WP e-Commerce Related Products Security & Risk Analysis

wordpress.org/plugins/wpec-related-products

WPEC Related Products for WP e-Commerce uses information available within the Single Product template to display related Products.

70 active installs v1.3.2 PHP + WP 3.0+ Updated Nov 21, 2012
specwp-e-commercewpsc-related-products
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP e-Commerce Related Products Safe to Use in 2026?

Generally Safe

Score 85/100

WP e-Commerce Related Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "wpec-related-products" v1.3.2 plugin exhibits a strong security posture in several key areas, notably the absence of known vulnerabilities and the complete reliance on prepared statements for its SQL queries. The plugin also reports zero external HTTP requests, file operations, and no reported CVEs, indicating a generally well-maintained and secure codebase. However, the static analysis reveals a significant weakness: 0% of its 24 output operations are properly escaped. This absence of output escaping presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as malicious data could be injected and rendered directly in the user's browser without proper sanitization. While the plugin has no reported vulnerability history, the lack of output escaping is a critical concern that could be easily exploited if user-supplied data is ever incorporated into these output streams.

Key Concerns

  • 0% of outputs properly escaped
Vulnerabilities
None known

WP e-Commerce Related Products Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP e-Commerce Related Products Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped24 total outputs
Attack Surface

WP e-Commerce Related Products Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterwpsc_additional_pageswpec-related-product.php:15
actionwp_headwpec-related-product.php:159
actioninitwpec-related-product.php:167
Maintenance & Trust

WP e-Commerce Related Products Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedNov 21, 2012
PHP min version
Downloads16K

Community Trust

Rating100/100
Number of ratings4
Active installs70
Developer Profile

WP e-Commerce Related Products Developer Profile

Onnay Okheng

4 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP e-Commerce Related Products

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpec-related-products/wpec-related-product.php

HTML / DOM Fingerprints

CSS Classes
wpec-related-wrapwpec-related-productwpec-related-imagewpec-related-title
Data Attributes
id="related-pro-id="product_image_
Shortcode Output
<div class='wpec-related-wrap'><h2>Related Products</h2><div class='wpec-related-product product-<div class='wpec-related-image' id='related-pro-
FAQ

Frequently Asked Questions about WP e-Commerce Related Products