WooCommerce
by Automattic · eCommerce
Also makes 68 other plugins · 18.2M+ installs across the portfolio →
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
93 health vs 68 average across 5,561 eCommerce plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
5.0M
now · peak 11.6M
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
132
releases in the last 12 months
1mo ago
latest release · v11.0.0-beta.1
636
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “7M+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-05-14 · 1,491 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
A large install base, a clear pro tier and a steady trend. As reliable as an outside estimate gets. The range spans more than 10x because wp.org publishes install counts as broad bands, and conversion and price compound on top. Read the midpoint as an order of magnitude, not a valuation.
How we estimate this
Assumptions
- Free → paid conversion. 0.5%–2% of active installs pay for the pro tier. Typical for freemium WordPress plugins; the real rate varies a lot by product. Past 1M installs we taper the rate down: a giant free plugin’s long tail converts far worse.
- Annual price per customer. $79–$199 a year, typical for eCommerce plugins rather than this plugin's own pricing.
- Acquisition multiple. 2x–4x annual revenue, the going range for small WordPress-plugin businesses, the typical range for a steady plugin.
- Install base. 7M–8M active installs, from our install estimate (wp.org only publishes the floor).
Inputs
- Active installs
- 7M–8M
- Category
- eCommerce
- Pro tier
- detected (known freemium plugin with a public paid tier)
- Download trend
- steady (30d downloads flat vs prior 30d)
- Reviews
- 4,819
- Last updated
- 15 days ago
Revenue is installs × conversion × price; value is revenue × a typical acquisition multiple. Every factor is an assumption band, so the output is a wide range on purpose. If you're buying or selling, treat this as a starting point for due diligence.
Details
Recent review vibe
read from the latest 12 reviews to 2026-07-15Reviewers mostly praise WooCommerce's support team for fast, helpful replies, with one recent complaint about updates that don't fix existing bugs.
Recent reviews
All reviews on wp.org ↗- ★★★★★ louisenglish19901mo ago
Absolutley excellent feedback, I spoke with our admin team and there was a filter applied in the background that was not allowing me to search. Thank you for all of your help
Read on wp.org ↗ - ★★★★★ jimk14162mo ago
very quick and reliable support if you have any issues
Read on wp.org ↗ - ★★★★★ wopodk2mo ago
Extremely helpful and fast support.Greatly appreciated!
Read on wp.org ↗ - ★★★★★ marco44222mo ago
Woocommerce offers a great support team, the can help you if you have any trouble or issue with wordpress or woocommerce. They answer in short time, in my case in 1 days. 5 stars
Read on wp.org ↗ - ★★★★★ icpte20242mo ago
Thanks Frank Remmy for his support on 25/05/2026 for our issue!
Read on wp.org ↗ - ★★★★★ cllamsupport2mo ago
Great Plugin
Read on wp.org ↗ - ★★★★★ krakanosh2mo ago
Плагин стабильно обновляется каждый месяц, а что в нем меняется – НИЧЕГО! Кроме мусорных функций или обновлений ради обновлений ничего не меняется. Баги не исправляются коих не малое количество, зато с лихвой заносятся новые. Десять раз подумайте прежде чем делать интернет-магазин на WooCommerce. Лучше использовать другой инструмент для создания магазина, благо сейчас их достаточное количество, в том числе open-source.
Read on wp.org ↗ - ★★★★★ Robby Barnes2mo ago
I ran into a problem with my site that my theme’s developers weren’t able to help me solve, so I tried the WooCommerce support forum. Within a day I received a thoughtful, detailed response… which also gave me enough info to solve the problem. Much appreciated!
Read on wp.org ↗
Latest updates
via official blogRecent releases and news for this plugin
- 2026-08-18 WooCommerce 11.1: What’s coming for developers Pre-release notes for WooCommerce 11.1 have dropped! The REST API has a new refund endpoint, right of withdrawal is available for EU users, and variable products get some performance improvements! The 11.1
- 2026-08-18 Reserved item meta keys are no longer persisted in the admin In WooCommerce 11.0.0, reserved order item meta keys added via the Add meta button are no longer saved in the admin, preventing unstable behavior and keeping internal order data consistent. The post R
- 2026-08-10 WooCommerce 11.0.1 Release Notes WooCommerce 11.0.1 has been released with targeted fixes for security, WordPress 7.1 compatibility, Store API behavior, analytics validation, and logging performance. The post WooCommerce 11.0.1 Relea 11.0.1
- 2026-08-06 August Office Hours: WCUS and WooCommerce Foundations Join our August Developer Office Hours to compare notes from WordCamp US and discuss the first weeks of WooCommerce's renewed focus on core performance, reliability, extensibility, and developer exper
- 2026-08-06 Security update for Stripe for WooCommerce Please update Stripe for WooCommerce for the latest security update. The post Security update for Stripe for WooCommerce appeared first on The WooCommerce Developer Blog .
