
Addonify – WooCommerce Wishlist Security & Risk Analysis
wordpress.org/plugins/addonify-wishlistAddonify WooCommerce Wishlist is a light-weight yet powerful tool that adds a wishlist functionality to your e-commerce shop.
Is Addonify – WooCommerce Wishlist Safe to Use in 2026?
Generally Safe
Score 99/100Addonify – WooCommerce Wishlist has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The addonify-wishlist plugin version 2.0.16 exhibits a mixed security posture. On the positive side, the code demonstrates good practices regarding SQL query preparation and output escaping, with high percentages of both being handled correctly. The absence of critical or high severity taint flows and the fact that all known past vulnerabilities are patched are also strong indicators of a relatively secure codebase. However, there are notable concerns related to the attack surface. The plugin exposes two AJAX handlers without proper authentication checks, creating a potential entry point for unauthorized actions. While the overall number of entry points isn't excessively high, these unprotected AJAX handlers represent a specific and actionable risk.
The vulnerability history, while showing no currently unpatched CVEs, does indicate one past medium-severity vulnerability, which was of the "Missing Authorization" type. This pattern, combined with the presence of unprotected AJAX handlers, suggests a recurring area of weakness in the plugin's authorization and authentication mechanisms. While the current version appears to have addressed past specific vulnerabilities, the underlying trend warrants vigilance.
In conclusion, addonify-wishlist v2.0.16 has made progress in core security areas like data handling and output sanitization. The lack of critical flaws in taint analysis is reassuring. Nevertheless, the exposed AJAX handlers present a clear and present risk that needs to be addressed. The past vulnerability pattern of missing authorization further emphasizes the need for robust checks on all user-facing functionalities, especially those exposed via AJAX.
Key Concerns
- Unprotected AJAX handlers detected
- Past medium vulnerability (Missing Authorization)
Addonify – WooCommerce Wishlist Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Addonify – WooCommerce Wishlist <= 2.0.15 - Missing Authorization to Unauthenticated Settings Update
Addonify – WooCommerce Wishlist Release Timeline
Addonify – WooCommerce Wishlist Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Addonify – WooCommerce Wishlist Attack Surface
AJAX Handlers 5
Shortcodes 3
WordPress Hooks 74
Scheduled Events 3
Maintenance & Trust
Addonify – WooCommerce Wishlist Maintenance & Trust
Maintenance Signals
Community Trust
Addonify – WooCommerce Wishlist Alternatives
QODE Wishlist for WooCommerce
qode-wishlist-for-woocommerce
Qode Wishlist for WooCommerce plugin is the ideal toolkit for letting your visitors save & share comprehensive lists with their products of interest.
Wishlist for WooCommerce: Multi Wishlists Per Customer
wish-list-for-woocommerce
Increase loyalty & sales by letting customers create, manage & share multiple wishlists on your WooCommerce store.
Airy Wishlist for WooCommerce
airy-wishlist
A powerful and user-friendly wishlist plugin for WooCommerce. Let customers save their favorite products for later!
Velocity Wishlist – WooCommerce Wishlist Plugin
velocity-wishlist
Powerful, lightweight wishlist functionality for WooCommerce. Supports guest users, product variations, social sharing, and fully customizable buttons …
YITH WooCommerce Wishlist
yith-woocommerce-wishlist
YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 10.7.x compatible.
Addonify – WooCommerce Wishlist Developer Profile
5 plugins · 4K total installs
How We Detect Addonify – WooCommerce Wishlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.