ZILI User Products for WooCommerce Security & Risk Analysis

wordpress.org/plugins/zili-user-products-for-woocommerce

Let users add new WooCommerce products from frontend.

0 active installs v2.0.2 PHP + WP 5.0+ Updated Jan 2, 2026
ecommerceuser-productswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ZILI User Products for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

ZILI User Products for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "zili-user-products-for-woocommerce" v2.0.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for all SQL queries, and a high percentage of properly escaped output indicate good coding practices. The plugin also demonstrates a commitment to security by including nonce checks, which help prevent cross-site request forgery attacks. Furthermore, the lack of any known CVEs, historically or currently, is a very positive sign, suggesting a mature and well-maintained codebase. The limited attack surface, consisting only of two shortcodes, with no identified vulnerabilities or unsanitized taint flows, further reinforces its security. However, it's worth noting the complete absence of capability checks. While not a direct vulnerability in this specific analysis, it could represent a potential oversight if the shortcodes handle sensitive user data or operations. Overall, this plugin appears to be a secure option, with its strengths significantly outweighing any minor concerns.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

ZILI User Products for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ZILI User Products for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
20 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped22 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
wc_user_products_add_new (includes\class-alg-wc-user-products-shortcode-add-new.php:531)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ZILI User Products for WooCommerce Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[zili_wc_user_products_add_new] includes\class-alg-wc-user-products-shortcode-add-new.php:123
[zili_wc_user_products_list] includes\class-alg-wc-user-products-shortcodes.php:24
WordPress Hooks 13
actionalg_wc_user_products_after_save_settingsincludes\class-alg-wc-user-products-my-account.php:34
filterquery_varsincludes\class-alg-wc-user-products-my-account.php:40
actioninitincludes\class-alg-wc-user-products-my-account.php:47
filterwoocommerce_account_menu_itemsincludes\class-alg-wc-user-products-my-account.php:53
actionwoocommerce_account_alg-wc-my-products_endpointincludes\class-alg-wc-user-products-my-account.php:59
filterthe_titleincludes\class-alg-wc-user-products-my-account.php:65
actioninitincludes\class-alg-wc-user-products.php:74
actionbefore_woocommerce_initincludes\class-alg-wc-user-products.php:78
filterwoocommerce_get_settings_pagesincludes\class-alg-wc-user-products.php:156
actionadmin_initincludes\class-alg-wc-user-products.php:163
filterwoocommerce_get_sections_alg_wc_user_productsincludes\settings\class-alg-wc-user-products-settings-section.php:40
actionadmin_noticesincludes\settings\class-alg-wc-user-products-settings.php:87
actionplugins_loadedzili-user-products-for-woocommerce.php:58
Maintenance & Trust

ZILI User Products for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 2, 2026
PHP min version
Downloads122

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ZILI User Products for WooCommerce Developer Profile

Algoritmika

14 plugins · 510 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZILI User Products for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zili-user-products-for-woocommerce/assets/css/alg-wc-user-products-frontend.css/wp-content/plugins/zili-user-products-for-woocommerce/assets/js/alg-wc-user-products-frontend.js
Script Paths
/wp-content/plugins/zili-user-products-for-woocommerce/assets/js/alg-wc-user-products-frontend.js
Version Parameters
zili-user-products-for-woocommerce/assets/css/alg-wc-user-products-frontend.css?ver=zili-user-products-for-woocommerce/assets/js/alg-wc-user-products-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
alg-wc-user-products-add-new-formalg-wc-user-products-add-new-product-title
HTML Comments
<!-- ZILI User Products for WooCommerce - Shortcode Class --><!-- ZILI User Products for WooCommerce - Frontend script --><!-- ZILI User Products for WooCommerce - Frontend style -->
Data Attributes
data-alg_wc_user_products_product_type
JS Globals
alg_wc_user_products_frontend_params
Shortcode Output
[zili_wc_user_products_add_new]
FAQ

Frequently Asked Questions about ZILI User Products for WooCommerce