Plugin Pulse
← Pulse

WooCommerce

by Automattic · eCommerce

Also makes 68 other plugins · 18.2M+ installs across the portfolio →

Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.

How scoring works →
93 Health · A
Maintenance 100/100
Rating quality 89/100
Support 86/100

93 health vs 68 average across 5,561 eCommerce plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

95 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 90/100
Listing tuning 100/100
Support resolution 80/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

+4% vs prior 30d
65.6KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

5.0M

now · peak 11.6M

5.01M30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

WooCommerce · #6 you Simple Shopping Cart · #1819 Ecwid by Lightspeed · #1230

Rating trend

Star average over time · dips mark rough releases

4.5Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

715per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

132

releases in the last 12 months

1mo ago

latest release · v11.0.0-beta.1

636

tagged releases on record

Recent releases

11.0.0-beta.1 · 1mo ago10.9.4 · 2mo ago10.9.3 · 2mo ago10.9.2 · 2mo ago10.9.1 · 2mo ago10.9.0 · 2mo ago10.9.0-rc.1 · 2mo ago10.9.0-beta.2 · 2mo ago10.9.0-beta.1 · 3mo ago10.8.1 · 3mo ago10.8.0 · 3mo ago10.8.0-rc.1 · 3mo ago10.8.0-beta.2 · 4mo ago10.8.0-beta.1 · 4mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v10.9 30%
v10.7 13%
v10.8 7%
v10.3 5.5%
Older / other versions 45%

Estimated active installs

The public count shows “7M+”. Our estimate pins where the real number sits.

tracked estimate
7M–8M ≈7.9M

Refined from the date this plugin crossed into its current band.

Install history · since 2015-05-14 · 1,491 observations

7MInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

high confidence

Est. annual revenue

≈$5.1M range $1.5M–$17M

Est. acquisition value

≈$14M range $3M–$68M

A large install base, a clear pro tier and a steady trend. As reliable as an outside estimate gets. The range spans more than 10x because wp.org publishes install counts as broad bands, and conversion and price compound on top. Read the midpoint as an order of magnitude, not a valuation.

How we estimate this

Assumptions

  • Free → paid conversion. 0.5%–2% of active installs pay for the pro tier. Typical for freemium WordPress plugins; the real rate varies a lot by product. Past 1M installs we taper the rate down: a giant free plugin’s long tail converts far worse.
  • Annual price per customer. $79–$199 a year, typical for eCommerce plugins rather than this plugin's own pricing.
  • Acquisition multiple. 2x–4x annual revenue, the going range for small WordPress-plugin businesses, the typical range for a steady plugin.
  • Install base. 7M–8M active installs, from our install estimate (wp.org only publishes the floor).

Inputs

Active installs
7M–8M
Category
eCommerce
Pro tier
detected (known freemium plugin with a public paid tier)
Download trend
steady (30d downloads flat vs prior 30d)
Reviews
4,819
Last updated
15 days ago

Revenue is installs × conversion × price; value is revenue × a typical acquisition multiple. Every factor is an assumption band, so the output is a wide range on purpose. If you're buying or selling, treat this as a starting point for due diligence.

Details

Version
11.0.1
Last updated
15d ago
Added
2011-09-27 · 14 yrs old
Requires WP
6.9
Tested up to
7.0.4
Requires PHP
7.4

Recent review vibe

read from the latest 12 reviews to 2026-07-15
Positive PraiseBroken updates

Reviewers mostly praise WooCommerce's support team for fast, helpful replies, with one recent complaint about updates that don't fix existing bugs.

Recent reviews

All reviews on wp.org ↗
  1. louisenglish1990
    1mo ago

    Absolutley excellent feedback, I spoke with our admin team and there was a filter applied in the background that was not allowing me to search. Thank you for all of your help

    Read on wp.org ↗
  2. jimk1416
    2mo ago

    very quick and reliable support if you have any issues

    Read on wp.org ↗
  3. wopodk
    2mo ago

    Extremely helpful and fast support.Greatly appreciated!

    Read on wp.org ↗
  4. marco4422
    2mo ago

    Woocommerce offers a great support team, the can help you if you have any trouble or issue with wordpress or woocommerce. They answer in short time, in my case in 1 days. 5 stars

    Read on wp.org ↗
  5. icpte2024
    2mo ago

    Thanks Frank Remmy for his support on 25/05/2026 for our issue!

