Woo vendor module Security & Risk Analysis

wordpress.org/plugins/woo-vendor-module-add-ons-woocommerce

Woo vendor module is used for vendor system with woocommerce website.It allow anyone to open a store on your site!

10 active installs v1.2 PHP + WP 3.1+ Updated Sep 23, 2015
product-vendorvendorvendor-shopvendor-systemwoo-vendor
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Woo vendor module Safe to Use in 2026?

Generally Safe

Score 85/100

Woo vendor module has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "woo-vendor-module-add-ons-woocommerce" plugin v1.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has a clean vulnerability history with no known CVEs. Furthermore, the static analysis reveals a small attack surface with no identified AJAX handlers or REST API routes that lack authentication checks, and no dangerous functions are present. The absence of file operations and external HTTP requests also reduces potential risks. However, a significant concern arises from the taint analysis, which found 6 flows with unsanitized paths, all analyzed. While none were flagged as critical or high severity, this indicates potential for unintended data manipulation or exposure if these flows are exploited. Additionally, the low percentage of properly escaped output (19%) across 74 identified outputs is a notable weakness, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities, especially when combined with the absence of nonce checks and capability checks on entry points.

Key Concerns

  • Flows with unsanitized paths (6)
  • Low output escaping percentage (19%)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Woo vendor module Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Woo vendor module Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
60
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

19% escaped74 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
<wv-woo-vendor-tab-pages> (init\admin\wv-woo-vendor-tab-pages.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Woo vendor module Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[woo_vendor_shop] init\wv-init.php:108
[woo_vendor_myaccount] init\wv-init.php:114
[woo_vendor_orders] init\wv-init.php:119
WordPress Hooks 14
filterparse_queryinclude\wv-functions.php:11
filterpre_get_postsinclude\wv-functions.php:13
filterbody_classinclude\wv-functions.php:17
actionwp_enqueue_scriptsinclude\wv-functions.php:25
actionadmin_enqueue_scriptsinclude\wv-functions.php:27
filtermanage_edit-product_columnsinit\admin\wv-extra_column_postType_product.php:6
actionmanage_product_posts_custom_columninit\admin\wv-extra_column_postType_product.php:7
actionadmin_menuinit\admin\wv-woo-vendors.php:9
filterwoocommerce_email_headersinit\wv-init.php:25
actionwoocommerce_payment_completeinit\wv-init.php:27
actionwoocommerce_thankyoupages\checkout\wv-thankyou.php:13
filterregister_formpages\myaccount\wv-vendorlinks-in-myaccount.php:10
actionwoocommerce_created_customerpages\myaccount\wv-vendorlinks-in-myaccount.php:25
actioninitwoo-vendor-module.php:59
Maintenance & Trust

Woo vendor module Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedSep 23, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Woo vendor module Developer Profile

Shankaranand Maurya

3 plugins · 190 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Woo vendor module

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-vendor-module-add-ons-woocommerce/assets/css/jquery-ui.css/wp-content/plugins/woo-vendor-module-add-ons-woocommerce/assets/css/wv-style.css/wp-content/plugins/woo-vendor-module-add-ons-woocommerce/assets/js/jquery-custom.js/wp-content/plugins/woo-vendor-module-add-ons-woocommerce/assets/css/admin-style.css
Script Paths
/wp-content/plugins/woo-vendor-module-add-ons-woocommerce/assets/js/jquery-custom.js
Version Parameters
woo-vendor-module-add-ons-woocommerce/assets/css/jquery-ui.css?ver=woo-vendor-module-add-ons-woocommerce/assets/css/wv-style.css?ver=woo-vendor-module-add-ons-woocommerce/assets/js/jquery-custom.js?ver=woo-vendor-module-add-ons-woocommerce/assets/css/admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wvm_role_vendor
HTML Comments
Author Request :Woocommerce Plugin NeededWoo vendor plugin functions initialization plugin.customize pages+33 more
JS Globals
WOO_VENDOR__PLUGIN_URL
FAQ

Frequently Asked Questions about Woo vendor module