Show Variations as Single Products for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-show-single-variations-shop-category

Display WooCommerce product variations as individual products on shop, category, and tag pages — helping customers find and buy exactly what they want …

500 active installs v3.0 PHP 7.2+ WP 5.0+ Updated Mar 8, 2026
product-variationsshow-variations-shop-pagevariable-productswoocommerce-shop-pagewoocommerce-variations
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 28, 2025
Download
Safety Verdict

Is Show Variations as Single Products for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Show Variations as Single Products for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 28, 2025Updated 2mo ago
Risk Assessment

The "woo-show-single-variations-shop-category" plugin version 3.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping, with 90% of outputs being properly handled, and avoids dangerous functions, file operations, and external HTTP requests. The plugin also has a history of a single medium severity vulnerability, which is now patched, suggesting a responsive development team.

However, there are notable concerns. The plugin exposes one REST API route without adequate permission checks, creating an immediate attack vector. While the static analysis did not reveal any critical or high severity taint flows, the lack of observed taint flows could be due to the limited scope of the analysis or simple plugin logic. The absence of nonce checks on any entry points, combined with the unprotected REST API route, is a significant weakness that could be exploited by attackers.

The plugin's vulnerability history, despite being currently clear, includes a past medium vulnerability related to missing authorization. This, coupled with the current unprotected REST API route, suggests a recurring pattern of authorization weaknesses. While the plugin has strengths in output handling and avoiding certain risky functions, the presence of an unprotected entry point and a history of authorization issues warrants caution.

Key Concerns

  • Unprotected REST API route
  • No nonce checks on entry points
  • Past medium severity vulnerability (now patched)
  • 50% of SQL queries not using prepared statements
Vulnerabilities
1 published

Show Variations as Single Products for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-66114medium · 5.3Missing Authorization

Show Variations as Single Products Woocommerce <= 2.0 - Missing Authorization

Nov 28, 2025 Patched in 3.0 (4d)
Version History

Show Variations as Single Products for WooCommerce Release Timeline

v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Show Variations as Single Products for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
4 prepared
Unescaped Output
2
18 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select23.4.8

SQL Query Safety

50% prepared8 total queries

Output Escaping

90% escaped20 total outputs
Attack Surface
1 unprotected

Show Variations as Single Products for WooCommerce Attack Surface

Entry Points6
Unprotected1

REST API Routes 6

GET/wp-json/wssvsc/v1/settingsincludes\WSSVSC_Admin.php:72
GET/wp-json/wssvsc/v1/categoriesincludes\WSSVSC_Admin.php:76
POST/wp-json/wssvsc/v1/resetincludes\WSSVSC_Admin.php:79
GET/wp-json/wssvsc/v1/statsincludes\WSSVSC_Admin.php:82
POST/wp-json/wssvsc/v1/setup-syncincludes\WSSVSC_Admin.php:87
POST/wp-json/wssvsc/v1/sync-batchincludes\WSSVSC_Admin.php:92
WordPress Hooks 12
actionadmin_enqueue_scriptsincludes\WSSVSC_Admin.php:9
actionadmin_menuincludes\WSSVSC_Admin.php:11
actionrest_api_initincludes\WSSVSC_Admin.php:12
filterwoocommerce_product_data_tabsincludes\WSSVSC_Admin.php:14
filterwoocommerce_product_data_panelsincludes\WSSVSC_Admin.php:15
actionwoocommerce_process_product_metaincludes\WSSVSC_Admin.php:16
actionwoocommerce_product_after_variable_attributesincludes\WSSVSC_Admin.php:17
actionwoocommerce_save_product_variationincludes\WSSVSC_Admin.php:18
filterwoocommerce_product_variation_titleincludes\WSSVSC_Admin.php:19
actionwoocommerce_product_queryincludes\WSSVSC_Frontend.php:9
filterposts_clausesincludes\WSSVSC_Frontend.php:10
filterwoocommerce_shortcode_products_queryincludes\WSSVSC_Frontend.php:11
Maintenance & Trust

Show Variations as Single Products for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 8, 2026
PHP min version7.2
Downloads17K

Community Trust

Rating62/100
Number of ratings18
Active installs500
Developer Profile

Show Variations as Single Products for WooCommerce Developer Profile

theme funda

26 plugins · 12K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Show Variations as Single Products for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-show-single-variations-shop-category/build/style-index.css/wp-content/plugins/woo-show-single-variations-shop-category/build/index.js
Version Parameters
woo-show-single-variations-shop-category/build/style-index.css?ver=woo-show-single-variations-shop-category/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
wssvsc-admin-root
JS Globals
wssvscAdminData
REST Endpoints
/wp-json/wssvsc/v1/settings/wp-json/wssvsc/v1/categories/wp-json/wssvsc/v1/reset/wp-json/wssvsc/v1/stats/wp-json/wssvsc/v1/setup-sync/wp-json/wssvsc/v1/sync-batch
FAQ

Frequently Asked Questions about Show Variations as Single Products for WooCommerce