- 2026-08-06 Introducing Reconciliation Reports for WooPayments WooPayments is introducing Reconciliation Reports that explain how the balance moves from the start to the end of the specified period. The post Introducing Reconciliation Reports for WooPayments appe
Known vulnerabilities
via Wordfence Intelligence44 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 4.3 WooCommerce < 10.5.3 - Cross-Site Request Forgery ↗
- 2025-12-22 CVE-2025-15033 Exposure of Sensitive Information to an Unauthorized Actor Affects 10.0 - 10.0.4 Patched in 10.0.5
- 2025-10-29 CVE-2025-49042 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 10.0.2 Patched in 10.0.3
- 2025-05-21 CVE-2025-5062 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.3.2 Patched in 9.3.4
- 2025-03-12 CVE-2025-26762 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.7.0 Patched in 9.7.1
- 2024-10-14 CVE-2024-9944 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.0.2 Patched in 9.1.0
- 2024-08-16 CVE-2024-39666 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.1.2 Patched in 9.1.3
- 2024-06-27 CVE-2024-35777 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 8.9.2 Patched in 9.0.0
- 2024-06-10 CVE-2024-37297 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 8.8.0 - 8.8.4 Patched in 8.8.5
- Medium · 4.3 WooCommerce <= 8.5.2 - Cross-Site Request Forgery ↗
- 2024-01-12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 8.4.0 Patched in 8.4.0
- Medium · 4.3 WooCommerce <= 8.2.2 - Cross-Site Request Forgery ↗
- 2023-11-15 CVE-2023-47777 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.1.1 Patched in 8.2.0
- 2023-09-11 CVE-2023-7320 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 7.8.2 Patched in 7.9.0
- 2023-09-11 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 7.0.0 Patched in 7.0.1
- 2022-06-20 CVE-2022-2099 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 6.6.0 Patched in 6.6.0
- 2022-04-10 Exposure of Sensitive Information to an Unauthorized Actor Affects < 4.0 Patched in 4.0.3
- 2022-03-10 Missing Authorization Affects 3.5 - 3.5.10 Patched in 3.5.10
- 2022-02-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 6.2.0 Patched in 6.2.1
- 2021-07-13 CVE-2021-32790 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.3 Patched in 3.3.6
- 2021-04-21 CVE-2021-24323 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 5.2.0 Patched in 5.2.0
- Medium · 6.5 WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 - Settings Bypass leading to Account Creation ↗2020-11-05 Missing Authorization Affects < 4.6.2 Patched in 4.6.2
- 2020-06-22 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.2.1 Patched in 4.2.1
- 2020-05-05 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.1.0 Patched in 4.1.0
- 2020-01-21 CVE-2020-29156 Authorization Bypass Through User-Controlled Key Affects < 4.7.0 Patched in 4.7.0
- 2019-07-02 Unrestricted Upload of File with Dangerous Type Affects <= 3.6.4 Patched in 3.6.5
- 2019-07-02 Cross-Site Request Forgery (CSRF) Affects < 3.6.5 Patched in 3.6.5
- Medium · 6.1 WooCommerce <= 3.5.4 - Stored Cross-Site Scripting ↗2019-02-20 CVE-2019-9168 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.5.5 Patched in 3.5.5
- 2018-11-29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.5.1 Patched in 3.5.2
- 2018-11-06 CVE-2018-20714 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 3.4.6 Patched in 3.4.6
- 2018-08-29 Deserialization of Untrusted Data Affects < 3.4.5 Patched in 3.4.5
- 2017-11-16 CVE-2017-18356 Improper Control of Generation of Code ('Code Injection') Affects < 3.2.4 Patched in 3.2.4
- 2016-12-07 CVE-2016-10112 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.6.9 Patched in 2.6.9
- 2016-07-26 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.6.4 Patched in 2.6.4
- Medium · 6.4 WooCommerce <= 2.6.2 - Stored Cross-Site Scripting ↗2016-07-19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.6.3 Patched in 2.6.3
- Medium · 5.5 WooCommerce < 2.4.9 - Cross-site Scripting ↗2015-11-17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.4.9 Patched in 2.4.9
- 2015-06-10 Deserialization of Untrusted Data Affects <= 2.3.10 Patched in 2.3.11
- 2015-03-13 CVE-2015-2329 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.3.6 Patched in 2.3.6
- Medium · 6.1 WooCommerce <= 2.2.10 - Cross-Site Scripting ↗2015-01-29 CVE-2015-2069 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.2.11 Patched in 2.2.11
- 2014-09-17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.2.3 Patched in 2.2.3
- 2014-09-15 CVE-2014-6313 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.2.3 Patched in 2.2.3
- Medium · 6.1 WooCommerce <= 2.0.17 - Cross-Site Scripting ↗2013-10-17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.17 Patched in 2.0.18
- 2013-07-18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.12 Patched in 2.0.13
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 103 languages, 41 at 90% or more
Plus 79 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-06-20 8M+ → 7M+ down after 124 days in tier
- 2025-02-16 7M+ → 8M+ up after 26 days in tier
- 2025-01-21 8M+ → 7M+ down after 90 days in tier
- 2024-10-23 7M+ → 8M+ up after 152 days in tier
- 2024-05-24 5M+ → 7M+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Simple Shopping Cart 10K+ installs · 4.5★ · 4 shared tags A -
Ecwid by Lightspeed Ecommerce Shopping Cart 20K+ installs · 4.5★ · 3 shared tags A
-
BigCommerce For WordPress 300+ installs · 3.9★ · 3 shared tags C -
TI WooCommerce Wishlist 100K+ installs · 4.7★ · 2 shared tags A -
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments 80K+ installs · 4.7★ · 2 shared tags A -
StoreCustomizer – A plugin to Customize all WooCommerce Pages 20K+ installs · 4.7★ · 2 shared tags A
Embed this report card
Drop a live Pulse card for WooCommerce into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/woocommerce" width="480" height="300" style="border:0" loading="lazy" title="WooCommerce — Plugin Pulse"></iframe> WooCommerce: 7M+ active installs, 4.5★ (4,819 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/woocommerce