
BizzWishlist – WooCommerce Wishlist Security & Risk Analysis
wordpress.org/plugins/bizzwishlistA lightweight and powerful WooCommerce Wishlist addon. Allow customers to save their favorite products and purchase them later.
Is BizzWishlist – WooCommerce Wishlist Safe to Use in 2026?
Generally Safe
Score 100/100BizzWishlist – WooCommerce Wishlist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bizzwishlist plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL query sanitization and output escaping, with 87% of SQL queries using prepared statements and 98% of outputs being properly escaped. The absence of known CVEs and dangerous functions is also a good sign. However, significant concerns arise from the attack surface analysis. A substantial portion of its entry points, specifically 18 out of 24, are unprotected by authentication checks. This, coupled with four identified taint flows with unsanitized paths, suggests a potential for vulnerabilities that could be exploited by unauthenticated users. The high number of unprotected AJAX handlers is a primary area of risk.
The vulnerability history shows no past recorded issues, which is encouraging, but it doesn't negate the immediate risks identified in the static analysis. The taint analysis, while not reporting critical or high severity flows as explicitly stated, does flag four flows with unsanitized paths. These, in conjunction with the numerous unprotected AJAX handlers, are the most pressing security concerns for this plugin. While the code demonstrates good practices in other areas, the lack of robust authentication on a significant number of entry points and the identified unsanitized paths create a considerable risk that needs to be addressed.
Key Concerns
- Large attack surface without auth
- Flows with unsanitized paths (4)
- Missing nonce checks on AJAX (18 handlers)
BizzWishlist – WooCommerce Wishlist Security Vulnerabilities
BizzWishlist – WooCommerce Wishlist Release Timeline
BizzWishlist – WooCommerce Wishlist Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BizzWishlist – WooCommerce Wishlist Attack Surface
AJAX Handlers 21
Shortcodes 3
WordPress Hooks 26
Maintenance & Trust
BizzWishlist – WooCommerce Wishlist Maintenance & Trust
Maintenance Signals
Community Trust
BizzWishlist – WooCommerce Wishlist Alternatives
Addonify – WooCommerce Wishlist
addonify-wishlist
Addonify WooCommerce Wishlist is a light-weight yet powerful tool that adds a wishlist functionality to your e-commerce shop.
Velocity Wishlist – WooCommerce Wishlist Plugin
velocity-wishlist
Powerful, lightweight wishlist functionality for WooCommerce. Supports guest users, product variations, social sharing, and fully customizable buttons …
WPMozo Wishlist Lite for WooCommerce
wpmozo-wishlist-lite-for-woocommerce
WPMozo Wishlist Lite for WooCommerce adds a wishlist feature to your WooCommerce store, allowing customers to save their favorite products for future …
Advanced Wishlist & Share – Save Products for Later
advwl-wishlist-for-woocommerce
A simple and user-friendly wishlist plugin that allows customers to save products they love for later purchase or review.
AICOSO Wishlist for WooCommerce
aicoso-wishlist-for-woocommerce
Comprehensive wishlist solution for WooCommerce with AI-powered recommendations, social sharing, and advanced analytics.
BizzWishlist – WooCommerce Wishlist Developer Profile
14 plugins · 19K total installs
How We Detect BizzWishlist – WooCommerce Wishlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bizzwishlist/assets/css/admin-analytics.css/wp-content/plugins/bizzwishlist/assets/js/vendor/chart.min.js/wp-content/plugins/bizzwishlist/assets/js/admin-analytics.js/wp-content/plugins/bizzwishlist/assets/js/admin-analytics.js/wp-content/plugins/bizzwishlist/assets/js/vendor/chart.min.jsbizzwishlist/assets/css/admin-analytics.css?ver=bizzwishlist/assets/js/admin-analytics.js?ver=HTML / DOM Fingerprints
data-nonce="bizzwishlist_analytics_nonce"window.bizzwishlistAnalytics