstreewidgetwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Woo Products Tree Safe to Use in 2026?

Generally Safe

Score 100/100

Woo Products Tree has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "woo-products-tree" v1.0 plugin presents a generally good security posture from a static analysis perspective, with no identified dangerous functions, file operations, external requests, or obvious SQL injection vulnerabilities due to the exclusive use of prepared statements. The attack surface also appears minimal, with no registered AJAX handlers, REST API routes, shortcodes, or cron events. However, a significant concern arises from the extremely low rate of proper output escaping (4%), indicating that a large percentage of user-facing output is not being sanitized, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully within the plugin's rendering logic. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a history of responsible development or a lack of public scrutiny. Despite the positive indicators, the critical weakness in output escaping, coupled with the complete lack of capability checks and nonce checks, presents a notable risk that could be exploited if any user-controlled data makes its way into output without proper sanitization.

Key Concerns

  • Insufficient output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Woo Products Tree Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Woo Products Tree Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
43
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

4% escaped45 total outputs
Attack Surface

Woo Products Tree Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_initmi_woo_products_tree_init.php:30
actionwp_enqueue_scriptsmi_woo_products_tree_init.php:63
Maintenance & Trust

Woo Products Tree Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Woo Products Tree Developer Profile

denispishniak

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Woo Products Tree

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-products-tree/js/scripts.js/wp-content/plugins/woo-products-tree/css/styles.css
Script Paths
/wp-content/plugins/woo-products-tree/js/scripts.js
Version Parameters
woo-products-tree/js/scripts.js?ver=woo-products-tree/css/styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
mi-catprodlistmi-prodmi-currentprodmi-prodlink
Data Attributes
data-img_sizedata-show_pricedata-show_lmarksdata-show_bordersdata-tab_transpdata-tab_color1+1 more
FAQ

Frequently Asked Questions about Woo Products Tree