WooCompany015 Security & Risk Analysis

wordpress.org/plugins/woocompany015

Plugin ufficiale WooCompany015, attiva l'integrazione degli ordini ricevuti sul sito WooCommerce con il gestionale COMPANY015 https://www.

0 active installs v1.1.0 PHP 5.6+ WP 4.6+ Updated Unknown
codice-destinatariofattura-elettronicafattura-xmlfatturewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WooCompany015 Safe to Use in 2026?

Generally Safe

Score 100/100

WooCompany015 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the static analysis, the "woocompany015" v1.1.0 plugin exhibits a generally good security posture in several key areas. It reports zero AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting its attack surface. Furthermore, the absence of dangerous functions, the use of prepared statements for all SQL queries, and the lack of known CVEs are all positive indicators. The plugin also avoids bundled libraries, which can sometimes introduce vulnerabilities.

However, there are notable areas of concern. A mere 27% of output escaping is a significant weakness, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might be rendered without proper sanitization. The complete absence of nonce checks and capability checks on any potential entry points, even though the reported attack surface is currently zero, indicates a critical lack of fundamental WordPress security practices that could become exploitable if new entry points are introduced or if the current analysis is incomplete. The plugin's history of zero vulnerabilities is reassuring but could also reflect a lack of rigorous security testing or a short operational history.

In conclusion, while "woocompany015" v1.1.0 demonstrates strengths in attack surface minimization and secure SQL handling, the extremely low output escaping rate and the complete absence of nonce and capability checks present substantial risks. The plugin would benefit greatly from a thorough review and remediation of its output escaping mechanisms and the implementation of appropriate security checks on all entry points.

Key Concerns

  • Low output escaping rate
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

WooCompany015 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WooCompany015 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
2
Bundled Libraries
0

Output Escaping

27% escaped15 total outputs
Attack Surface

WooCompany015 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_initwoocompany015.php:16
actionadmin_menuwoocompany015.php:17
filterplugin_action_links_woocompany015/woocompany015.phpwoocompany015.php:26
filterplugin_action_links_woocompany015/woocompany015.phpwoocompany015.php:43
actionwoocommerce_checkout_order_processedwoocompany015.php:338
actionwoocommerce_new_orderwoocompany015.php:339
actionwoocommerce_process_shop_order_metawoocompany015.php:366
Maintenance & Trust

WooCompany015 Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedUnknown
PHP min version5.6
Downloads999

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WooCompany015 Developer Profile

mediapromotionsrl

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WooCompany015

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WooCompany015