
Woo Purchased Products Security & Risk Analysis
wordpress.org/plugins/woo-purchased-productsThe plugin to help a logged in user show list of products purchased by him in his account
Is Woo Purchased Products Safe to Use in 2026?
Generally Safe
Score 85/100Woo Purchased Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-purchased-products" plugin v1.1 presents a concerning security posture due to a significant lack of security controls. While the absence of dangerous functions, SQL injection vulnerabilities through prepared statements, file operations, and external HTTP requests are positive signs, the plugin suffers from critical omissions. The most glaring issue is a single AJAX handler that lacks any authentication or capability checks, creating a direct entry point for attackers. Furthermore, the extremely low percentage of properly escaped output (17%) suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site.
The plugin's vulnerability history is clean, which might suggest a generally stable codebase. However, this is overshadowed by the fundamental security flaws identified in the static analysis. The lack of nonce checks on the AJAX handler is a significant oversight that makes it susceptible to Cross-Site Request Forgery (CSRF) attacks. In conclusion, while the plugin avoids some common pitfalls, the unprotected AJAX handler and widespread unescaped output create substantial risks that require immediate attention. The plugin's strengths in avoiding raw SQL and dangerous functions are completely undermined by its direct, unprotected entry points and potential for XSS.
Key Concerns
- AJAX handler without auth checks
- Low percentage of properly escaped output
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
Woo Purchased Products Security Vulnerabilities
Woo Purchased Products Code Analysis
Output Escaping
Woo Purchased Products Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Woo Purchased Products Maintenance & Trust
Maintenance Signals
Community Trust
Woo Purchased Products Alternatives
No alternatives data available yet.
Woo Purchased Products Developer Profile
16 plugins · 500 total installs
How We Detect Woo Purchased Products
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-purchased-products/assets/css/wrapper-bs.css/wp-content/plugins/woo-purchased-products/assets/css/vote.css/wp-content/plugins/woo-purchased-products/assets/js/vote.jswp-content/plugins/woo-purchased-products/assets/js/vote.jsHTML / DOM Fingerprints
bs-containercontainer-fluidwcpp-vote-actionwcpp-vote-buttonwcpp-cancel-buttondata-action