    Read on wp.org ↗
  6. cllamsupport
    2mo ago

    Great Plugin

    Read on wp.org ↗
  7. krakanosh
    2mo ago

    Плагин стабильно обновляется каждый месяц, а что в нем меняется – НИЧЕГО! Кроме мусорных функций или обновлений ради обновлений ничего не меняется. Баги не исправляются коих не малое количество, зато с лихвой заносятся новые. Десять раз подумайте прежде чем делать интернет-магазин на WooCommerce. Лучше использовать другой инструмент для создания магазина, благо сейчас их достаточное количество, в том числе open-source.

    Read on wp.org ↗
  8. Robby Barnes
    2mo ago

    I ran into a problem with my site that my theme’s developers weren’t able to help me solve, so I tried the WooCommerce support forum. Within a day I received a thoughtful, detailed response… which also gave me enough info to solve the problem. Much appreciated!

    Read on wp.org ↗

Latest updates

via official blog

Recent releases and news for this plugin

  1. 2026-08-18 WooCommerce 11.1: What’s coming for developers Pre-release notes for WooCommerce 11.1 have dropped! The REST API has a new refund endpoint, right of withdrawal is available for EU users, and variable products get some performance improvements! The 11.1
  2. 2026-08-18 Reserved item meta keys are no longer persisted in the admin In WooCommerce 11.0.0, reserved order item meta keys added via the Add meta button are no longer saved in the admin, preventing unstable behavior and keeping internal order data consistent. The post R
  3. 2026-08-10 WooCommerce 11.0.1 Release Notes WooCommerce 11.0.1 has been released with targeted fixes for security, WordPress 7.1 compatibility, Store API behavior, analytics validation, and logging performance. The post WooCommerce 11.0.1 Relea 11.0.1
  4. 2026-08-06 August Office Hours: WCUS and WooCommerce Foundations Join our August Developer Office Hours to compare notes from WordCamp US and discuss the first weeks of WooCommerce's renewed focus on core performance, reliability, extensibility, and developer exper
  5. 2026-08-06 Security update for Stripe for WooCommerce Please update Stripe for WooCommerce for the latest security update. The post Security update for Stripe for WooCommerce appeared first on The WooCommerce Developer Blog .
  6. 2026-08-06 Introducing Reconciliation Reports for WooPayments WooPayments is introducing Reconciliation Reports that explain how the balance moves from the start to the end of the specified period. The post Introducing Reconciliation Reports for WooPayments appe

