
Name: WP e-Commerce Popular Products Security & Risk Analysis
wordpress.org/plugins/wp-e-commerce-popular-productsAdds a Widget and Shortcode to display Popular Products for WP e-Commerce Plugin.
Is Name: WP e-Commerce Popular Products Safe to Use in 2026?
Generally Safe
Score 85/100Name: WP e-Commerce Popular Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-e-commerce-popular-products v1.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries use prepared statements, and there are no external HTTP requests or file operations. The plugin also has a clean vulnerability history with zero known CVEs, which is a strong indicator of good past security practices. However, significant concerns arise from the lack of output escaping and the absence of nonce and capability checks.
The most critical weakness is the extremely low percentage (6%) of properly escaped outputs, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The presence of a shortcode, while a single entry point, is not protected by any nonce or capability checks, which could be exploited if it interacts with user-supplied data or performs sensitive actions. The lack of taint analysis results is also noted, though it could imply no complex data flows were analyzed or that no issues were found in the analyzed flows.
Overall, while the plugin's foundation appears solid with secure database interactions and no known past exploits, the severe deficiency in output escaping and the lack of authorization checks on its shortcode represent substantial immediate risks. The absence of vulnerabilities in the past is encouraging, but it does not negate the present concerns highlighted by the static analysis. Developers should prioritize addressing the output escaping and authorization issues.
Key Concerns
- Poor output escaping (6% properly escaped)
- Missing nonce checks
- Missing capability checks
- Shortcode with potential security risks
Name: WP e-Commerce Popular Products Security Vulnerabilities
Name: WP e-Commerce Popular Products Code Analysis
SQL Query Safety
Output Escaping
Name: WP e-Commerce Popular Products Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Name: WP e-Commerce Popular Products Maintenance & Trust
Maintenance Signals
Community Trust
Name: WP e-Commerce Popular Products Alternatives
Name: WP e-Commerce Featured Products
wp-e-commerce-featured-products
Adds a Widget and Shortcode to display Featured Products for WP e-Commerce Plugin.
Name: WP e-Commerce Table Price Shortcode
wp-e-commerce-table-price-shortcode
This plugin adds a shortcode for use with the WordPress e-Commerce Plugin.
DropStream – Automated eCommerce Fulfillment
wp-dropstream
DropStream is a powerful eCommerce plugin that integrates your WordPress site with your shipping solution or third-party fulfillment provider, allowin …
GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon
gourl-wp-ecommerce-bitcoin-altcoin-payment-gateway-addon
Provides Bitcoin/Altcoin Payment Gateway for WP eCommerce 3.8.10+ or higher. Accept Bitcoin, Bitcoin Cash, Litecoin, Dogecoin, Dash, etc Payments on Y …
Content Shelf Shopping Cart
content-shelf-shopping-cart
Content Shelf is shopping cart software for selling digital content, tangible products, services, subscriptions and gift cards.
Name: WP e-Commerce Popular Products Developer Profile
19 plugins · 2K total installs
How We Detect Name: WP e-Commerce Popular Products
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-e-commerce-popular-products/style.css/wp-content/plugins/wp-e-commerce-popular-products/script.js/wp-content/plugins/wp-e-commerce-popular-products/script.jswp-e-commerce-popular-products/style.css?ver=wp-e-commerce-popular-products/script.js?ver=HTML / DOM Fingerprints
widget_wpsc_popular_productsid="wpsc_popular_products-number"name="wpsc_popular_products-number"id="wpsc_popular_products-show_description"name="wpsc_popular_products-show_description"id="wpsc_popular_products-show_thumbnails"name="wpsc_popular_products-show_thumbnails"+4 moreWP_Widget_Popular_Products