Change Add to Cart Button Text for WooCommerce Security & Risk Analysis

wordpress.org/plugins/add-to-cart-button-labels-for-woocommerce

Customize "Add to cart" button labels in WooCommerce. Beautifully.

1K active installs v2.2.5 PHP + WP 4.4+ Updated Sep 10, 2025
add-to-cartwoo-commercewoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 19, 2025
Safety Verdict

Is Change Add to Cart Button Text for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Change Add to Cart Button Text for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: May 19, 2025Updated 8mo ago
Risk Assessment

The plugin "add-to-cart-button-labels-for-woocommerce" v2.2.5 exhibits a generally good security posture based on the static analysis provided. The complete absence of identified attack surface points such as AJAX handlers, REST API routes, shortcodes, and cron events is a significant strength. Furthermore, the code signals show no dangerous functions, no file operations, and no external HTTP requests, all of which are positive indicators. The use of prepared statements for all SQL queries and a high percentage of properly escaped output also contribute to its good standing. However, the presence of one past medium severity vulnerability, specifically Cross-Site Scripting (XSS), even though currently patched, warrants attention. This history, coupled with the complete lack of nonce checks and capability checks, suggests a potential blind spot. While the static analysis found no current XSS issues or critical taint flows, the historical vulnerability in this area combined with the absence of input validation mechanisms like nonces could still pose a risk if new, undiscovered vulnerabilities are introduced or if existing ones are exploitable through different vectors. In conclusion, the plugin is strong in its sanitization and query practices and has a minimal attack surface. The primary weakness lies in the historical vulnerability pattern and the complete lack of input validation checks, which could become a concern for future security if not addressed.

Key Concerns

  • Past medium vulnerability (XSS)
  • No nonce checks
  • No capability checks
Vulnerabilities
1 published

Change Add to Cart Button Text for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48254medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Change Add to Cart Button Text for WooCommerce <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 19, 2025 Patched in 2.2.3 (10d)
Version History

Change Add to Cart Button Text for WooCommerce Release Timeline

v2.2.5Current
v2.2.4
v2.2.3
v2.2.21 CVE
v2.2.11 CVE
v2.2.01 CVE
v2.1.11 CVE
v2.1.01 CVE
v2.0.81 CVE
v2.0.71 CVE
v2.0.61 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.3.11 CVE
v1.3.01 CVE
v1.2.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Change Add to Cart Button Text for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped17 total outputs
Attack Surface

Change Add to Cart Button Text for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionplugins_loadedadd-to-cart-button-labels-for-woocommerce.php:57
actioninitincludes\class-alg-wc-atcbl.php:86
actionbefore_woocommerce_initincludes\class-alg-wc-atcbl.php:89
actioninitincludes\class-alg-wc-atcbl.php:97
actioninitincludes\class-alg-wc-atcbl.php:187
actioninitincludes\class-alg-wc-atcbl.php:190
filterwoocommerce_get_settings_pagesincludes\class-alg-wc-atcbl.php:193
actionadmin_initincludes\class-alg-wc-atcbl.php:197
filterwoocommerce_product_single_add_to_cart_textincludes\sections\class-alg-wc-atcbl-handler.php:65
filterwoocommerce_product_add_to_cart_textincludes\sections\class-alg-wc-atcbl-handler.php:66
actionadd_meta_boxesincludes\settings\class-alg-wc-atcbl-settings-meta-boxes.php:24
actionsave_post_productincludes\settings\class-alg-wc-atcbl-settings-meta-boxes.php:25
filterwoocommerce_get_sections_alg_wc_add_to_cart_button_labelsincludes\settings\class-alg-wc-atcbl-settings-section.php:53
filterwoocommerce_admin_settings_sanitize_optionincludes\settings\class-alg-wc-settings-atcbl.php:30
actionadmin_noticesincludes\settings\class-alg-wc-settings-atcbl.php:104
Maintenance & Trust

Change Add to Cart Button Text for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 10, 2025
PHP min version
Downloads28K

Community Trust

Rating100/100
Number of ratings6
Active installs1K
Developer Profile

Change Add to Cart Button Text for WooCommerce Developer Profile

WPFactory

64 plugins · 137K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
94 days
View full developer profile
Detection Fingerprints

How We Detect Change Add to Cart Button Text for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-to-cart-button-labels-for-woocommerce/assets/css/alg-wc-atcbl.css/wp-content/plugins/add-to-cart-button-labels-for-woocommerce/assets/js/alg-wc-atcbl.js
Version Parameters
add-to-cart-button-labels-for-woocommerce/assets/css/alg-wc-atcbl.css?ver=add-to-cart-button-labels-for-woocommerce/assets/js/alg-wc-atcbl.js?ver=

HTML / DOM Fingerprints

CSS Classes
alg-wc-atcbl-section-title
Data Attributes
data-alg_wc_atcbl_translate
Shortcode Output
[alg_wc_atcbl_user_name][alg_wc_atcbl_product_title][alg_wc_atcbl_product_price][alg_wc_atcbl_product_stock]
FAQ

Frequently Asked Questions about Change Add to Cart Button Text for WooCommerce