WP E-Commerce Advance Sales Report Lite Security & Risk Analysis

wordpress.org/plugins/wp-e-commerce-advance-sales-report-lite

WP E-Commerce Advance Sales Report Lite shows you all key sales information in one main Dashboard in very intuitive, easy to understand format which g …

10 active installs v1.0 PHP + WP 3.8.1+ Updated Mar 5, 2014
adminadministrationwoocommercewordpress-e-commercewp-e-commerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP E-Commerce Advance Sales Report Lite Safe to Use in 2026?

Generally Safe

Score 85/100

WP E-Commerce Advance Sales Report Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The plugin 'wp-e-commerce-advance-sales-report-lite' version 1.0 exhibits a significant security concern due to an unprotected AJAX handler, representing its entire attack surface. While the majority of SQL queries utilize prepared statements and there's a lack of dangerous functions or external HTTP requests, the absence of authentication checks on the sole entry point is a critical oversight. This leaves the plugin vulnerable to unauthorized access and potential manipulation of its sales report functionalities.

The static analysis also reveals a concerning 0% of output escaping. This means that any data processed or displayed by the plugin could be susceptible to cross-site scripting (XSS) attacks, as user-supplied input might not be properly sanitized before being rendered in the browser. The lack of nonce checks and capability checks further exacerbates these risks, as there are no mechanisms in place to verify user authorization or prevent request forgery.

Despite the lack of recorded vulnerability history, which is a positive indicator, the current state of the code suggests a foundational lack of security best practices. The presence of an unprotected AJAX handler and universally unescaped output are serious weaknesses that outweigh the positive aspects of prepared SQL statements. While the plugin is small and has no known CVEs, the existing code signals highlight significant potential vulnerabilities that require immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • 0% properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP E-Commerce Advance Sales Report Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP E-Commerce Advance Sales Report Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
12 prepared
Unescaped Output
29
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

92% prepared13 total queries

Output Escaping

0% escaped29 total outputs
Attack Surface
1 unprotected

WP E-Commerce Advance Sales Report Lite Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_ic_cr_action_commanic-wpecommerce-advance-sales-report.php:27
WordPress Hooks 4
actionadmin_menuic-wpecommerce-advance-sales-report.php:23
actionadmin_enqueue_scriptsic-wpecommerce-advance-sales-report.php:26
actionadmin_footeric-wpecommerce-advance-sales-report.php:32
actionadmin_noticesic-wpecommerce-advance-sales-report.php:217
Maintenance & Trust

WP E-Commerce Advance Sales Report Lite Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedMar 5, 2014
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP E-Commerce Advance Sales Report Lite Developer Profile

infosoftplugin

6 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP E-Commerce Advance Sales Report Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-e-commerce-advance-sales-report-lite/assets/css/admin.css/wp-content/plugins/wp-e-commerce-advance-sales-report-lite/assets/graph/css/jquery.jqplot.min.css/wp-content/plugins/wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/jquery.jqplot.min.js/wp-content/plugins/wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/jqplot.pieRenderer.min.js/wp-content/plugins/wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/jqplot.meterGaugeRenderer.min.js/wp-content/plugins/wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/jqplot.pointLabels.min.js/wp-content/plugins/wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/jqplot.dateAxisRenderer.min.js/wp-content/plugins/wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/graph.js
Script Paths
/wp-content/plugins/wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/graph.js
Version Parameters
wp-e-commerce-advance-sales-report-lite/assets/css/admin.css?ver=wp-e-commerce-advance-sales-report-lite/assets/graph/css/jquery.jqplot.min.css?ver=wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/jquery.jqplot.min.js?ver=wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/jqplot.pieRenderer.min.js?ver=wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/jqplot.meterGaugeRenderer.min.js?ver=wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/jqplot.pointLabels.min.js?ver=wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/jqplot.dateAxisRenderer.min.js?ver=wp-e-commerce-advance-sales-report-lite/assets/graph/scripts/graph.js?ver=

HTML / DOM Fingerprints

CSS Classes
ic_mis_reportic_cr_wrapwoo_cr-reports-wrapwoo_cr-reports-topstatThreeCol_BoxesLastBox_Marginexample-chart
Data Attributes
id="today_order_count_meter_gauge"id="top_product_pie_chart"id="last_7_days_sales_order_amount"
JS Globals
ajax_object
FAQ

Frequently Asked Questions about WP E-Commerce Advance Sales Report Lite