
Show Variations as Single Products for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-show-single-variations-shop-categoryDisplay WooCommerce product variations as individual products on shop, category, and tag pages — helping customers find and buy exactly what they want …
Is Show Variations as Single Products for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Show Variations as Single Products for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "woo-show-single-variations-shop-category" plugin version 3.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping, with 90% of outputs being properly handled, and avoids dangerous functions, file operations, and external HTTP requests. The plugin also has a history of a single medium severity vulnerability, which is now patched, suggesting a responsive development team.
However, there are notable concerns. The plugin exposes one REST API route without adequate permission checks, creating an immediate attack vector. While the static analysis did not reveal any critical or high severity taint flows, the lack of observed taint flows could be due to the limited scope of the analysis or simple plugin logic. The absence of nonce checks on any entry points, combined with the unprotected REST API route, is a significant weakness that could be exploited by attackers.
The plugin's vulnerability history, despite being currently clear, includes a past medium vulnerability related to missing authorization. This, coupled with the current unprotected REST API route, suggests a recurring pattern of authorization weaknesses. While the plugin has strengths in output handling and avoiding certain risky functions, the presence of an unprotected entry point and a history of authorization issues warrants caution.
Key Concerns
- Unprotected REST API route
- No nonce checks on entry points
- Past medium severity vulnerability (now patched)
- 50% of SQL queries not using prepared statements
Show Variations as Single Products for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Show Variations as Single Products Woocommerce <= 2.0 - Missing Authorization
Show Variations as Single Products for WooCommerce Release Timeline
Show Variations as Single Products for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Show Variations as Single Products for WooCommerce Attack Surface
REST API Routes 6
WordPress Hooks 12
Maintenance & Trust
Show Variations as Single Products for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Show Variations as Single Products for WooCommerce Alternatives
QODE Variation Swatches for WooCommerce
qode-variation-swatches-for-woocommerce
QODE Variation Swatches for WooCommerce provides you with a clear-cut way to present shoppers with detailed item variations alongside your products.
Variation Dropdown to Radio Buttons for WooCommerce
gm-variations-radio-buttons-for-woocommerce
Replace the default WooCommerce variation dropdown with radio buttons, switch boxes, or a styled Select2 — boosting conversions and user experience on …
WT Variation Bulk Order
wt-variation-bulk-order
WT Variation Bulk Order plugin simplifies purchasing variant products by streamlining the selection process for bulk orders.
WCBoost – Variation Swatches
wcboost-variation-swatches
WCBoost – Variation Swatches is the ultimate plugin to display WooCommerce product variations in style.
Show only lowest prices in variable products for WooCommerce
show-only-lowest-prices-in-woocommerce-variable-products
Clean up your variable product prices by showing only the lowest price instead of confusing price ranges. Now with customizable settings!
Show Variations as Single Products for WooCommerce Developer Profile
26 plugins · 12K total installs
How We Detect Show Variations as Single Products for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-show-single-variations-shop-category/build/style-index.css/wp-content/plugins/woo-show-single-variations-shop-category/build/index.jswoo-show-single-variations-shop-category/build/style-index.css?ver=woo-show-single-variations-shop-category/build/index.js?ver=HTML / DOM Fingerprints
wssvsc-admin-rootwssvscAdminData/wp-json/wssvsc/v1/settings/wp-json/wssvsc/v1/categories/wp-json/wssvsc/v1/reset/wp-json/wssvsc/v1/stats/wp-json/wssvsc/v1/setup-sync/wp-json/wssvsc/v1/sync-batch