Alter Inventory – Woocommerce Plugin Security & Risk Analysis

wordpress.org/plugins/woocommerce-alter-inventory

Woocommerce Inventory is a alternative products display, plugin worked on Wordpress 4.1 & Woocommerce 2.2.8.

10 active installs v1.2.8 PHP + WP 3.6.1+ Updated Jun 14, 2016
inventoryproduct-variationswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Alter Inventory – Woocommerce Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Alter Inventory – Woocommerce Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "woocommerce-alter-inventory" plugin v1.2.8 demonstrates a generally strong security posture with several positive indicators. Notably, there are no known CVEs associated with this plugin, suggesting a history of responsible development and maintenance. The code analysis reveals a complete absence of dangerous functions, file operations, and external HTTP requests, which are common vectors for exploitation. Furthermore, all SQL queries are properly prepared, and a decent number of nonce and capability checks are in place, indicating an awareness of common WordPress security best practices. However, there are areas for improvement. The output escaping is only properly implemented in 38% of cases, presenting a potential risk for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled rigorously in the remaining outputs. The taint analysis yielded no flows, which is positive, but the lack of comprehensive taint analysis may hide potential issues that weren't explicitly flagged. The presence of two shortcodes, while not inherently insecure, represents potential entry points that warrant careful review for proper sanitization and validation, especially in conjunction with the lower output escaping rate.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Alter Inventory – Woocommerce Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Alter Inventory – Woocommerce Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
50
30 escaped
Nonce Checks
2
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped80 total outputs
Attack Surface

Alter Inventory – Woocommerce Plugin Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[alter-inventory] admin\class-woocommerce-alter-inventory-admin.php:88
[alter-report] admin\class-woocommerce-alter-inventory-admin.php:89
WordPress Hooks 13
filterwoocommerce_settings_tabs_arrayadmin\class-woocommerce-alter-inventory-admin.php:74
actionwoocommerce_settings_tabs_alter_inventory_tabadmin\class-woocommerce-alter-inventory-admin.php:75
actionwoocommerce_update_options_alter_inventory_tabadmin\class-woocommerce-alter-inventory-admin.php:76
filterwoocommerce_available_payment_gatewaysadmin\class-woocommerce-alter-inventory-admin.php:92
actionwoocommerce_checkout_initadmin\class-woocommerce-alter-inventory-admin.php:220
filterwoocommerce_billing_fieldsadmin\class-woocommerce-alter-inventory-admin.php:232
filterwoocommerce_shipping_fieldsadmin\class-woocommerce-alter-inventory-admin.php:233
actionplugins_loadedincludes\class-woocommerce-alter-inventory.php:139
actionadmin_enqueue_scriptsincludes\class-woocommerce-alter-inventory.php:154
actionadmin_enqueue_scriptsincludes\class-woocommerce-alter-inventory.php:155
actionwp_enqueue_scriptsincludes\class-woocommerce-alter-inventory.php:170
actionwp_enqueue_scriptsincludes\class-woocommerce-alter-inventory.php:171
actionadmin_noticeswoocommerce-alter-inventory.php:90
Maintenance & Trust

Alter Inventory – Woocommerce Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJun 14, 2016
PHP min version
Downloads4K

Community Trust

Rating94/100
Number of ratings3
Active installs10
Developer Profile

Alter Inventory – Woocommerce Plugin Developer Profile

Alberto Cocchiara

2 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Alter Inventory – Woocommerce Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-alter-inventory/assets/css/alter-inventory-admin.css/wp-content/plugins/woocommerce-alter-inventory/assets/js/alter-inventory-admin.js/wp-content/plugins/woocommerce-alter-inventory/assets/css/alter-inventory-public.css/wp-content/plugins/woocommerce-alter-inventory/assets/js/alter-inventory-public.js
Script Paths
/wp-content/plugins/woocommerce-alter-inventory/admin/js/alter-inventory-admin.js/wp-content/plugins/woocommerce-alter-inventory/public/js/alter-inventory-public.js
Version Parameters
woocommerce-alter-inventory/assets/css/alter-inventory-admin.css?ver=woocommerce-alter-inventory/assets/js/alter-inventory-admin.js?ver=woocommerce-alter-inventory/assets/css/alter-inventory-public.css?ver=woocommerce-alter-inventory/assets/js/alter-inventory-public.js?ver=woocommerce-alter-inventory/admin/js/alter-inventory-admin.js?ver=woocommerce-alter-inventory/public/js/alter-inventory-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
alter_inventory_tablealter_inventory_cellalter_inventory_row
Data Attributes
data-alterinventory
JS Globals
wc_alter_inventory_admin_paramswc_alter_inventory_public_params
Shortcode Output
[alterinventory][altereports]
FAQ

Frequently Asked Questions about Alter Inventory – Woocommerce Plugin