
WPC Shop as a Customer for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wpc-shop-as-customerWPC Shop as a Customer allows store administrators to login as a customer on the frontend.
Is WPC Shop as a Customer for WooCommerce Safe to Use in 2026?
Generally Safe
Score 97/100WPC Shop as a Customer for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "wpc-shop-as-customer" plugin v1.3.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped outputs. The presence of nonce checks and capability checks on its 11 AJAX handlers is also encouraging, and the absence of exposed REST API routes, shortcodes, or cron events limits its external attack surface. However, the static analysis reveals a significant concern: the presence of the `unserialize` function, which is inherently risky if not handled with extreme care. While the taint analysis did not identify critical or high severity unsanitized paths, the potential for deserialization vulnerabilities is a known weakness based on past CVEs. The plugin's history of two high severity CVEs, specifically related to "Deserialization of Untrusted Data" and "Use of Insufficiently Random Values," strongly suggests that deserialization vulnerabilities have been a recurring issue. Although there are currently no unpatched CVEs, this historical pattern indicates a past susceptibility that requires diligent monitoring and secure implementation when handling serialized data. The current version appears to have addressed past vulnerabilities, but the inherent risk of `unserialize` remains.
Key Concerns
- Dangerous function: unserialize used
- Past high severity CVEs (Deserialization, Insufficient Randomness)
WPC Shop as a Customer for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key
WPC Shop as a Customer for WooCommerce <= 1.2.6 - Authenticated (Subscriber+) PHP Object Injection
WPC Shop as a Customer for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WPC Shop as a Customer for WooCommerce Attack Surface
AJAX Handlers 11
WordPress Hooks 18
Maintenance & Trust
WPC Shop as a Customer for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WPC Shop as a Customer for WooCommerce Alternatives
Feedback Company
the-feedback-company
This plugin integrates Feedback Company review widgets and order registration into Wordpress/WooCommerce
WPC Shoppable Images for WooCommerce
wpc-shoppable-images
WPC Shoppable Images is impressively a versatile, multipurpose, and powerful plugin, which helps you increase your sales by creating shoppable images.
Shop UX Toolkit
shop-ux-toolkit
Free WooCommerce plugin transforms a stock Storefront shop into an eCommerce site with premium features like Facebook/Instagram integration and more.
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
WPC Smart Quick View for WooCommerce
woo-smart-quick-view
WPC Smart Quick View allows users to get a quick look at products without opening the product page.
WPC Shop as a Customer for WooCommerce Developer Profile
71 plugins · 441K total installs
How We Detect WPC Shop as a Customer for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpc-shop-as-customer/assets/css/frontend.css/wp-content/plugins/wpc-shop-as-customer/assets/js/frontend.js/wp-content/plugins/wpc-shop-as-customer/assets/js/frontend.jswpc-shop-as-customer/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wpcsa-barwpcsa-backwpcsa-choosewpcsa-search-wrapwpcsa-search-innerwpcsa-search-formwpcsa-search-closewpcsa-search-user-itemdata-iddata-keywpcsa_vars