Advance Waitlist Security & Risk Analysis

wordpress.org/plugins/advance-waitlist

Enable your customer to add out-of-stock products into their waitlist and get notified when the product becomes in-stock and can place the order easil …

10 active installs v2.0.2 PHP + WP 4.0+ Updated Unknown
add-to-waitlistadvance-waitlistout-of-stockwaitlistwoocommerce-waitlist
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advance Waitlist Safe to Use in 2026?

Generally Safe

Score 100/100

Advance Waitlist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "advance-waitlist" plugin version 2.0.2 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and avoids file operations or external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of robust development. However, significant concerns arise from the static analysis, particularly regarding its attack surface. Two out of three identified entry points, specifically AJAX handlers, lack authentication checks. This creates a potential avenue for unauthorized actions if these handlers are exploitable. Furthermore, a notable portion (49%) of output escaping is not properly handled, which, while not directly indicated as a critical taint flow, could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. The taint analysis itself found no critical or high-severity issues, which is reassuring, but the existence of flows with unsanitized paths, even if not leading to critical issues in this version, warrants attention.

Key Concerns

  • AJAX handlers without auth checks
  • Significant portion of output unescaped
  • Flows with unsanitized paths
Vulnerabilities
None known

Advance Waitlist Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Advance Waitlist Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
24
25 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

51% escaped49 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
ced_awl_ced_add_to_cart (includes\ced_waitlist_main.php:588)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Advance Waitlist Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_chng_sts_wtl_btnced_waitlist.php:91
authwp_ajax_awl_email_actionincludes\ced_email.php:34

Shortcodes 1

[wish_list] includes\ced_waitlist_main.php:222
WordPress Hooks 47
actionplugins_loadedced_waitlist.php:59
actiondeactivated_pluginced_waitlist.php:75
actioninitced_waitlist.php:79
actionadmin_menuced_waitlist.php:83
actionadmin_enqueue_scriptsced_waitlist.php:87
actionadmin_initced_waitlist.php:330
actionadmin_noticesced_waitlist.php:342
actionwoocommerce_product_options_stock_fieldsced_waitlist.php:346
actionsave_postced_waitlist.php:376
actionwpincludes\ced_email.php:10
actionload-post.phpincludes\ced_metabox.php:22
actionload-post-new.phpincludes\ced_metabox.php:23
actionadmin_print_scriptsincludes\ced_metabox.php:26
actionadd_meta_boxesincludes\ced_metabox.php:58
actionsave_postincludes\ced_metabox.php:62
actionpost_updated_messagesincludes\ced_metabox.php:66
actionwoocommerce_before_single_productincludes\ced_plugin_class.php:42
actiontemplate_redirectincludes\ced_plugin_class.php:43
filterwoocommerce_available_variationincludes\ced_plugin_class.php:46
actionwoocommerce_get_stock_htmlincludes\ced_plugin_class.php:132
actionwoocommerce_get_stock_htmlincludes\ced_plugin_class.php:142
actionwoocommerce_after_shop_loop_itemincludes\ced_waitlist_main.php:325
actionwoocommerce_after_shop_loop_itemincludes\ced_waitlist_main.php:335
actionwoocommerce_after_shop_loop_itemincludes\ced_waitlist_main.php:359
actionwoocommerce_single_product_summaryincludes\ced_waitlist_main.php:426
actionwoocommerce_single_product_summaryincludes\ced_waitlist_main.php:465
actionwoocommerce_add_to_cart_validationincludes\ced_waitlist_main.php:547
actionwoocommerce_add_to_cartincludes\ced_waitlist_main.php:549
actionwpincludes\ced_waitlist_main.php:611
actionadmin_menuincludes\ced_waitlist_main.php:630
actionadmin_head-post.phpincludes\ced_waitlist_main.php:647
actionadmin_head-post-new.phpincludes\ced_waitlist_main.php:648
actionadmin_head-post.phpincludes\ced_waitlist_main.php:665
filtergettextincludes\ced_waitlist_main.php:670
filtermanage_wait_list_posts_columnsincludes\ced_waitlist_main.php:687
actionmanage_posts_custom_columnincludes\ced_waitlist_main.php:706
actionadmin_head-post.phpincludes\ced_waitlist_main.php:770
actionadmin_menuincludes\ced_waitlist_main.php:772
filterwp_get_nav_menu_itemsincludes\ced_waitlist_main.php:798
filtermanage_edit-page_columnsincludes\ced_waitlist_main.php:832
actionwp_dashboard_setupincludes\ced_waitlist_main.php:834
filterwoocommerce_login_redirectincludes\ced_waitlist_main.php:937
filterpost_row_actionsincludes\ced_waitlist_main.php:968
actionviews_edit-wait_listincludes\ced_waitlist_main.php:984
filtermonths_dropdown_resultsincludes\ced_waitlist_main.php:1022
filterwoocommerce_cart_item_quantityincludes\ced_waitlist_main.php:1024
actionadmin_headincludes\ced_waitlist_main.php:1064
Maintenance & Trust

Advance Waitlist Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating60/100
Number of ratings1
Active installs10
Developer Profile

Advance Waitlist Developer Profile

cedcommerce

21 plugins · 5K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
204 days
View full developer profile
Detection Fingerprints

How We Detect Advance Waitlist

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advance-waitlist/assets/css/ced-css.css/wp-content/plugins/advance-waitlist/assets/js/ced-js.js
Script Paths
/wp-content/plugins/advance-waitlist/assets/js/ced-js.js
Version Parameters
advance-waitlist/assets/css/ced-css.css?ver=advance-waitlist/assets/js/ced-js.js?ver=

HTML / DOM Fingerprints

JS Globals
obj
Shortcode Output
[wish_list]
FAQ

Frequently Asked Questions about Advance Waitlist