WooInventory Lite Security & Risk Analysis

wordpress.org/plugins/wooinventory-lite

plugins.infosfttech.com presents WooInventory Lite, Its basic WooCommerce Inventory Management Plugin to help you easily manage WooCommerce stock for …

10 active installs v2.0 PHP 5.6+ WP 5.7+ Updated Feb 20, 2023
inventory-reportwoocommercewoocommerce-inventorywoocommerce-inventory-lite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WooInventory Lite Safe to Use in 2026?

Generally Safe

Score 85/100

WooInventory Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The wooinventory-lite v2.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no recorded history of known vulnerabilities. The absence of file operations and external HTTP requests also reduces the potential attack vectors. However, significant concerns arise from the static analysis. The plugin has a notable attack surface with one AJAX handler that lacks authentication checks, presenting a direct entry point for unauthenticated users. Furthermore, a low percentage of output escaping (14%) indicates a high risk of cross-site scripting (XSS) vulnerabilities, as data is likely being rendered directly without proper sanitization. The taint analysis, while limited in scope, flagged two unsanitized paths, suggesting potential for more subtle vulnerabilities even if not classified as critical or high severity in this specific analysis. The lack of nonce checks on the unprotected AJAX handler is also a significant omission.

In conclusion, while the plugin avoids common pitfalls like raw SQL and known CVEs, its handling of user input and access control for its AJAX endpoint is concerning. The limited output escaping is a critical weakness that could be easily exploited for XSS attacks. The presence of unsanitized paths, even without critical severity, warrants attention and further investigation. The overall security can be considered moderate with significant areas for improvement, particularly in input validation, output escaping, and securing AJAX endpoints.

Key Concerns

  • AJAX handler without auth checks
  • Low output escaping percentage
  • Taint flows with unsanitized paths
  • No nonce checks
Vulnerabilities
None known

WooInventory Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WooInventory Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
16 prepared
Unescaped Output
57
9 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared16 total queries

Output Escaping

14% escaped66 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
page_init (include\ic-woo-manage-inventory.php:7)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

WooInventory Lite Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_ic_mange_inv_liteinclude\ic-woocommerce-inventory-lite-init.php:8
WordPress Hooks 5
filterplugin_action_links_wp-job-pro/ic-job-manager.phpic-woocommerce-inventory-lite.php:24
actioninitic-woocommerce-inventory-lite.php:25
actionplugins_loadedic-woocommerce-inventory-lite.php:26
actionadmin_menuinclude\ic-woocommerce-inventory-lite-init.php:6
actionadmin_enqueue_scriptsinclude\ic-woocommerce-inventory-lite-init.php:7
Maintenance & Trust

WooInventory Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 20, 2023
PHP min version5.6
Downloads4K

Community Trust

Rating46/100
Number of ratings3
Active installs10
Developer Profile

WooInventory Lite Developer Profile

infosoftplugin

6 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WooInventory Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wooinventory-lite/js/script.js/wp-content/plugins/wooinventory-lite/js/ic-mange-inv.js/wp-content/plugins/wooinventory-lite/css/ic-mange-inv.css/wp-content/plugins/wooinventory-lite/css/lib/font-awesome.min.css
Script Paths
../js/script.js../js/ic-mange-inv.js

HTML / DOM Fingerprints

CSS Classes
ic_inventory_liteic_postboxic_summaryic_blockic_block-orangeic_block-pinkic_block-purpleic_block-yellow
JS Globals
ic_taxt_report_ajax_object
REST Endpoints
/wp-json/ic-woocommerce-inventory-lite/v1/some_endpoint
FAQ

Frequently Asked Questions about WooInventory Lite