
Add Product To Cart Via URL Security & Risk Analysis
wordpress.org/plugins/add-product-to-cart-via-urlAllows a CMS users (eg shop admin) to create a URL (for WooCommerce only) with specific product(s) and quantity info. When clicked by a user this URL …
Is Add Product To Cart Via URL Safe to Use in 2026?
Generally Safe
Score 85/100Add Product To Cart Via URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "add-product-to-cart-via-url" v2.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, exclusively using prepared statements, and has no recorded vulnerabilities or known CVEs. This suggests a generally well-maintained codebase.
However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks, presenting a considerable attack surface. Furthermore, the absence of nonce checks on these AJAX endpoints is a critical oversight, potentially allowing for Cross-Site Request Forgery (CSRF) attacks. While taint analysis did not reveal any immediate threats, the lack of sanitization and capability checks on entry points is worrying and could lead to unforeseen vulnerabilities when combined with external data.
In conclusion, while the plugin's history of security is commendable, the current version has clear, exploitable weaknesses in its AJAX handling. The lack of authentication and nonce checks on two entry points represents a direct risk to WordPress installations using this plugin. Developers should prioritize addressing these critical security gaps to improve the plugin's overall security.
Key Concerns
- AJAX handlers without authentication
- Missing nonce checks on AJAX
- No capability checks on entry points
- 72% properly escaped output
Add Product To Cart Via URL Security Vulnerabilities
Add Product To Cart Via URL Code Analysis
Output Escaping
Add Product To Cart Via URL Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Add Product To Cart Via URL Maintenance & Trust
Maintenance Signals
Community Trust
Add Product To Cart Via URL Alternatives
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Mollie Payments for WooCommerce
mollie-payments-for-woocommerce
Accept all major payment methods in WooCommerce today. Credit cards, iDEAL and more! Fast, safe and intuitive.
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
Mercado Pago payments for WooCommerce
woocommerce-mercadopago
Offer to your clients the best experience in e-Commerce by using Mercado Pago as your payment method.
WPML Multilingual & Multicurrency for WooCommerce
woocommerce-multilingual
Make your store multilingual and enable multiple currencies.
Add Product To Cart Via URL Developer Profile
1 plugin · 0 total installs
How We Detect Add Product To Cart Via URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-product-to-cart-via-url/assets/css/wcad.css/wp-content/plugins/add-product-to-cart-via-url/assets/js/wcad.jsadd-product-to-cart-via-url/assets/css/wcad.css?ver=add-product-to-cart-via-url/assets/js/wcad.js?ver=HTML / DOM Fingerprints
csetRowprod_qty_setprod_url_selectprod_url_qtywcad_remove_inputdata-indexdata-searchdata-childrendata-variationsdata-namedata-attributevalue+1 morewcad_producturlform_ajax_obj<form<select id="wcad_prod_url_select_<input placeholder="Quantity" type="number"<a href="#" class="wcad_remove_input"