Related Products for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-related-products-refresh-on-reload

Display random related products in a slider based on product category, tag, or attribute on every product page.

3K active installs v3.3.17 PHP + WP 4.0+ Updated Oct 2, 2025
products-sliderrandomrelated-productssliderwoocommerce
100
A · Safe
CVEs total1
Unpatched0
Last CVEOct 29, 2023
Safety Verdict

Is Related Products for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Related Products for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 29, 2023Updated 7mo ago
Risk Assessment

The plugin "woo-related-products-refresh-on-reload" v3.3.17 exhibits a generally good security posture with several positive indicators. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output suggest that the developers have a strong understanding of secure coding practices. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its stability. However, there are areas for concern. The presence of external HTTP requests, while not inherently a vulnerability, introduces potential risks if not handled with extreme care, especially if the target endpoints are untrusted or vulnerable themselves. Furthermore, the plugin has a history of known vulnerabilities, specifically a medium-severity Cross-Site Scripting (XSS) issue discovered in late 2023. Although this vulnerability is currently patched, the recurrence of such issues indicates a potential for new vulnerabilities to emerge, especially if the development team does not maintain rigorous security testing and code review processes.

Key Concerns

  • Medium severity XSS vulnerability in history
  • Presence of external HTTP requests
  • No capability checks on entry points
Vulnerabilities
1 published

Related Products for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-5234medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Related Products for WooCommerce <= 3.3.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Oct 29, 2023 Patched in 3.3.16 (86d)
Version History

Related Products for WooCommerce Release Timeline

v3.3.17Current
v3.3.16
v3.3.151 CVE
v3.3.141 CVE
v3.3.131 CVE
Code Analysis
Analyzed Mar 16, 2026

Related Products for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
52 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

93% escaped56 total outputs
Attack Surface

Related Products for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[woo-related] woo-related-products.php:532
WordPress Hooks 15
actionplugins_loadedincludes\class-woo-related-products.php:136
actionadmin_enqueue_scriptsincludes\class-woo-related-products.php:150
actionadmin_enqueue_scriptsincludes\class-woo-related-products.php:151
actionadmin_menuincludes\class-woo-related-products.php:152
actionadmin_menuincludes\class-woo-related-products.php:153
actionwp_enqueue_scriptsincludes\class-woo-related-products.php:168
actionwp_enqueue_scriptsincludes\class-woo-related-products.php:169
actionwp_enqueue_scriptsincludes\class-woo-related-products.php:170
actionwp_enqueue_scriptsincludes\class-woo-related-products.php:171
filterwoocommerce_related_products_argspublic\class-woo-related-products-public.php:125
actionupgrader_process_completewoo-related-products.php:574
actionwoocommerce_after_single_productwoo-related-products.php:614
filterwidget_textwoo-related-products.php:615
actionadmin_noticeswoo-related-products.php:626
actionadmin_initwoo-related-products.php:687
Maintenance & Trust

Related Products for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 2, 2025
PHP min version
Downloads179K

Community Trust

Rating98/100
Number of ratings46
Active installs3K
Developer Profile

Related Products for WooCommerce Developer Profile

peachpay

3 plugins · 4K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect Related Products for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-related-products-refresh-on-reload/assets/css/styles.css/wp-content/plugins/woo-related-products-refresh-on-reload/assets/js/custom.js/wp-content/plugins/woo-related-products-refresh-on-reload/assets/js/woo-related-products.js/wp-content/plugins/woo-related-products-refresh-on-reload/assets/css/owl.carousel.min.css/wp-content/plugins/woo-related-products-refresh-on-reload/assets/css/owl.theme.default.min.css/wp-content/plugins/woo-related-products-refresh-on-reload/assets/js/owl.carousel.min.js
Script Paths
/wp-content/plugins/woo-related-products-refresh-on-reload/assets/js/custom.js/wp-content/plugins/woo-related-products-refresh-on-reload/assets/js/woo-related-products.js/wp-content/plugins/woo-related-products-refresh-on-reload/assets/js/owl.carousel.min.js
Version Parameters
woo-related-products-refresh-on-reload/assets/css/styles.css?ver=woo-related-products-refresh-on-reload/assets/js/custom.js?ver=woo-related-products-refresh-on-reload/assets/js/woo-related-products.js?ver=woo-related-products-refresh-on-reload/assets/css/owl.carousel.min.css?ver=woo-related-products-refresh-on-reload/assets/css/owl.theme.default.min.css?ver=woo-related-products-refresh-on-reload/assets/js/owl.carousel.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
woo-related-products-containerwoorelated-titleowl-carouselowl-themeowl-navowl-dots
Data Attributes
data-woorelated-basedondata-woorelated-excludedata-woorelated-titledata-woorelated-number
JS Globals
wrprr_custom_script_params
Shortcode Output
[wrprrdisplay][related_products]
FAQ

Frequently Asked Questions about Related Products for WooCommerce