WooCommerce Product Type Column Security & Risk Analysis

wordpress.org/plugins/woocommerce-product-type-column

Displays a "product type" column (with icons) on the products admin screen in WooCommerce.

100 active installs v1.0.0 PHP 5.2+ WP 4.7+ Updated Aug 10, 2020
admin-columnsproductswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WooCommerce Product Type Column Safe to Use in 2026?

Generally Safe

Score 85/100

WooCommerce Product Type Column has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The WooCommerce Product Type Column plugin, version 1.0.0, exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the reliance on prepared statements for all SQL queries and the absence of dangerous functions are commendable practices. However, the analysis does reveal a weakness in output escaping, with only 40% of identified outputs being properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected in these unescaped outputs. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a good track record. Despite the positive indicators, the unescaped output is a notable concern that warrants attention to ensure robust protection against potential XSS attacks.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

WooCommerce Product Type Column Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WooCommerce Product Type Column Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped10 total outputs
Attack Surface

WooCommerce Product Type Column Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptsincludes\class-wc-product-type-column-admin.php:26
filtermanage_product_posts_columnsincludes\class-wc-product-type-column-admin.php:27
actionmanage_product_posts_custom_columnincludes\class-wc-product-type-column-admin.php:28
actioninitincludes\class-wc-product-type-column.php:19
actionplugins_loadedwoocommerce-product-type-column.php:50
Maintenance & Trust

WooCommerce Product Type Column Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 10, 2020
PHP min version5.2
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

WooCommerce Product Type Column Developer Profile

Automattic

213 plugins · 19.2M total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
1384 days
View full developer profile
Detection Fingerprints

How We Detect WooCommerce Product Type Column

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-product-type-column/assets/css/admin/admin.css
Version Parameters
woocommerce-product-type-column/assets/css/admin/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
wc-typeparent-tipsproduct-typetipsgroupedexternalvirtualdownloadable+2 more
Data Attributes
data-tip
FAQ

Frequently Asked Questions about WooCommerce Product Type Column