Addonify Floating Cart For WooCommerce Security & Risk Analysis

wordpress.org/plugins/addonify-floating-cart

Addonify Floating Cart is a free WooCommerce addon that adds a sticky, interactive cart, letting visitors manage items without visiting the cart page.

1K active installs v1.2.17 PHP 7.4+ WP 6.0.0+ Updated Dec 27, 2025
cartfloating-cartmini-cartside-cartwoocommerce-cart
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEFeb 5, 2026
Safety Verdict

Is Addonify Floating Cart For WooCommerce Safe to Use in 2026?

Mostly Safe

Score 78/100

Addonify Floating Cart For WooCommerce is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Feb 5, 2026Updated 4mo ago
Risk Assessment

The addonify-floating-cart plugin v1.2.17 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped outputs. The absence of dangerous functions and file operations is also encouraging. However, significant concerns arise from its attack surface, particularly the presence of two AJAX handlers that lack authentication checks. This creates a direct path for unauthorized actions if these handlers are exploitable.

The vulnerability history is a critical indicator of potential weaknesses. A single known CVE, although medium severity, being currently unpatched suggests an immediate risk. The pattern of past vulnerabilities, specifically "Missing Authorization," strongly correlates with the observed unprotected AJAX handlers, highlighting a recurring security oversight in the plugin. While the taint analysis shows no critical or high severity flows, the combination of unprotected entry points and a history of authorization issues warrants careful consideration.

In conclusion, addonify-floating-cart v1.2.17 has strengths in its handling of SQL and output escaping. Nevertheless, the identified unprotected AJAX endpoints, coupled with a history of missing authorization vulnerabilities and an unpatched CVE, represent significant security weaknesses that need to be addressed to improve the overall security posture of the plugin.

Key Concerns

  • Unprotected AJAX handlers
  • Currently unpatched CVE (medium severity)
  • History of missing authorization vulnerabilities
Vulnerabilities
1 published

Addonify Floating Cart For WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68025medium · 5.3Missing Authorization

Addonify Floating Cart For WooCommerce <= 1.2.17 - Missing Authorization

Feb 5, 2026Unpatched
Version History

Addonify Floating Cart For WooCommerce Release Timeline

v1.2.17Current1 CVE
v1.2.161 CVE
v1.2.151 CVE
v1.2.141 CVE
v1.2.131 CVE
v1.2.121 CVE
v1.2.111 CVE
v1.2.101 CVE
v1.2.91 CVE
v1.2.81 CVE
v1.2.71 CVE
v1.2.61 CVE
v1.2.51 CVE
v1.2.41 CVE
v1.2.31 CVE
v1.2.21 CVE
v1.2.11 CVE
v1.2.01 CVE
v1.1.111 CVE
v1.1.101 CVE
Code Analysis
Analyzed Mar 16, 2026

Addonify Floating Cart For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
253 escaped
Nonce Checks
8
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

97% escaped262 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
process_user_tracking_choice (includes\udp\class-udp-agent.php:174)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Addonify Floating Cart For WooCommerce Attack Surface

