Commerce APIs expose structured access to products, orders, customers, and store operations. A compatibility plugin that restores legacy endpoints must enforce authentication and permissions consistently across every request. WooCommerce Legacy REST API version 1.0.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64680, confirming that the plugin was reviewed from a secure code perspective with attention to API authentication, request authorization, object access, input parsing, response data, and legacy endpoint behavior.
| Name of | WooCommerce Legacy REST API |
| Version | 1.0.5 |
| Active installations | 400,000+ |
| Description | Restores the WooCommerce Legacy REST API functionality for WooCommerce versions where it is no longer included in core. |
| Security | Successfully tested for: SQL Injection (SQLi) Cross-Site Scripting (XSS) – Stored and Reflected Cross-Site Request Forgery (CSRF) Authentication Vulnerabilities Authentication Bypass Exploits Privilege Escalation Buffer Overflow Denial-of-Service (DoS) vectors Data Leakage Vulnerabilities Insecure Dependency Usage Remote Code Execution (RCE) Risks Unauthorized File Access Insufficient Injection Protection Information Disclosure via Misconfigured Endpoints |
| CleanTalk Certification | Proudly earned the “Plugin Security Certification” (PSC) from CleanTalk, indicating adherence to stringent security standards. |
| Additional Information | Use WooCommerce Legacy REST API with confidence backed by the “Plugin Security Certification” (PSC). Keep API credentials private, review active integrations, and migrate to current WooCommerce APIs when compatibility permits. |
| Plugin Security Certification by CleanTalk | ![]() |
| Logo of the plugin |
PSC by CleantalkJoin the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Key Features
WooCommerce Legacy REST API restores the legacy WooCommerce REST API for sites and integrations that still depend on it. The plugin brings legacy request handling back into WooCommerce 9.0 and later installations. Its endpoints can interact with store objects and integration credentials, so authentication, object permissions, request parsing, and response filtering remain central to safe operation.
Security Assurance
The CleanTalk Plugin Security Certification evaluation focused on API authentication, signature and credential handling, authorization for commerce objects, and validation of request parameters. The review also considered object identifiers, error responses, exposure of order or customer data, write operations, and the compatibility boundary between legacy clients and current WooCommerce behavior.
The plugin has been successfully tested for:
✅ Information Leakage Vulnerabilities
✅ SQL Injection Vulnerabilities
✅ Cross-Site Scripting (XSS) Attacks
✅ Cross-Site Request Forgery (CSRF) Attacks
✅ Authentication and Authentication Bypass Vulnerabilities
✅ Privilege Escalation Vulnerabilities
✅ Buffer Overflow Vulnerabilities
✅ Denial-of-Service (DoS) Vulnerabilities
✅ Data Leakage Vulnerabilities
✅ Insecure Dependencies
✅ Code Execution Vulnerabilities
✅ File Unauthorized Access Vulnerabilities
✅ Insufficient Injection Protection
Conclusion
With PSC-2026-64680, WooCommerce Legacy REST API version 1.0.5 demonstrates strong baseline security for restored legacy commerce API workflows. The certification addresses the sensitive boundaries around credentials, object permissions, request parsing, and store data returned through legacy endpoints. Store owners should keep an inventory of active API clients, rotate credentials when access changes, and plan migration to current interfaces where practical.
Note: The date and certification information may change over time. It is advisable to verify the latest details on the plugin developer’s website.
