Ajax instant buy checkout for WooCommerce Security & Risk Analysis

wordpress.org/plugins/bss-ajax-checkout-instant

Ajax instant buy checkout for WooCommerce

0 active installs v1.1.0 PHP + WP 4.8+ Updated Mar 20, 2025
fast-checkoutinstant-checkoutwoocommercewoocommerce-ajaxwoocommerce-ajax-cart
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Ajax instant buy checkout for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Ajax instant buy checkout for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'bss-ajax-checkout-instant' plugin v1.1.0 presents a significant security concern due to its substantial attack surface lacking proper authentication checks. All five identified AJAX handlers are exposed without any form of authorization. This means that any authenticated user, or potentially even unauthenticated users depending on broader WordPress configurations, could trigger these AJAX actions, leading to unintended consequences.

Despite the absence of dangerous functions, raw SQL queries, or untrusted file operations, the lack of nonces and capability checks on the AJAX endpoints is a critical oversight. While the plugin boasts good practices in SQL query preparation and output escaping (79%), this is overshadowed by the potential for unauthorized actions. The absence of any recorded vulnerability history could suggest a lack of discovery or exploitation, but it does not negate the inherent risks posed by the exposed AJAX handlers.

In conclusion, while the plugin demonstrates positive attributes in secure coding for SQL and output handling, the critical flaw of unprotected AJAX endpoints makes it vulnerable to unauthorized actions. This plugin should be treated with caution, and immediate attention should be given to implementing proper authentication and authorization mechanisms for its AJAX handlers.

Key Concerns

  • AJAX handlers without authorization
  • AJAX handlers without nonce checks
  • Large attack surface without auth checks
Vulnerabilities
None known

Ajax instant buy checkout for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ajax instant buy checkout for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
49 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

79% escaped62 total outputs
Attack Surface
5 unprotected

Ajax instant buy checkout for WooCommerce Attack Surface

Entry Points5
Unprotected5

AJAX Handlers 5

authwp_ajax_ins_ajax_install_pluginwoo-ajax-instant-checkout.php:52
authwp_ajax_fstchk_notice_dismisswoo-ajax-instant-checkout.php:204
noprivwp_ajax_cart_loaderwoo-ajax-instant-checkout.php:208
noprivwp_ajax_upsell_loaderwoo-ajax-instant-checkout.php:379
noprivwp_ajax_post_to_orderwoo-ajax-instant-checkout.php:395
WordPress Hooks 16
actionadmin_noticeswoo-ajax-instant-checkout.php:47
actioninitwoo-ajax-instant-checkout.php:59
filterfstchk_upsell_productwoo-ajax-instant-checkout.php:62
filterwoocommerce_coupons_enabledwoo-ajax-instant-checkout.php:112
actionwp_enqueue_scriptswoo-ajax-instant-checkout.php:203
actionwc_ajax_cart_loaderwoo-ajax-instant-checkout.php:207
filterwoocommerce_minicart_item_namewoo-ajax-instant-checkout.php:220
actionwoocommerce_minicart_cartwoo-ajax-instant-checkout.php:222
actionwoocommerce_minicart_checkout_order_reviewwoo-ajax-instant-checkout.php:230
actionwoocommerce_minicart_checkout_order_reviewwoo-ajax-instant-checkout.php:231
actionwc_ajax_fstchk_add_to_cartwoo-ajax-instant-checkout.php:258
actionwc_ajax_nopriv_fstchk_add_to_cartwoo-ajax-instant-checkout.php:259
filterwoocommerce_add_to_cart_fragmentswoo-ajax-instant-checkout.php:314
filterwoocommerce_update_order_review_fragmentswoo-ajax-instant-checkout.php:338
actionwc_ajax_upsell_loaderwoo-ajax-instant-checkout.php:378
actionwc_ajax_post_to_orderwoo-ajax-instant-checkout.php:394
Maintenance & Trust

Ajax instant buy checkout for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 20, 2025
PHP min version
Downloads510

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Ajax instant buy checkout for WooCommerce Developer Profile

Bss

2 plugins · 0 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ajax instant buy checkout for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bss-ajax-checkout-instant/assets/css/bss-ajax-checkout-instant.css/wp-content/plugins/bss-ajax-checkout-instant/assets/js/bss-ajax-checkout-instant.min.js
Script Paths
/wp-content/plugins/bss-ajax-checkout-instant/assets/js/bss-ajax-checkout-instant.min.js
Version Parameters
bss-ajax-checkout-instant.min.js?ver=bss-ajax-checkout-instant.css?ver=

HTML / DOM Fingerprints

JS Globals
BSSFSTCHK_PLUGIN_SLUGFSTCHK_URLFSTCHK_INC_URLFSTCHK_ASSETS_URLFSTCHK_ADMIN_URLFSTCHK_PATH+7 more
FAQ

Frequently Asked Questions about Ajax instant buy checkout for WooCommerce