Improved External Products for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocommerce-improved-external-products

Opens links to external/affiliate products in a new tab.

1K active installs v1.6.9 PHP 7.4+ WP 3.5+ Updated Mar 25, 2026
affiliateexternal-productexternal-affiliatelinkwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Improved External Products for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Improved External Products for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of WooCommerce Improved External Products v1.6.9 indicates a generally strong security posture. The absence of dangerous functions, file operations, and external HTTP requests, coupled with a high percentage of properly escaped output and the use of prepared statements for SQL queries, are all positive indicators. The presence of a nonce check is also a good practice. However, the complete lack of capability checks across the codebase is a significant concern, suggesting potential for unauthorized access to certain functionalities if any sensitive operations were present. Taint analysis showing zero flows and a lack of known vulnerabilities further reinforce the impression of a well-secured plugin, but the absence of capability checks represents a notable area for improvement.

While the current version shows no critical flaws based on the provided data, the lack of capability checks is a weakness that could become a problem if the plugin's functionality were to expand or if unforeseen entry points were discovered. The plugin's history of zero recorded vulnerabilities is commendable and suggests a commitment to security by the developers. Overall, the plugin appears robust due to good coding practices in key areas, but the absence of permission controls warrants attention to ensure long-term security.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

Improved External Products for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Improved External Products for WooCommerce Release Timeline

v1.6.9Current
v1.6.8
v1.6.7
v1.6.6
v1.6.5
v1.6.4
v1.6.3
v1.6.2
v1.6.1
v1.6.0
v1.5.16
v1.5.15
v1.5.14
v1.5.13
v1.5.12
v1.5.11
v1.5.10
v1.5.9
v1.5.8
v1.5.7
Code Analysis
Analyzed Mar 16, 2026

Improved External Products for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
72 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped79 total outputs
Attack Surface

Improved External Products for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_enqueue_scriptsincludes\class-wciep-settings.php:15
actionadmin_initincludes\class-wciep-settings.php:16
actionadmin_menuincludes\class-wciep-settings.php:17
actioninitwc-improved-external-products.php:43
actioninitwc-improved-external-products.php:46
actionwp_loadedwc-improved-external-products.php:49
actionadmin_initwc-improved-external-products.php:58
actionadmin_noticeswc-improved-external-products.php:61
actionadmin_enqueue_scriptswc-improved-external-products.php:62
actionbefore_woocommerce_initwc-improved-external-products.php:65
actionwoocommerce_external_add_to_cartwc-improved-external-products.php:184
Maintenance & Trust

Improved External Products for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 25, 2026
PHP min version7.4
Downloads80K

Community Trust

Rating74/100
Number of ratings26
Active installs1K
Developer Profile

Improved External Products for WooCommerce Developer Profile

WP Overnight

7 plugins · 390K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
410 days
View full developer profile
Detection Fingerprints

How We Detect Improved External Products for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-improved-external-products/assets/js/admin-script.js
Version Parameters
woocommerce-improved-external-products/assets/js/admin-script.js?ver=woocommerce-improved-external-products/woocommerce-improved-external-products.php?ver=

HTML / DOM Fingerprints

CSS Classes
wpo-iepp-pro-notice
HTML Comments
<!-- keep track of how many days this notice is show so we can remove it after 7 days -->
Data Attributes
wpo-iepp-dismiss
FAQ

Frequently Asked Questions about Improved External Products for WooCommerce