Add To Cart AI – The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search Security & Risk Analysis

wordpress.org/plugins/add-to-cart-ai

The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search

0 active installs v0.2.0 PHP 7.4+ WP 5.8+ Updated Feb 6, 2026
aiassistantcartshoppingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Add To Cart AI – The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search Safe to Use in 2026?

Generally Safe

Score 100/100

Add To Cart AI – The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

This plugin, add-to-cart-ai v0.2.0, exhibits a strong security posture based on the provided static analysis. All identified entry points, including AJAX handlers and REST API routes, appear to have authentication checks in place, which is a crucial security practice. The code also demonstrates excellent adherence to secure coding standards by exclusively using prepared statements for SQL queries and properly escaping all output, preventing common injection vulnerabilities. Furthermore, the absence of any known CVEs or recorded vulnerabilities in its history suggests a history of secure development and maintenance. The plugin also avoids common pitfalls like bundled libraries and file operations that can introduce risks.

However, there are a few areas that, while not showing immediate critical vulnerabilities in this analysis, represent potential weaknesses. The absence of capability checks on AJAX handlers and REST API routes means that while an authenticated user can access these endpoints, the plugin does not verify if that user has the specific permissions required for the actions performed. This could lead to privilege escalation if not handled carefully within the endpoint logic. Additionally, the presence of external HTTP requests, while not inherently insecure, introduces a dependency on external services, which could be a vector for attacks if those services are compromised or if the requests are not handled securely (e.g., lack of input validation before sending data). The plugin's limited version and lack of extensive vulnerability history also mean it hasn't been heavily scrutinized by the security community, so there might be undiscovered issues.

In conclusion, add-to-cart-ai v0.2.0 is currently in a good security state, with significant strengths in its use of prepared statements, output escaping, and authentication checks on its entry points. The absence of known vulnerabilities is a positive sign. The primary areas for caution are the lack of capability checks and the reliance on external HTTP requests, which warrant careful review of the specific implementation within those areas. The low version number also implies it's a relatively new plugin and might benefit from continued security scrutiny as it matures and its attack surface potentially grows.

Key Concerns

  • Missing capability checks on entry points
  • External HTTP requests present
Vulnerabilities
None known

Add To Cart AI – The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Add To Cart AI – The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
47 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

100% escaped47 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ajax_validate_license (admin\a2cai-admin-ajax.php:24)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Add To Cart AI – The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 5

authwp_ajax_a2cai_validate_licenseadmin\a2cai-admin-ajax.php:17
authwp_ajax_a2cai_start_product_loadadmin\a2cai-admin-ajax.php:18
authwp_ajax_a2cai_reset_setupadmin\a2cai-admin-ajax.php:19
authwp_ajax_a2cai_fetch_product_load_statusadmin\a2cai-admin-ajax.php:20
authwp_ajax_a2cai_get_sync_statusadmin\a2cai-admin-ajax.php:21

REST API Routes 2

GET/wp-json/a2cai/v1/products/batchincludes\class-a2cai-api.php:16
GET/wp-json/a2cai/v1/healthincludes\class-a2cai-api.php:22
WordPress Hooks 14
actionadmin_noticesadd-to-cart-ai.php:32
actionadmin_initadd-to-cart-ai.php:35
actionadmin_menuadmin\a2cai-admin.php:12
actionadmin_headadmin\a2cai-admin.php:13
actionadmin_enqueue_scriptsadmin\a2cai-admin.php:14
actionadmin_enqueue_scriptsadmin\a2cai-admin.php:15
filteradmin_footer_textadmin\a2cai-admin.php:16
actionadmin_initadmin\admin-hooks.php:25
actionrest_api_initincludes\class-a2cai-api.php:11
actionwoocommerce_update_productincludes\class-a2cai-product-sync.php:14
actionbefore_delete_postincludes\class-a2cai-product-sync.php:15
actionwp_trash_postincludes\class-a2cai-product-sync.php:16
actionuntrashed_postincludes\class-a2cai-product-sync.php:17
actionwp_enqueue_scriptspublic\class-a2cai-widget.php:11
Maintenance & Trust

Add To Cart AI – The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 6, 2026
PHP min version7.4
Downloads323

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Add To Cart AI – The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search Developer Profile

Add To Cart AI

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add To Cart AI – The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-to-cart-ai/public/css/admin-notices.css/wp-content/plugins/add-to-cart-ai/public/css/admin-style.css/wp-content/plugins/add-to-cart-ai/assets/js/setup-wizard.js/wp-content/plugins/add-to-cart-ai/assets/js/settings-page.js
Script Paths
/wp-content/plugins/add-to-cart-ai/admin/a2cai-admin.php/wp-content/plugins/add-to-cart-ai/admin/a2cai-admin-ajax.php/wp-content/plugins/add-to-cart-ai/admin/admin-hooks.php/wp-content/plugins/add-to-cart-ai/includes/class-a2cai-api.php/wp-content/plugins/add-to-cart-ai/includes/class-a2cai-product-sync.php/wp-content/plugins/add-to-cart-ai/public/class-a2cai-widget.php+1 more
Version Parameters
add-to-cart-ai/public/css/admin-notices.css?ver=add-to-cart-ai/public/css/admin-style.css?ver=add-to-cart-ai/assets/js/setup-wizard.js?ver=add-to-cart-ai/assets/js/settings-page.js?ver=

HTML / DOM Fingerprints

CSS Classes
a2cai-admin-notices
Data Attributes
data-path
JS Globals
a2caiSettings
FAQ

Frequently Asked Questions about Add To Cart AI – The Ultimate AI Shopping Assistant to Boost Woocommerce Sales with Chat, Lists & Photo Search