Addonify – Compare Products For WooCommerce Security & Risk Analysis

wordpress.org/plugins/addonify-compare-products

Addonify Compare Products is a WooCommerce extension that allows website visitors to compare multiple products on your online store.

1K active installs v1.1.18 PHP 7.4+ WP 6.3+ Updated Feb 15, 2026
comparecompare-productscompare-woocommerceproducts-comparisonwoocommerce-compare
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 4, 2026
Safety Verdict

Is Addonify – Compare Products For WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Addonify – Compare Products For WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 4, 2026Updated 3mo ago
Risk Assessment

The addonify-compare-products plugin version 1.1.18 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries, performing output escaping on a high percentage of outputs, and not employing dangerous functions or performing file operations. The absence of critical or high-severity taint flows is also reassuring. However, several areas warrant concern. The presence of two AJAX handlers without proper authorization checks represents a significant attack vector, potentially allowing unauthenticated users to trigger sensitive actions. While the plugin has a history of vulnerabilities, notably a medium severity one related to missing authorization in the past, the fact that there are no currently unpatched CVEs is a positive sign. The vulnerability history, however, suggests a recurring pattern of authorization issues which, even if addressed in the past, could indicate a need for continued vigilance in this area. The plugin also has a moderate attack surface with 10 entry points, two of which are unprotected.

Key Concerns

  • AJAX handlers without authorization checks
  • Past medium severity vulnerability (Missing Authorization)
  • Moderate attack surface with unprotected entry points
Vulnerabilities
1 published

Addonify – Compare Products For WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68023medium · 5.3Missing Authorization

Addonify – Compare Products For WooCommerce <= 1.1.17 - Missing Authorization to Unauthenticated Settings Update

Feb 4, 2026 Patched in 1.1.18 (13d)
Version History

Addonify – Compare Products For WooCommerce Release Timeline

v1.1.18Current
v1.1.171 CVE
v1.1.161 CVE
v1.1.151 CVE
v1.1.141 CVE
v1.1.131 CVE
v1.1.121 CVE
v1.1.111 CVE
v1.1.101 CVE
v1.1.91 CVE
v1.1.81 CVE
v1.1.71 CVE
v1.1.61 CVE
v1.1.51 CVE
v1.1.41 CVE
v1.1.31 CVE
v1.1.11 CVE
v1.1.01 CVE
v1.0.51 CVE
v1.0.41 CVE
Code Analysis
Analyzed Mar 16, 2026

Addonify – Compare Products For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
74 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

93% escaped80 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
process_user_tracking_choice (includes\udp\class-udp-agent.php:174)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Addonify – Compare Products For WooCommerce Attack Surface

Entry Points10
Unprotected2

AJAX Handlers 8

authwp_ajax_addonify_compare_products_initpublic\class-addonify-compare-products-public.php:173
noprivwp_ajax_addonify_compare_products_initpublic\class-addonify-compare-products-public.php:174
authwp_ajax_addonify_compare_products_add_productpublic\class-addonify-compare-products-public.php:177
noprivwp_ajax_addonify_compare_products_add_productpublic\class-addonify-compare-products-public.php:178
authwp_ajax_addonify_compare_products_search_productspublic\class-addonify-compare-products-public.php:181
noprivwp_ajax_addonify_compare_products_search_productspublic\class-addonify-compare-products-public.php:182
authwp_ajax_addonify_compare_products_compare_contentpublic\class-addonify-compare-products-public.php:185
noprivwp_ajax_addonify_compare_products_compare_contentpublic\class-addonify-compare-products-public.php:186

