Add to Cart Button Manipulation for WooCommerce Security & Risk Analysis

wordpress.org/plugins/add-to-cart-button-manipulation-for-woocommerce

WooCommerce extension that allows you to control "Add to Cart" button on single product or set time slot to buy product (with countdown).

20 active installs v1.0.2 PHP 7.4+ WP 4.0+ Updated Dec 12, 2025
add-to-cartproduct-availabilitypromotional-toolsspecial-offerswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Add to Cart Button Manipulation for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Add to Cart Button Manipulation for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "add-to-cart-button-manipulation-for-woocommerce" plugin exhibits a generally good security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events, particularly those without authentication checks, significantly reduces the potential attack surface. Furthermore, the plugin demonstrates a commitment to secure database interactions by exclusively using prepared statements for its SQL queries and shows a lack of dangerous function usage, file operations, or external HTTP requests. This indicates a developer mindful of common web security pitfalls.

However, a critical concern arises from the output escaping analysis, which shows that 0% of the nine identified outputs are properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the WordPress site and executed in users' browsers. While the plugin has no recorded vulnerability history, this single area of weakness is substantial and could be exploited if user-supplied data or plugin-generated content is not handled with care. The presence of a capability check, though only one, is a positive sign, but it doesn't mitigate the output escaping issue.

In conclusion, the plugin has a strong foundation with its limited attack surface and secure data handling for SQL. Nevertheless, the complete lack of output escaping is a severe deficiency that overshadows these strengths. While the vulnerability history is clean, it is likely a matter of time before the XSS risk is exploited. Developers must address the output escaping issue immediately to ensure the plugin's safety and prevent potential security breaches.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
None known

Add to Cart Button Manipulation for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Add to Cart Button Manipulation for WooCommerce Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Add to Cart Button Manipulation for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped9 total outputs
Attack Surface

Add to Cart Button Manipulation for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
filterwoocommerce_settings_tabs_arrayadmin\class-wc-atcbm-settings.php:23
actionplugins_loadedincludes\class-wc-atcbm.php:139
actionadmin_enqueue_scriptsincludes\class-wc-atcbm.php:154
actionadmin_enqueue_scriptsincludes\class-wc-atcbm.php:155
filterwoocommerce_get_settings_pagesincludes\class-wc-atcbm.php:156
actionwoocommerce_product_options_advancedincludes\class-wc-atcbm.php:158
actionwoocommerce_process_product_metaincludes\class-wc-atcbm.php:159
actionwp_enqueue_scriptsincludes\class-wc-atcbm.php:174
actionwp_enqueue_scriptsincludes\class-wc-atcbm.php:175
actionwoocommerce_locate_templateincludes\class-wc-atcbm.php:176
actionwoocommerce_single_product_summaryincludes\class-wc-atcbm.php:178
actionwoocommerce_single_product_summaryincludes\class-wc-atcbm.php:179
filterwoocommerce_is_purchasableincludes\class-wc-atcbm.php:181
filterwoocommerce_get_price_htmlincludes\class-wc-atcbm.php:182
actionwoocommerce_single_product_summaryincludes\class-wc-atcbm.php:185
actionwoocommerce_initwc-atcbm.php:62
actionbefore_woocommerce_initwc-atcbm.php:66
actionadmin_noticeswc-atcbm.php:73
Maintenance & Trust

Add to Cart Button Manipulation for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 12, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating80/100
Number of ratings1
Active installs20
Developer Profile

Add to Cart Button Manipulation for WooCommerce Developer Profile

wpgenie2

10 plugins · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add to Cart Button Manipulation for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-to-cart-button-manipulation-for-woocommerce/css/wc-atcbm-admin.css/wp-content/plugins/add-to-cart-button-manipulation-for-woocommerce/js/jquery-ui-timepicker-addon.js/wp-content/plugins/add-to-cart-button-manipulation-for-woocommerce/js/wc-atcbm-admin.js
Version Parameters
add-to-cart-button-manipulation-for-woocommerce/css/wc-atcbm-admin.css?ver=add-to-cart-button-manipulation-for-woocommerce/js/jquery-ui-timepicker-addon.js?ver=add-to-cart-button-manipulation-for-woocommerce/js/wc-atcbm-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wc_atcbm
Data Attributes
id="_wc_atcbm_disable_add_to_cart_button"name="_wc_atcbm_button_dates_from"id="_wc_atcbm_button_dates_from"name="_wc_atcbm_button_dates_to"id="_wc_atcbm_button_dates_to"
JS Globals
timepicker-addon
FAQ

Frequently Asked Questions about Add to Cart Button Manipulation for WooCommerce