WPSSO Schema Product Metadata for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wpsso-wc-metadata

MPN, ISBN, GTIN-8, UPC, EAN, GTIN-14, net dimensions, and fluid volume for better WooCommerce Schema markup.

600 active installs v6.0.0 PHP 7.4.33+ WP 6.0+ Updated Mar 11, 2026
eanisbnmpnschemaupc
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPSSO Schema Product Metadata for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

WPSSO Schema Product Metadata for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 24d ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the wpsso-wc-metadata plugin v6.0.0 exhibits a strong security posture. The absence of any detected dangerous functions, unsanitized taint flows, direct SQL queries, file operations, external HTTP requests, or output escaping issues is highly commendable. Furthermore, the plugin demonstrates a commitment to security by not exposing a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events identified. The complete lack of known CVEs and historical vulnerabilities reinforces this positive assessment, suggesting a well-maintained and secure codebase.

However, it's important to note the complete absence of any identified security checks like nonce or capability checks in the static analysis. While the current attack surface is zero, meaning there are no immediate exploitable entry points lacking these checks, this could indicate a general lack of defensive programming patterns. Should the plugin's functionality expand in the future and introduce new entry points without these checks, it could present a security risk. The reliance on an undeveloped attack surface for its current security is a weakness. In conclusion, the plugin is currently very secure due to its minimal exposure and lack of known issues, but a review of defensive coding practices for future development would be beneficial.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

WPSSO Schema Product Metadata for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPSSO Schema Product Metadata for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WPSSO Schema Product Metadata for WooCommerce Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

WPSSO Schema Product Metadata for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4.33
Downloads34K

Community Trust

Rating96/100
Number of ratings16
Active installs600
Developer Profile

WPSSO Schema Product Metadata for WooCommerce Developer Profile

JS Morisset

31 plugins · 33K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
12 days
View full developer profile
Detection Fingerprints

How We Detect WPSSO Schema Product Metadata for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpsso-wc-metadata/lib/js/wpsso-wc-metadata.js
Script Paths
/wp-content/plugins/wpsso-wc-metadata/lib/js/wpsso-wc-metadata.js
Version Parameters
wpsso-wc-metadata/lib/js/wpsso-wc-metadata.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- WPSSO WC Metadata -->
Data Attributes
data-wcmd-gpcdata-wcmd-gtindata-wcmd-mpndata-wcmd-sku
JS Globals
WpssoWcMetadata
FAQ

Frequently Asked Questions about WPSSO Schema Product Metadata for WooCommerce