WPC Brands for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wpc-brands

WPC Brands allows you to manage product brands in the easiest.

400 active installs v2.0.3 PHP + WP 4.0+ Updated Dec 11, 2025
brandswoocommercewpc
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPC Brands for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

WPC Brands for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "wpc-brands" v2.0.3 plugin exhibits a generally strong security posture based on the static analysis. The absence of any recorded CVEs and the apparent commitment to secure coding practices like using prepared statements for all SQL queries and a high percentage of properly escaped output are positive indicators. The plugin also incorporates a reasonable number of nonce and capability checks, and importantly, has no unprotected entry points into its attack surface. This suggests the developers have a good understanding of WordPress security principles.

However, the presence of three instances of the `unserialize` function is a notable concern. While no specific taint flows were identified as unsanitized, `unserialize` is inherently risky if not handled with extreme care, as it can lead to Remote Code Execution (RCE) if it processes untrusted data. The static analysis did not reveal any critical or high severity taint flows, which is reassuring, but the potential for exploitation remains a risk factor, especially if external data sources are involved. The plugin's vulnerability history is clean, indicating good maintenance and potentially a low exposure, but this does not negate the inherent risk of using potentially unsafe functions. Overall, the plugin is well-developed from a security standpoint, but the `unserialize` usage warrants careful review and potentially mitigation strategies to ensure it's not processing user-controlled input without robust validation.

Key Concerns

  • Use of unserialize function
Vulnerabilities
None known

WPC Brands for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPC Brands for WooCommerce Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
0 prepared
Unescaped Output
30
171 escaped
Nonce Checks
7
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

Dangerous Functions Found

unserialize$plugins = unserialize( $response['body'] );includes\dashboard\wpc-dashboard.php:111
unserialize$plugins = unserialize( $response['body'] );includes\dashboard\wpc-dashboard.php:189
unserialize$plugins = unserialize( $response['body'] );includes\kit\wpc-kit.php:98

Output Escaping

85% escaped201 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
ajax_export (includes\dashboard\wpc-dashboard.php:225)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WPC Brands for WooCommerce Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 5

authwp_ajax_wpc_get_pluginsincludes\dashboard\wpc-dashboard.php:19
authwp_ajax_wpc_get_suggestionincludes\dashboard\wpc-dashboard.php:20
authwp_ajax_wpc_exportincludes\dashboard\wpc-dashboard.php:21
authwp_ajax_wpc_importincludes\dashboard\wpc-dashboard.php:22
authwp_ajax_wpc_get_essential_kitincludes\kit\wpc-kit.php:22

Shortcodes 3

[wpcbr] wpc-brands.php:121
[wpcbr_banner] wpc-brands.php:122
[wpcbr_list] wpc-brands.php:123
WordPress Hooks 41
actionadmin_enqueue_scriptsincludes\dashboard\wpc-dashboard.php:17
actionadmin_menuincludes\dashboard\wpc-dashboard.php:18
actionbefore_woocommerce_initincludes\hpos.php:7
actionadmin_enqueue_scriptsincludes\kit\wpc-kit.php:20
actionadmin_menuincludes\kit\wpc-kit.php:21
actionplugins_loadedwpc-brands.php:37
actionadmin_noticeswpc-brands.php:41
actioninitwpc-brands.php:65
actionwoocommerce_initwpc-brands.php:66
actionwidgets_initwpc-brands.php:67
actionadmin_initwpc-brands.php:70
actionadmin_menuwpc-brands.php:71
actionadmin_enqueue_scriptswpc-brands.php:74
actionwp_enqueue_scriptswpc-brands.php:77
filterplugin_action_linkswpc-brands.php:80
filterplugin_row_metawpc-brands.php:81
actionwpc-brand_add_form_fieldswpc-brands.php:84
actionwpc-brand_edit_form_fieldswpc-brands.php:85
actionedit_wpc-brandwpc-brands.php:86
actioncreate_wpc-brandwpc-brands.php:87
filtermanage_edit-wpc-brand_columnswpc-brands.php:88
filtermanage_wpc-brand_custom_columnwpc-brands.php:89
filterwoocommerce_product_filterswpc-brands.php:92
actionwoocommerce_archive_descriptionwpc-brands.php:95
filterwoocommerce_product_tabswpc-brands.php:99
filterwpcsm_locationswpc-brands.php:103
actionwoocommerce_before_shop_loop_itemwpc-brands.php:130
actionwoocommerce_shop_loop_item_titlewpc-brands.php:133
actionwoocommerce_shop_loop_item_titlewpc-brands.php:136
actionwoocommerce_after_shop_loop_item_titlewpc-brands.php:139
actionwoocommerce_after_shop_loop_item_titlewpc-brands.php:142
actionwoocommerce_after_shop_loop_itemwpc-brands.php:145
actionwoocommerce_after_shop_loop_itemwpc-brands.php:148
actionwoocommerce_single_product_summarywpc-brands.php:157
actionwoocommerce_single_product_summarywpc-brands.php:160
actionwoocommerce_single_product_summarywpc-brands.php:163
actionwoocommerce_single_product_summarywpc-brands.php:166
actionwoocommerce_single_product_summarywpc-brands.php:169
actionwoocommerce_single_product_summarywpc-brands.php:172
actionwoocommerce_single_product_summarywpc-brands.php:175
actionwoocommerce_single_product_summarywpc-brands.php:178
Maintenance & Trust

WPC Brands for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings3
Active installs400
Developer Profile

WPC Brands for WooCommerce Developer Profile

WPClever

71 plugins · 441K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
68 days
View full developer profile
Detection Fingerprints

How We Detect WPC Brands for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpc-brands/assets/css/backend.css/wp-content/plugins/wpc-brands/assets/css/frontend.css/wp-content/plugins/wpc-brands/assets/js/backend.js/wp-content/plugins/wpc-brands/assets/js/frontend.js
Script Paths
/wp-content/plugins/wpc-brands/assets/js/backend.js/wp-content/plugins/wpc-brands/assets/js/frontend.js
Version Parameters
wpc-brands/assets/css/backend.css?ver=wpc-brands/assets/css/frontend.css?ver=wpc-brands/assets/js/backend.js?ver=wpc-brands/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpc-brands-logowpc-brands-listwpc-brands-itemwpc-brands-titlewpc-brands-linkwpc-brands-attribute
Data Attributes
data-wpcbr-id
JS Globals
wpc_brands_params
Shortcode Output
[wpcbr][wpcbr_banner][wpcbr_list]
FAQ

Frequently Asked Questions about WPC Brands for WooCommerce