Entry Points19
Unprotected2

AJAX Handlers 18

authwp_ajax_addonify_floating_cart_add_to_cartpublic\class-addonify-floating-cart-public.php:152
noprivwp_ajax_addonify_floating_cart_add_to_cartpublic\class-addonify-floating-cart-public.php:153
authwp_ajax_addonify_floating_cart_remove_from_cartpublic\class-addonify-floating-cart-public.php:155
noprivwp_ajax_addonify_floating_cart_remove_from_cartpublic\class-addonify-floating-cart-public.php:156
authwp_ajax_addonify_floating_cart_restore_in_cartpublic\class-addonify-floating-cart-public.php:158
noprivwp_ajax_addonify_floating_cart_restore_in_cartpublic\class-addonify-floating-cart-public.php:159
authwp_ajax_addonify_floating_cart_update_cart_itempublic\class-addonify-floating-cart-public.php:161
noprivwp_ajax_addonify_floating_cart_update_cart_itempublic\class-addonify-floating-cart-public.php:162
authwp_ajax_addonify_floating_cart_apply_couponpublic\class-addonify-floating-cart-public.php:164
noprivwp_ajax_addonify_floating_cart_apply_couponpublic\class-addonify-floating-cart-public.php:165
authwp_ajax_addonify_floating_cart_remove_couponpublic\class-addonify-floating-cart-public.php:167
noprivwp_ajax_addonify_floating_cart_remove_couponpublic\class-addonify-floating-cart-public.php:168
authwp_ajax_addonify_floating_update_shipping_infopublic\class-addonify-floating-cart-public.php:170
noprivwp_ajax_addonify_floating_update_shipping_infopublic\class-addonify-floating-cart-public.php:171
authwp_ajax_addonify_floating_update_shipping_methodpublic\class-addonify-floating-cart-public.php:173
noprivwp_ajax_addonify_floating_update_shipping_methodpublic\class-addonify-floating-cart-public.php:174
authwp_ajax_addonify_floating_cart_refresh_cart_fragmentspublic\class-addonify-floating-cart-public.php:176
noprivwp_ajax_addonify_floating_cart_refresh_cart_fragmentspublic\class-addonify-floating-cart-public.php:177

Shortcodes 1

[afc_cart_icon] public\class-addonify-floating-cart-public.php:179
WordPress Hooks 62
actionadmin_noticesaddonify-floating-cart.php:65
actionplugins_loadedaddonify-floating-cart.php:77
actionrest_api_initincludes\class-addonify-floating-cart-rest-api.php:38
actioninitincludes\class-addonify-floating-cart.php:155
actionadmin_menuincludes\class-addonify-floating-cart.php:171
actionadmin_enqueue_scriptsincludes\class-addonify-floating-cart.php:173
actionadmin_enqueue_scriptsincludes\class-addonify-floating-cart.php:175
actioninitincludes\class-addonify-floating-cart.php:189
actionwp_enqueue_scriptsincludes\class-addonify-floating-cart.php:190
actionwp_enqueue_scriptsincludes\class-addonify-floating-cart.php:191
actionwp_footerincludes\class-addonify-floating-cart.php:192
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart-buttons.php:65
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart-display.php:48
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart-display.php:213
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart-display.php:374
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart-display.php:445
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart-display.php:538
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart-header.php:66
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart-items.php:57
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart-subtotals.php:63
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart.php:59
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\cart.php:87
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\coupon-modal.php:81
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\custom-css.php:34
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\miscellaneous.php:53
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\shipping.php:115
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\shopping-meter.php:67
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\toast-notification.php:90
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\toast-notification.php:188
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\toggle-button.php:88
filteraddonify_floating_cart_settings_fieldsincludes\functions\fields\toggle-button.php:250
actionaddonify_floating_cart_footer_templateincludes\template-functions.php:110
actionaddonify_floating_cart_footer_templateincludes\template-functions.php:133
actionaddonify_floating_cart_sidebar_cartincludes\template-functions.php:154
actionaddonify_floating_cart_sidebar_cart_headerincludes\template-functions.php:183
actionaddonify_floating_cart_sidebar_cart_bodyincludes\template-functions.php:207
actionaddonify_floating_cart_sidebar_cart_couponincludes\template-functions.php:231
actionaddonify_floating_cart_sidebar_cart_applied_couponsincludes\template-functions.php:257
actionaddonify_floating_cart_sidebar_cart_shipping_barincludes\template-functions.php:327
actionaddonify_floating_cart_sidebar_cart_shippingincludes\template-functions.php:382
actionaddonify_floating_cart_sidebar_cart_footerincludes\template-functions.php:407
actionaddonify_floating_cart_cart_footer_buttonincludes\template-functions.php:461
actionaddonify_floating_cart_cart_footer_buttonincludes\template-functions.php:489
actionaddonify_floating_cart_product_imageincludes\template-functions.php:518
actionaddonify_floating_cart_product_quantity_fieldincludes\template-functions.php:552
actionaddonify_floating_cart_product_quantity_priceincludes\template-functions.php:580
actionaddonify_floating_cart_product_titleincludes\template-functions.php:656
actionaddonify_floating_cart_sidebar_cart_noticeincludes\template-functions.php:671
actionaddonify_floating_cart_render_empty_cartincludes\template-functions.php:749
actionaddonify_floating_cart_coupon_shipping_modal_close_buttonincludes\template-functions.php:780
actioninitincludes\udp\class-udp-agent.php:76
actionadmin_initincludes\udp\class-udp-agent.php:77
actioninitincludes\udp\class-udp-agent.php:80
actionadmin_initincludes\udp\init.php:53
actionload-index.phpincludes\udp\init.php:113
actionadmin_noticesincludes\udp\init.php:116
actioncc_udp_agent_send_dataincludes\udp\init.php:179
actionafter_switch_themeincludes\udp\init.php:184
actionactivate_pluginincludes\udp\init.php:213
actiondeactivate_pluginincludes\udp\init.php:223
actionswitch_themeincludes\udp\init.php:254
filterwoocommerce_add_to_cart_fragmentspublic\class-addonify-floating-cart-public.php:140

