Social Commerce for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-to-facebook-shop

Now you can start your facebook shop free. With Social Commerce for WooCommerce plugin you can easily sync or unsync your products from your woocommer …

200 active installs v2.5.4 PHP + WP 3.3.1+ Updated Apr 6, 2020
ecommercefacebookfacebook-shopfacebook-storeimport
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Social Commerce for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Social Commerce for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "woo-to-facebook-shop" plugin, version 2.5.4, presents a moderate security risk primarily due to its unprotected REST API entry points. While the plugin shows good practices by avoiding dangerous functions and file operations, and has a clean vulnerability history, the static analysis reveals two REST API routes that lack permission callbacks. This means any authenticated user could potentially interact with these endpoints without proper authorization checks, creating an attack vector. The presence of unsanitized paths in taint analysis, although not leading to critical or high severity issues in this scan, further highlights the potential for unintended data exposure or manipulation if combined with other weaknesses. The low percentage of SQL queries using prepared statements (33%) is also a concern, as it increases the risk of SQL injection vulnerabilities, although no specific instances were flagged as critical in this analysis. Overall, while the plugin has a positive track record, the identified unprotected REST API endpoints and the less-than-ideal SQL practices warrant attention and mitigation.

Key Concerns

  • REST API routes without permission callbacks
  • Unsanitized paths in taint analysis
  • Low percentage of SQL queries using prepared statements
  • No nonce checks on entry points (REST API)
Vulnerabilities
None known

Social Commerce for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Social Commerce for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
10
5 prepared
Unescaped Output
14
40 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

33% prepared15 total queries

Output Escaping

74% escaped54 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
wctofb_facebook_bulk_action (wctofb.php:376)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Social Commerce for WooCommerce Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

POST/wp-json/wctofb/v1/updatestatus/wctofb.php:936
POST/wp-json/wctofb/v1/updateproductdeletestatus/wctofb.php:974
WordPress Hooks 25
actionadmin_initwctofb.php:20
actionadmin_noticeswctofb.php:50
filtercron_scheduleswctofb.php:93
actionwctofbcronjobwctofb.php:127
actionadmin_enqueue_scriptswctofb.php:133
actionwoocommerce_settings_savedwctofb.php:142
filterwoocommerce_settings_tabs_arraywctofb.php:145
actionwoocommerce_settings_tabs_settings_tab_wctofbwctofb.php:146
actionwoocommerce_update_options_settings_tab_wctofbwctofb.php:147
actionadmin_enqueue_scriptswctofb.php:268
actioninitwctofb.php:270
actiontemplate_redirectwctofb.php:276
filterrequestwctofb.php:283
filtermanage_edit-product_columnswctofb.php:306
actionmanage_posts_custom_columnwctofb.php:340
actionadmin_footer-edit.phpwctofb.php:345
actionadmin_footer-edit.phpwctofb.php:360
actionload-edit.phpwctofb.php:375
actionadmin_noticeswctofb.php:475
actionwp_trash_postwctofb.php:512
actionsave_postwctofb.php:586
actionwp_insert_postwctofb.php:587
actionrest_api_initwctofb.php:934
actionrest_api_initwctofb.php:972
actionwp_loadedwctofb.php:1050

Scheduled Events 1

wctofbcronjob
Maintenance & Trust

Social Commerce for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 6, 2020
PHP min version
Downloads47K

Community Trust

Rating64/100
Number of ratings9
Active installs200
Developer Profile

Social Commerce for WooCommerce Developer Profile

premiumthemes

2 plugins · 250 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Commerce for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
notice-infonotice-errorfirst_time
Data Attributes
page=settings_tab_wctofb
FAQ

Frequently Asked Questions about Social Commerce for WooCommerce