AlphaCommerce – Cart Recovery for WooCommerce Security & Risk Analysis

wordpress.org/plugins/alphacommerce-cart-recovery

Free abandoned cart recovery for WooCommerce. Captures carts, sends multi-step recovery emails, and restores carts with one click — fully local.

0 active installs v1.0.1 PHP 8.1+ WP 6.9+ Updated Mar 15, 2026
abandoned-cartcart-recoveryemail-recoverywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AlphaCommerce – Cart Recovery for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

AlphaCommerce – Cart Recovery for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The alphacommerce-cart-recovery plugin version 1.0.3 exhibits a generally strong security posture, with no known vulnerabilities or CVEs recorded. The static analysis reveals a healthy approach to database interactions, with all SQL queries utilizing prepared statements. Furthermore, the plugin demonstrates a good practice of implementing nonce and capability checks, which are crucial for securing various WordPress functionalities.

However, there are areas that warrant attention. A significant portion of output escaping (33%) is not properly handled, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without sufficient sanitization. While the attack surface appears minimal with no directly exposed AJAX handlers, REST API routes, or shortcodes without authentication, the presence of a cron event without explicit mention of its security context is a minor concern. The single external HTTP request also merits a review to ensure it is being made securely and does not introduce any supply chain risks.

Overall, the plugin is well-built with a strong foundation in secure coding practices. The absence of historical vulnerabilities is a positive indicator. The primary areas for improvement are ensuring all output is properly escaped and scrutinizing the security of the cron event and external HTTP request. Addressing the output escaping issue would significantly harden the plugin against common web exploits.

Key Concerns

  • Significant percentage of unescaped output
  • Cron event with potential for unauthorized execution
  • External HTTP request without clear security context
Vulnerabilities
None known

AlphaCommerce – Cart Recovery for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AlphaCommerce – Cart Recovery for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
59 prepared
Unescaped Output
83
172 escaped
Nonce Checks
10
Capability Checks
8
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared59 total queries

Output Escaping

67% escaped255 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
maybe_handle_actions (includes\class-admin.php:148)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AlphaCommerce – Cart Recovery for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 26
actionadmin_noticesalphacommerce-cart-recovery.php:72
actionadmin_initalphacommerce-cart-recovery.php:83
actionadmin_initalphacommerce-cart-recovery.php:157
actionplugins_loadedalphacommerce-cart-recovery.php:210
actionadmin_menuincludes\class-admin.php:19
actionadmin_enqueue_scriptsincludes\class-admin.php:20
actionwp_dashboard_setupincludes\class-admin.php:21
actioninitincludes\class-alphacommerce-abilities.php:30
actionwp_abilities_api_categories_initincludes\class-alphacommerce-abilities.php:33
actionwp_abilities_api_initincludes\class-alphacommerce-abilities.php:34
actionwp_enqueue_scriptsincludes\class-capture.php:25
actionrest_api_initincludes\class-capture.php:26
actionwoocommerce_checkout_update_order_reviewincludes\class-capture.php:29
actionwoocommerce_store_api_checkout_update_customer_from_requestincludes\class-capture.php:30
actionwoocommerce_after_checkout_billing_formincludes\class-capture.php:33
actionwoocommerce_checkout_create_orderincludes\class-conversion.php:38
actionwoocommerce_payment_completeincludes\class-conversion.php:39
actionwoocommerce_order_status_processingincludes\class-conversion.php:40
actionwoocommerce_order_status_completedincludes\class-conversion.php:41
actionwoocommerce_order_status_changedincludes\class-conversion.php:42
actionalphacommerce_local_recovery_sendincludes\class-local-recovery.php:19
actionalphacommerce_process_recovery_queueincludes\class-local-recovery.php:20
actioninitincludes\class-local-recovery.php:21
actioninitincludes\class-local-recovery.php:24
actionalphacommerce_send_recovery_reportincludes\class-reporter.php:16
actiontemplate_redirectincludes\class-restore.php:23

Scheduled Events 1

alphacommerce_local_recovery_send
Maintenance & Trust

AlphaCommerce – Cart Recovery for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version8.1
Downloads66

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AlphaCommerce – Cart Recovery for WooCommerce Developer Profile

AlphaCommerce™

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AlphaCommerce – Cart Recovery for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/alphacommerce-cart-recovery/assets/css/admin.css/wp-content/plugins/alphacommerce-cart-recovery/assets/js/admin.js
Script Paths
https://fonts.googleapis.com/css2?family=Figtree:wght@300;400;500;600;700&family=JetBrains+Mono&display=swap
Version Parameters
alphacommerce-cart-recovery/assets/css/admin.css?ver=alphacommerce-cart-recovery/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
accr-admin-dashboard-widget
Data Attributes
data-alphacommerce-cart-recovery-admin
JS Globals
ACCRAdmin
FAQ

Frequently Asked Questions about AlphaCommerce – Cart Recovery for WooCommerce