Scheduled Events 3

cc_udp_agent_send_data
cc_udp_agent_send_data
cc_udp_agent_send_data
Maintenance & Trust

Addonify Floating Cart For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 27, 2025
PHP min version7.4
Downloads33K

Community Trust

Rating94/100
Number of ratings15
Active installs1K
Developer Profile

Addonify Floating Cart For WooCommerce Developer Profile

Addonify

5 plugins · 4K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
23 days
View full developer profile
Detection Fingerprints

How We Detect Addonify Floating Cart For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/addonify-floating-cart/admin/assets/css/admin.css/wp-content/plugins/addonify-floating-cart/admin/assets/js/manifest.js/wp-content/plugins/addonify-floating-cart/admin/assets/js/vendor.js/wp-content/plugins/addonify-floating-cart/admin/assets/js/main.js/wp-content/plugins/addonify-floating-cart/public/css/style.css/wp-content/plugins/addonify-floating-cart/public/js/frontend.js/wp-content/plugins/addonify-floating-cart/public/js/frontend-app.js
Script Paths
/wp-content/plugins/addonify-floating-cart/admin/assets/js/manifest.js/wp-content/plugins/addonify-floating-cart/admin/assets/js/vendor.js/wp-content/plugins/addonify-floating-cart/admin/assets/js/main.js/wp-content/plugins/addonify-floating-cart/public/js/frontend.js/wp-content/plugins/addonify-floating-cart/public/js/frontend-app.js
Version Parameters
addonify-floating-cart/admin/assets/css/admin.css?ver=addonify-floating-cart/admin/assets/js/manifest.js?ver=addonify-floating-cart/admin/assets/js/vendor.js?ver=addonify-floating-cart/admin/assets/js/main.js?ver=addonify-floating-cart/public/css/style.css?ver=addonify-floating-cart/public/js/frontend.js?ver=addonify-floating-cart/public/js/frontend-app.js?ver=

HTML / DOM Fingerprints

CSS Classes
addonify-woo-fcaddonify-woo-fc-header-btnaddonify-woo-fc-empty-cart
HTML Comments
<!-- Addonify Floating Cart --><!-- Floating Cart Main Wrapper --><!-- Floating Cart Header --><!-- Floating Cart Body -->+2 more
Data Attributes
data-addfy-slugdata-addfy-cart-wrapperdata-addfy-item-qtydata-addfy-price
JS Globals
ADDONIFY_WOOFC_LOCOLIZERAddonifyFloatingCartApp
REST Endpoints
/wp-json/addonify_floating_cart_options_api/v1/get_settings/wp-json/addonify_floating_cart_options_api/v1/save_settings
Shortcode Output
[addonify_floating_cart_button]
FAQ

Frequently Asked Questions about Addonify Floating Cart For WooCommerce