Ade Cart Manager Security & Risk Analysis

wordpress.org/plugins/ade-cart-manager

A powerful plugin that enables you to track and recover abandoned cart items, turning lost sales into successful transactions.

0 active installs v1.4.5 PHP 5.5+ WP 3.6.0+ Updated Unknown
ade-cart-managerade-custom-shippingcartcart-managerwoocommerce-shipping
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ade Cart Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Ade Cart Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'ade-cart-manager' plugin v1.4.5 exhibits a mixed security posture. While the absence of known CVEs and no critical taint analysis results are positive indicators, significant concerns arise from its attack surface. A substantial portion of its AJAX handlers lack authentication checks, presenting a direct pathway for potential unauthorized actions. Furthermore, the limited implementation of prepared statements in SQL queries and a concerning percentage of unescaped output suggest vulnerabilities that could be exploited for data manipulation or information leakage.

The plugin's reliance on potentially vulnerable AJAX endpoints without proper authorization is a key area of risk. The 4 unprotected AJAX handlers represent a critical weakness. The moderate usage of prepared statements for SQL queries (only 30% protected) and the low rate of proper output escaping (44%) further indicate that attackers could potentially inject malicious SQL or leverage cross-site scripting (XSS) vulnerabilities. The presence of only one nonce check across the entire plugin is also a significant oversight, particularly for the unprotected AJAX endpoints.

The plugin's vulnerability history is currently clean, showing no recorded CVEs. This could indicate a history of good security practices or simply a lack of past discovery. However, the static analysis results reveal inherent weaknesses that could be exploited regardless of historical incidents. A balanced conclusion suggests that while the plugin has not been historically compromised, its current implementation contains several exploitable vulnerabilities that require immediate attention to improve its overall security.

Key Concerns

  • Unprotected AJAX handlers
  • SQL queries not using prepared statements
  • Improper output escaping
  • Missing nonce checks on AJAX
  • No capability checks
Vulnerabilities
None known

Ade Cart Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ade Cart Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
3 prepared
Unescaped Output
27
21 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

30% prepared10 total queries

Output Escaping

44% escaped48 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
ade_cart_manager_page (inc\ade-dashboard-data.php:6)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Ade Cart Manager Attack Surface

Entry Points6
Unprotected4

AJAX Handlers 6

authwp_ajax_ade_cart_manager_ajax_processinc\ade-cart-manager.php:10
noprivwp_ajax_ade_cart_manager_ajax_processinc\ade-cart-manager.php:11
authwp_ajax_ade_cart_manager_ajax_dataAPIinc\ade-cart-manager.php:13
noprivwp_ajax_ade_cart_manager_ajax_dataAPIinc\ade-cart-manager.php:14
authwp_ajax_ade_cart_manager_ajaxinc\ade-dashboard.php:16
noprivwp_ajax_ade_cart_manager_ajaxinc\ade-dashboard.php:17
WordPress Hooks 11
actionbefore_wcfm_customersinc\ade-dashboard-data.php:731
filterwcfm_menusinc\ade-dashboard-data.php:732
filterwpinc\ade-dashboard-data.php:761
actionadmin_menuinc\ade-dashboard.php:13
actionwp_footerinc\ade-dashboard.php:212
actionwp_footerinc\ade-dashboard.php:215
actionwp_footerinc\ade-dashboard.php:218
filterwpinc\ade-dashboard.php:222
actionwp_logoutinc\ade-dashboard.php:231
filterwpinc\ade-search.php:8
actionwp_headinc\ade-search.php:18
Maintenance & Trust

Ade Cart Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedUnknown
PHP min version5.5
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Ade Cart Manager Developer Profile

adeleyeayodeji

5 plugins · 1K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ade Cart Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ade-cart-manager/assets/css/datatable.css/wp-content/plugins/ade-cart-manager/assets/js/datatable.js
Script Paths
/wp-content/plugins/ade-cart-manager/assets/js/datatable.js
Version Parameters
ade-cart-manager/assets/js/datatable.js?ver=ade-cart-manager-script?ver=

HTML / DOM Fingerprints

CSS Classes
ade-cart-managerxpdmodalxpdmodal-content
HTML Comments
aria-label has no advantage, it won't be read inside a .ade-cart-managerenable popupdisable popupCart Manager Popup Settings Updated+1 more
Data Attributes
data-label
FAQ

Frequently Asked Questions about Ade Cart Manager