WPB Related Products Slider for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wpb-woocommerce-related-products-slider

Replace the default WooCommerce related products with a responsive, dynamic slider to boost product engagement and conversions.

1K active installs v1.9 PHP + WP 5.0+ Updated Mar 13, 2026
custom-related-productsproducts-sliderrelated-productsrelated-products-sliderwoocommerce-related-products
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPB Related Products Slider for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

WPB Related Products Slider for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The "wpb-woocommerce-related-products-slider" plugin version 1.9 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and appears to have no known vulnerabilities in its history. The attack surface is also minimal, with only one shortcode identified as an entry point and no AJAX handlers or REST API routes without authentication checks. However, significant concerns arise from the static code analysis. The presence of the dangerous `create_function` function is a critical security risk, as it can lead to arbitrary code execution if misused or if its input is not strictly controlled. Furthermore, a substantial portion of output (55%) is not properly escaped, which opens the door to Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on its entry points, even if limited, represents a missed opportunity for robust access control and protection against certain types of attacks.

While the lack of known CVEs and taint analysis findings is encouraging, the identified code signals of `create_function` and insufficient output escaping are serious flaws that require immediate attention. The plugin's strengths lie in its minimal attack surface and secure SQL handling, but these are overshadowed by the potential for code execution and XSS due to improper output sanitization and the use of a deprecated, insecure function. A balanced conclusion is that while the plugin currently has no recorded vulnerabilities, the static analysis reveals critical weaknesses that could be exploited, particularly the `create_function` and unescaped output.

Key Concerns

  • Dangerous function create_function found
  • Insufficient output escaping (45% properly escaped)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WPB Related Products Slider for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPB Related Products Slider for WooCommerce Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
18
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_function$callback = create_function('', 'echo "'.str_replace('"', '\"', $section['desc']).'";');admin\class.settings-api.php:108

Output Escaping

45% escaped33 total outputs
Attack Surface

WPB Related Products Slider for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpb_wrps_related_products] inc\wpb-wrps-functions.php:108
WordPress Hooks 14
actionadmin_enqueue_scriptsadmin\class.settings-api.php:30
actionadmin_initadmin\settings-config.php:24
actionadmin_menuadmin\settings-config.php:25
actionwpinc\wpb-wrps-filter.php:12
actionwoocommerce_after_single_product_summaryinc\wpb-wrps-filter.php:25
actionwpb_wrps_settings_contentinc\wpb-wrps-functions.php:151
actionwp_enqueue_scriptsinc\wpb-wrps-scripts.php:20
actionwp_enqueue_scriptsinc\wpb-wrps-scripts.php:32
actionadmin_enqueue_scriptsinc\wpb-wrps-scripts.php:45
actionadmin_noticesmain.php:46
actionactivated_pluginmain.php:62
actionadmin_noticesmain.php:155
actionadmin_initmain.php:156
actionplugins_loadedmain.php:164
Maintenance & Trust

WPB Related Products Slider for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version
Downloads50K

Community Trust

Rating94/100
Number of ratings12
Active installs1K
Developer Profile

WPB Related Products Slider for WooCommerce Developer Profile

WPBean

25 plugins · 40K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
20 days
View full developer profile
Detection Fingerprints

How We Detect WPB Related Products Slider for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpb-woocommerce-related-products-slider/css/wpb-wrps-frontend.css/wp-content/plugins/wpb-woocommerce-related-products-slider/css/slick.css/wp-content/plugins/wpb-woocommerce-related-products-slider/css/slick-theme.css/wp-content/plugins/wpb-woocommerce-related-products-slider/js/wpb-wrps-frontend.js/wp-content/plugins/wpb-woocommerce-related-products-slider/js/slick.min.js
Script Paths
/wp-content/plugins/wpb-woocommerce-related-products-slider/js/wpb-wrps-frontend.js/wp-content/plugins/wpb-woocommerce-related-products-slider/js/slick.min.js
Version Parameters
wpb-woocommerce-related-products-slider/css/wpb-wrps-frontend.css?ver=wpb-woocommerce-related-products-slider/css/slick.css?ver=wpb-woocommerce-related-products-slider/css/slick-theme.css?ver=wpb-woocommerce-related-products-slider/js/wpb-wrps-frontend.js?ver=wpb-woocommerce-related-products-slider/js/slick.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpb-wrps-container
Data Attributes
data-slick
JS Globals
wpb_wrps_frontend_params
FAQ

Frequently Asked Questions about WPB Related Products Slider for WooCommerce