Known vulnerabilities

via Wordfence Intelligence

44 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-03-10 CVE-2026-3589 Cross-Site Request Forgery (CSRF) Affects < 10.5.3 Patched in 10.5.3
  2. 2025-12-22 CVE-2025-15033 Exposure of Sensitive Information to an Unauthorized Actor Affects 10.0 - 10.0.4 Patched in 10.0.5
  3. 2025-10-29 CVE-2025-49042 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 10.0.2 Patched in 10.0.3
  4. 2025-05-21 CVE-2025-5062 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.3.2 Patched in 9.3.4
  5. 2025-03-12 CVE-2025-26762 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.7.0 Patched in 9.7.1
  6. 2024-10-14 CVE-2024-9944 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.0.2 Patched in 9.1.0
  7. 2024-08-16 CVE-2024-39666 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.1.2 Patched in 9.1.3
  8. 2024-06-27 CVE-2024-35777 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 8.9.2 Patched in 9.0.0
  9. 2024-06-10 CVE-2024-37297 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 8.8.0 - 8.8.4 Patched in 8.8.5
  10. 2024-04-05 CVE-2024-22155 Cross-Site Request Forgery (CSRF) Affects <= 8.5.2 Patched in 8.6.0
  11. 2024-01-12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 8.4.0 Patched in 8.4.0
  12. 2024-01-05 CVE-2023-52222 Cross-Site Request Forgery (CSRF) Affects <= 8.2.2 Patched in 8.3.0
  13. 2023-11-15 CVE-2023-47777 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.1.1 Patched in 8.2.0
  14. 2023-09-11 CVE-2023-7320 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 7.8.2 Patched in 7.9.0
  15. 2023-09-11 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 7.0.0 Patched in 7.0.1
  16. 2022-06-20 CVE-2022-2099 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 6.6.0 Patched in 6.6.0
  17. 2022-04-10 Exposure of Sensitive Information to an Unauthorized Actor Affects < 4.0 Patched in 4.0.3
  18. 2022-03-10 Missing Authorization Affects 3.5 - 3.5.10 Patched in 3.5.10
  19. 2022-02-22 CVE-2022-0775 Improper Authorization Affects <= 6.2.0 Patched in 6.2.1
  20. 2022-02-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 6.2.0 Patched in 6.2.1
  21. 2021-07-13 CVE-2021-32790 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.3 Patched in 3.3.6
  22. 2021-04-21 CVE-2021-24323 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 5.2.0 Patched in 5.2.0
  23. 2020-11-05 Missing Authorization Affects < 4.6.2 Patched in 4.6.2
  24. 2020-06-22 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.2.1 Patched in 4.2.1
  25. 2020-05-05 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.1.0 Patched in 4.1.0
  26. 2020-01-21 CVE-2020-29156 Authorization Bypass Through User-Controlled Key Affects < 4.7.0 Patched in 4.7.0
  27. 2019-07-02 Unrestricted Upload of File with Dangerous Type Affects <= 3.6.4 Patched in 3.6.5
  28. 2019-07-02 Cross-Site Request Forgery (CSRF) Affects < 3.6.5 Patched in 3.6.5
  29. 2019-02-20 CVE-2019-9168 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.5.5 Patched in 3.5.5
  30. 2018-11-29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.5.1 Patched in 3.5.2
  31. 2018-11-06 CVE-2018-20714 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects < 3.4.6 Patched in 3.4.6
  32. 2018-08-29 Deserialization of Untrusted Data Affects < 3.4.5 Patched in 3.4.5
  33. 2017-11-16 CVE-2017-18356 Improper Control of Generation of Code ('Code Injection') Affects < 3.2.4 Patched in 3.2.4
  34. 2016-12-07 CVE-2016-10112 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.6.9 Patched in 2.6.9
  35. 2016-07-26 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.6.4 Patched in 2.6.4
  36. 2016-07-19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.6.3 Patched in 2.6.3
  37. 2015-11-17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.4.9 Patched in 2.4.9
  38. 2015-06-10 Deserialization of Untrusted Data Affects <= 2.3.10 Patched in 2.3.11
  39. 2015-03-13 CVE-2015-2329 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.3.6 Patched in 2.3.6
  40. 2015-01-29 CVE-2015-2069 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.2.11 Patched in 2.2.11
  41. 2014-09-17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.2.3 Patched in 2.2.3
  42. 2014-09-15 CVE-2014-6313 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.2.3 Patched in 2.2.3
  43. 2013-10-17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.17 Patched in 2.0.18
  44. 2013-07-18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.0.12 Patched in 2.0.13

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 103 languages, 41 at 90% or more

Chinese (China) 100%
Czech 100%
Dutch 100%
Dutch (Formal) 100%
English (UK) 100%
French (France) 100%
German 100%
German (Formal) 100%
Hebrew 100%
Indonesian 100%
Italian 100%
Japanese 100%
Korean 100%
Norwegian (Bokmål) 100%
Polish 100%
Romanian 100%
Russian 100%
Spanish (Argentina) 100%
Spanish (Spain) 100%
Turkish 100%
Arabic 99%
Catalan 99%
Chinese (Taiwan) 99%
Kurdish (Sorani) 99%

Plus 79 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2025-06-20 8M+ → 7M+ down after 124 days in tier
  2. 2025-02-16 7M+ → 8M+ up after 26 days in tier
  3. 2025-01-21 8M+ → 7M+ down after 90 days in tier
  4. 2024-10-23 7M+ → 8M+ up after 152 days in tier
  5. 2024-05-24 5M+ → 7M+ up

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for WooCommerce into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/woocommerce" width="480" height="300" style="border:0" loading="lazy" title="WooCommerce — Plugin Pulse"></iframe>
Preview card ↗

WooCommerce: 7M+ active installs, 4.5★ (4,819 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/woocommerce