BEW Menu Cart Security & Risk Analysis

wordpress.org/plugins/bew-menu-cart

Add Woocommerce and Easy Digital Download Menu Cart Widget to the popular free page builder Elementor.

100 active installs v1.0.3 PHP + WP 4.9+ Updated Apr 2, 2018
briefcasewpeasy-digital-downloadelementorwidgetswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BEW Menu Cart Safe to Use in 2026?

Generally Safe

Score 85/100

BEW Menu Cart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of the "bew-menu-cart" v1.0.3 plugin reveals a seemingly secure codebase with no immediately identifiable critical vulnerabilities. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and taint flows is a strong indicator of good development practices. Furthermore, the plugin has no known historical CVEs, suggesting a history of stable and secure operation.

However, a significant concern arises from the complete lack of nonce checks and capability checks. While the current attack surface appears small and has no unprotected entry points, this absence of authorization mechanisms makes the plugin highly susceptible to unauthorized actions if new entry points were to be introduced in future versions or if the current structure is not as static as it appears. The 17% of outputs that are not properly escaped also present a potential cross-site scripting (XSS) risk, although the severity of this risk is mitigated by the lack of readily exploitable entry points in the current analysis.

In conclusion, "bew-menu-cart" v1.0.3 demonstrates a good foundation in secure coding for existing functionalities. The lack of historical vulnerabilities is positive. Nevertheless, the absence of robust authorization checks and incomplete output escaping represent significant weaknesses that could be exploited if the plugin's attack surface evolves or if these areas are not addressed in future updates.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Unescaped output detected (17%)
Vulnerabilities
None known

BEW Menu Cart Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BEW Menu Cart Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

BEW Menu Cart Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
34 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped41 total outputs
Attack Surface

BEW Menu Cart Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitbew-menu-cart.php:86
actioninitbew-menu-cart.php:87
actionelementor/initbew-menu-cart.php:90
actionelementor/widgets/widgets_registeredbew-menu-cart.php:93
actionelementor/frontend/after_register_scriptsbew-menu-cart.php:159
actionelementor/frontend/after_register_stylesbew-menu-cart.php:160
filterwoocommerce_add_to_cart_fragmentsincludes\woo-config.php:21
filterwoocommerce_add_to_cart_fragmentsincludes\woo-config.php:22
Maintenance & Trust

BEW Menu Cart Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 2, 2018
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

BEW Menu Cart Developer Profile

dgovea

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BEW Menu Cart

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bew-menu-cart/assets/css/third/font-awesome.min.css/wp-content/plugins/bew-menu-cart/assets/css/edd.min.css/wp-content/plugins/bew-menu-cart/assets/css/bew-edd.css/wp-content/plugins/bew-menu-cart/assets/css/bew-woocommerce-owp.css/wp-content/plugins/bew-menu-cart/assets/css/bew-woocommerce.css/wp-content/plugins/bew-menu-cart/assets/js/woocart-script.js
Script Paths
/wp-content/plugins/bew-menu-cart/assets/js/woocart-script.js
Version Parameters
/wp-content/plugins/bew-menu-cart/assets/css/third/font-awesome.min.css?ver=/wp-content/plugins/bew-menu-cart/assets/css/edd.min.css?ver=/wp-content/plugins/bew-menu-cart/assets/css/bew-edd.css?ver=/wp-content/plugins/bew-menu-cart/assets/css/bew-woocommerce-owp.css?ver=/wp-content/plugins/bew-menu-cart/assets/css/bew-woocommerce.css?ver=/wp-content/plugins/bew-menu-cart/assets/js/woocart-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
bew-edd-cart-iconbew-woo-cart-icon
Data Attributes
data-bew-cart-type
JS Globals
woocart_script
FAQ

Frequently Asked Questions about BEW Menu Cart