PDF Compression & Watermarking – WoowPDF Security & Risk Analysis

wordpress.org/plugins/woow-pdf

A wordpress plugin by WoowPDF.

20 active installs v1.1.0 PHP 7.4+ WP 5.3+ Updated Sep 5, 2024
compresspdfwatermark
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PDF Compression & Watermarking – WoowPDF Safe to Use in 2026?

Generally Safe

Score 92/100

PDF Compression & Watermarking – WoowPDF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'woow-pdf' v1.1.0 plugin demonstrates strong adherence to secure coding practices based on the static analysis. It exhibits a complete absence of known vulnerabilities, including critical or high severity ones, and a clean vulnerability history. The code properly utilizes prepared statements for all SQL queries, ensures 100% of output is escaped, and includes a nonce check. This indicates a well-maintained and security-conscious development approach.

However, the absence of capability checks is a notable concern. While the attack surface appears minimal with zero AJAX handlers, REST API routes, shortcodes, or cron events without authentication, the lack of capability checks means that even if an entry point were to be discovered or introduced in a future version, access might not be properly restricted to authorized users. The presence of file operations and external HTTP requests, while not inherently malicious, represents potential vectors that could be exploited if not handled with extreme care, though no specific risks were flagged in the taint analysis.

Overall, 'woow-pdf' v1.1.0 presents a low-risk profile due to its robust implementation of fundamental security measures and its lack of historical vulnerabilities. The primary area for improvement lies in the implementation of capability checks to enforce user roles and permissions, ensuring a more comprehensive security posture against potential future threats.

Key Concerns

  • No capability checks implemented
Vulnerabilities
None known

PDF Compression & Watermarking – WoowPDF Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PDF Compression & Watermarking – WoowPDF Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
148 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
7
Bundled Libraries
0

Output Escaping

100% escaped148 total outputs
Attack Surface

PDF Compression & Watermarking – WoowPDF Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_initadmin\compress-settings.php:74
actionadd_attachmentadmin\functions-compress.php:162
actionadd_attachmentadmin\functions-processed-files.php:36
actionadd_attachmentadmin\functions-watermark-compress.php:143
actionadd_attachmentadmin\functions-watermark.php:300
actionadmin_initadmin\general-settings.php:49
actionadmin_initadmin\watermark-settings.php:59
actionadmin_initadmin\watermark-settings.php:259
actionadmin_footeradmin\watermark-settings.php:522
actionadmin_menuadmin\woow-pdf-admin-page-settings.php:40
actionplugins_loadedincludes\class-woow-pdf.php:136
actionadmin_enqueue_scriptsincludes\class-woow-pdf.php:151
actionadmin_enqueue_scriptsincludes\class-woow-pdf.php:152
Maintenance & Trust

PDF Compression & Watermarking – WoowPDF Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 5, 2024
PHP min version7.4
Downloads559

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

PDF Compression & Watermarking – WoowPDF Developer Profile

kfshakeel

1 plugin · 20 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PDF Compression & Watermarking – WoowPDF

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woow-pdf/admin/css/woow-pdf-admin.css/wp-content/plugins/woow-pdf/admin/js/woow-pdf-admin.js/wp-content/plugins/woow-pdf/admin/js/media-selector.js
Script Paths
/wp-content/plugins/woow-pdf/admin/js/woow-pdf-admin.js/wp-content/plugins/woow-pdf/admin/js/media-selector.js
Version Parameters
woow-pdf/admin/css/woow-pdf-admin.css?ver=woow-pdf/admin/js/woow-pdf-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-upload-image-buttondata-upload-image-inputdata-add-image-to-editor
JS Globals
woow_pdf_admin_media_selector
FAQ

Frequently Asked Questions about PDF Compression & Watermarking – WoowPDF