
WooMaxMin for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woomaxminWooCommerce Minimum & Maximum Purchase Limit plugin gives you the ability to set up minimum and maximum purchase limit for your customers.
Is WooMaxMin for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100WooMaxMin for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woomaxmin" v1.1 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events suggests a minimal attack surface. Furthermore, the code does not appear to utilize dangerous functions, perform file operations, or make external HTTP requests, which are common vectors for vulnerabilities. The fact that all SQL queries utilize prepared statements is a strong indicator of good database security practices.
However, a significant concern arises from the output escaping analysis. With 0% of its total outputs properly escaped, the plugin presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any data that is displayed to users, especially if it originates from user input or external sources, could be manipulated to inject malicious scripts. The lack of nonce and capability checks, while not directly leading to a deduction in this specific analysis due to the lack of entry points, indicates a potential weakness that could become exploitable if new entry points are introduced in future versions without corresponding security measures.
The plugin's vulnerability history is entirely clean, with no recorded CVEs. This, combined with the positive findings in the static analysis, suggests a generally well-maintained codebase. The absence of vulnerabilities in the past, especially with the current output escaping issue, might indicate that the plugin's functionality is limited or that it has not been subjected to extensive security testing or exploitation attempts. Nevertheless, the unescaped output remains a critical area of concern that should be addressed.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
WooMaxMin for WooCommerce Security Vulnerabilities
WooMaxMin for WooCommerce Code Analysis
Output Escaping
WooMaxMin for WooCommerce Attack Surface
WordPress Hooks 9
Maintenance & Trust
WooMaxMin for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WooMaxMin for WooCommerce Alternatives
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Welcart e-Commerce
usc-e-shop
Welcart is a free e-commerce plugin for Wordpress with top market share in Japan.
External Product New Tab for WooCommerce
wc-external-product-new-tab
This plugin sets all external / affiliate product buy now links on a WooCommerce site to open in a new web browser tab.
Shopping Cart & eCommerce Store
wp-easycart
A FREE WordPress eCommerce & WordPress Shopping Cart plugin that can sell products, subscriptions, downloads, services, donations, and much more o …
Invoice Payment Gateway for WooCommerce
wc-invoice-gateway
The Invoice Payment Gateway for WooCommerce plugin adds an Invoice Payment Gateway feature to the WooCommerce plugin for B2B transactions when instant …
WooMaxMin for WooCommerce Developer Profile
2 plugins · 10 total installs
How We Detect WooMaxMin for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woomaxmin/woomaxmin.php