Display WooCommerce User Info Security & Risk Analysis

wordpress.org/plugins/woocommerce-user-shortcode

Displays formatted copy of Woo Commerce Shipping and/or Billing information in a shortcode.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Unknown
billing-infoshipping-infoshortcodeswoowoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Display WooCommerce User Info Safe to Use in 2026?

Generally Safe

Score 100/100

Display WooCommerce User Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'woocommerce-user-shortcode' plugin v1.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, and proper output escaping are significant strengths. The plugin also demonstrates a clean vulnerability history with no recorded CVEs, indicating a history of secure development or minimal exposure.

However, there are areas for improvement. The most notable concern is the complete lack of nonce checks and capability checks across all entry points. While the static analysis shows zero unprotected entry points, the absence of these standard security mechanisms leaves the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks and unauthorized privilege escalation if the entry points were ever to become unprotected or if new vulnerabilities are introduced in future versions. The taint analysis also shows zero flows analyzed, which may indicate limited testing or complexity that prevented analysis, leaving potential vulnerabilities undiscovered.

In conclusion, the plugin is well-coded in terms of direct code security practices. The lack of historical vulnerabilities is reassuring. Nevertheless, the absence of essential security checks like nonces and capability checks represents a significant weakness that could be exploited. This should be addressed proactively to ensure long-term security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Taint analysis incomplete
Vulnerabilities
None known

Display WooCommerce User Info Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Display WooCommerce User Info Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Display WooCommerce User Info Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[shipping_info] woocommerce-user-shortcode.php:45
[billing_info] woocommerce-user-shortcode.php:81
Maintenance & Trust

Display WooCommerce User Info Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedUnknown
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Display WooCommerce User Info Developer Profile

richymilo

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Display WooCommerce User Info

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
title
Shortcode Output
<header class="title"><h3>Shipping Address</h3></header><i><header class="title"><h3>Billing Address</h3></header><i>
FAQ

Frequently Asked Questions about Display WooCommerce User Info