- Active installations
- 6 million+
- WordPress.org status
- Active
- Known vulnerabilities
- Several, historically
- Open unresolved
- 0 in supported releases
- Last vulnerability
- Handled through the Automattic security programme
- PHP compatibility
- PHP 7.4+ supported
- Maintenance frequency
- Active — scheduled release cycle with security patches
Data reviewed August 2026. Version numbers move weekly — the WordPress.org listing linked in the sidebar is always authoritative for the current release.
Current security status
WooCommerce is maintained by Automattic on a scheduled release cycle with a formal security programme and backported patches for supported branches. WPDeeply rates it LOW risk.
Where the real risk is
For a WooCommerce store, the core plugin is rarely the weak point. The weak points are the extensions: payment gateways, shipping calculators, cart add-ons, subscription tools and marketing integrations, many maintained by small teams and distributed outside WordPress.org — which means no automatic update notifications.
Two entries from our archive make the point. Abandoned Cart Lite ≤ 5.8.2 exposed customer names and email addresses through unauthenticated SQL injection — an add-on, not Woo. And WooCommerce before 4.1.0 is mostly a story about how quietly a security fix was described, and about the plugins that had copied the original pattern and were never fixed.
Store-specific checks
- Inventory every extension, including paid ones, and check each for maintenance and open issues.
- Premium extensions need a manual update routine — they will not appear in the WordPress updates screen.
- Keep PHP on a supported version; stores lag here more than blogs because owners fear breaking checkout.
- Remember that a store breach is a personal-data breach, with the notification duties that follow.
Recommendation
Keep WooCommerce updated and audit the extensions around it quarterly. A scan covers all of them at once, including the paid ones.