Shortcodes 2

[addonify_compare_products] public\class-addonify-compare-products-public.php:189
[addonify_compare_button] public\class-addonify-compare-products-public.php:191
WordPress Hooks 45
actionadmin_noticesaddonify-compare-products.php:77
actionplugins_loadedaddonify-compare-products.php:90
actionaddonify_compare_products_compare_buttonincludes\addonify-compare-products-template-hooks.php:9
actionaddonify_compare_products_docker_modalincludes\addonify-compare-products-template-hooks.php:11
actionaddonify_compare_products_docker_messageincludes\addonify-compare-products-template-hooks.php:13
actionaddonify_compare_products_docker_contentincludes\addonify-compare-products-template-hooks.php:14
actionaddonify_compare_products_docker_add_buttonincludes\addonify-compare-products-template-hooks.php:15
actionaddonify_compare_products_docker_compare_buttonincludes\addonify-compare-products-template-hooks.php:16
actionaddonify_compare_products_search_modalincludes\addonify-compare-products-template-hooks.php:18
actionaddonify_compare_products_search_resultincludes\addonify-compare-products-template-hooks.php:19
actionaddonify_compare_products_comparison_modalincludes\addonify-compare-products-template-hooks.php:21
actionaddonify_compare_products_comparison_contentincludes\addonify-compare-products-template-hooks.php:23
actionrest_api_initincludes\class-addonify-compare-products-rest-api.php:44
actionplugins_loadedincludes\class-addonify-compare-products.php:157
actionadmin_menuincludes\class-addonify-compare-products.php:174
actionadmin_enqueue_scriptsincludes\class-addonify-compare-products.php:176
actionadmin_enqueue_scriptsincludes\class-addonify-compare-products.php:177
actioninitincludes\class-addonify-compare-products.php:191
filteraddonify_compare_products_settings_fieldsincludes\setting-functions\fields\compare-button.php:144
filteraddonify_compare_products_settings_fieldsincludes\setting-functions\fields\comparison-table.php:275
filteraddonify_compare_products_settings_fieldsincludes\setting-functions\fields\custom-css.php:49
filteraddonify_compare_products_settings_fieldsincludes\setting-functions\fields\floating-compare-bar.php:108
filteraddonify_compare_products_settings_fieldsincludes\setting-functions\fields\general.php:123
filteraddonify_compare_products_settings_fieldsincludes\setting-functions\fields\search-modal.php:152
actioninitincludes\udp\class-udp-agent.php:76
actionadmin_initincludes\udp\class-udp-agent.php:77
actioninitincludes\udp\class-udp-agent.php:80
actionadmin_initincludes\udp\init.php:53
actionload-index.phpincludes\udp\init.php:113
actionadmin_noticesincludes\udp\init.php:116
actioncc_udp_agent_send_dataincludes\udp\init.php:179
actionafter_switch_themeincludes\udp\init.php:184
actionactivate_pluginincludes\udp\init.php:213
actiondeactivate_pluginincludes\udp\init.php:223
actionswitch_themeincludes\udp\init.php:254
actionwp_enqueue_scriptspublic\class-addonify-compare-products-public.php:123
actionwp_enqueue_scriptspublic\class-addonify-compare-products-public.php:124
actionwoocommerce_after_shop_loop_itempublic\class-addonify-compare-products-public.php:131
actionwoocommerce_after_shop_loop_itempublic\class-addonify-compare-products-public.php:138
actionwoocommerce_before_add_to_cart_formpublic\class-addonify-compare-products-public.php:147
actionwoocommerce_after_add_to_cart_quantitypublic\class-addonify-compare-products-public.php:151
actionwoocommerce_before_add_to_cart_buttonpublic\class-addonify-compare-products-public.php:155
actionwoocommerce_after_add_to_cart_buttonpublic\class-addonify-compare-products-public.php:159
actionwoocommerce_after_add_to_cart_formpublic\class-addonify-compare-products-public.php:163
actionwp_footerpublic\class-addonify-compare-products-public.php:170

Scheduled Events 3

cc_udp_agent_send_data
cc_udp_agent_send_data
cc_udp_agent_send_data
Maintenance & Trust

Addonify – Compare Products For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 15, 2026
PHP min version7.4
Downloads39K

Community Trust

Rating100/100
Number of ratings4
Active installs1K
Developer Profile

Addonify – Compare Products For WooCommerce Developer Profile

Addonify

5 plugins · 4K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
23 days
View full developer profile
Detection Fingerprints

How We Detect Addonify – Compare Products For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/addonify-compare-products/public/assets/css/frontend.css/wp-content/plugins/addonify-compare-products/public/assets/js/frontend.js
Script Paths
/wp-content/plugins/addonify-compare-products/public/assets/js/frontend.js
Version Parameters
addonify-compare-products/public/assets/css/frontend.css?ver=addonify-compare-products/public/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
addonify-compare-productsadfy-compare-btnadfy-compare-widget
Data Attributes
data-addonify-cp-compare-slugdata-addonify-cp-compare-btn-text
JS Globals
ADDONIFY_COMPARE_PRODUCTS_LOCALIZER
REST Endpoints
/wp-json/addonify_compare_products_options_api/v1/options
Shortcode Output
[addonify_compare_products]
FAQ

Frequently Asked Questions about Addonify – Compare Products For WooCommerce