Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles Security & Risk Analysis

wordpress.org/plugins/appsell

Increase your store's average order value, conversion rate, sales, and revenues significantly with the easiest-to-use Upsell & Cross-sell builder app.

10 active installs v1.0.2 PHP 5.4+ WP 3.1+ Updated Apr 9, 2025
bundlescross-sellfrequently-bought-togetherpost-checkoutupsell
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles Safe to Use in 2026?

Generally Safe

Score 100/100

Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "appsell" plugin v1.0.2 exhibits a mixed security posture, with some positive practices but significant concerns regarding its attack surface. While the plugin demonstrates good SQL hygiene by exclusively using prepared statements and generally handles output escaping well, the lack of authentication checks on its AJAX handlers presents a critical security risk. This means that any unauthenticated user can trigger functionality via these handlers, potentially leading to unauthorized actions or data exposure.

The static analysis reveals a small attack surface, but the fact that both entry points (AJAX handlers) lack any authorization checks is a major weakness. The absence of taint analysis findings and vulnerability history suggests that, thus far, no known vulnerabilities or exploitable code patterns have been identified in this specific version. However, this does not negate the immediate risk posed by the unprotected AJAX endpoints.

In conclusion, the plugin's strengths lie in its secure database interactions and generally robust output escaping. Nevertheless, the critical deficiency in securing its AJAX handlers significantly elevates the risk profile. It is highly recommended that these endpoints be protected with appropriate capability checks or nonce verification to mitigate the risk of unauthorized access and potential exploitation.

Key Concerns

  • AJAX handlers without authorization checks
  • Missing nonce checks on AJAX handlers
Vulnerabilities
None known

Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
8 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

89% escaped9 total outputs
Attack Surface
2 unprotected

Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_appsell_installationappsell.php:36
authwp_ajax_appsell_installationappsell.php:37
WordPress Hooks 3
actionadmin_enqueue_scriptsappsell.php:33
actionadmin_menuappsell.php:34
actionwp_headappsell.php:35
Maintenance & Trust

Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 9, 2025
PHP min version5.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles Developer Profile

Appsell

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/appsell/assets/css/style.css/wp-content/plugins/appsell/assets/js/script.js
Script Paths
https://app.appsell.io/api/js/upsaleWoo.js
Version Parameters
appsell/style.css?ver=appsell-admin?ver=

HTML / DOM Fingerprints

CSS Classes
appsell_icon
Data Attributes
data-appsell-keyid="devappsellScript"id="appsellScript"
JS Globals
appsell_installation
REST Endpoints
/wp-json/appsell/v1/installation
FAQ

Frequently Asked Questions about Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles