C4D Woo Cart Popup & Slide – Boost Sell Collections Security & Risk Analysis

wordpress.org/plugins/c4d-woo-cart-icon

Popup Cart, Side Cart, Sticky Add To Cart Button, Call For Price Button

10 active installs v3.0.9 PHP + WP 4.0+ Updated Jul 5, 2019
call-for-pricefly-add-to-cartpopup-cartside-cartsticky-add-to-cart
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is C4D Woo Cart Popup & Slide – Boost Sell Collections Safe to Use in 2026?

Generally Safe

Score 85/100

C4D Woo Cart Popup & Slide – Boost Sell Collections has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "c4d-woo-cart-icon" plugin v3.0.9 exhibits a concerning security posture due to a significant number of unprotected entry points. While the plugin demonstrates good practices in its SQL query handling and appears to avoid dangerous functions, file operations, and external HTTP requests, the presence of 6 AJAX handlers without authentication checks presents a substantial risk. This means that any unauthenticated user could potentially trigger actions within these handlers, leading to unintended consequences or information disclosure.

The static analysis did not reveal any taint flows or vulnerabilities in its vulnerability history, which is a positive indicator. However, the lack of nonces and capability checks on the identified AJAX handlers is a critical oversight. The plugin's attack surface is dominated by these unprotected AJAX endpoints, leaving it vulnerable to Cross-Site Request Forgery (CSRF) or other injection attacks if the AJAX actions are not inherently safe or are performed without proper validation. The high percentage of properly escaped output is a mitigating factor, but it does not fully address the fundamental lack of authorization on the entry points.

In conclusion, while the plugin avoids common pitfalls like raw SQL queries and has no known vulnerabilities, its security is significantly undermined by the unprotected AJAX handlers. The absence of nonces and capability checks on these entry points creates a clear pathway for potential exploitation by unauthenticated users. Developers should prioritize adding robust authentication and authorization mechanisms to these AJAX handlers to strengthen the plugin's security.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
  • High percentage of unprotected entry points
  • Some outputs not properly escaped
Vulnerabilities
None known

C4D Woo Cart Popup & Slide – Boost Sell Collections Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

C4D Woo Cart Popup & Slide – Boost Sell Collections Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
31 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

74% escaped42 total outputs
Attack Surface
6 unprotected

C4D Woo Cart Popup & Slide – Boost Sell Collections Attack Surface

Entry Points7
Unprotected6

AJAX Handlers 6

authwp_ajax_c4d_woo_cart_popup_templatec4d-woo-cart-icon.php:39
noprivwp_ajax_c4d_woo_cart_popup_templatec4d-woo-cart-icon.php:40
authwp_ajax_c4d_woo_cart_icon_popup_qty_updatec4d-woo-cart-icon.php:41
noprivwp_ajax_c4d_woo_cart_icon_popup_qty_updatec4d-woo-cart-icon.php:42
authwp_ajax_c4d_woo_cart_icon_remove_cart_itemc4d-woo-cart-icon.php:57
noprivwp_ajax_c4d_woo_cart_icon_remove_cart_itemc4d-woo-cart-icon.php:58

Shortcodes 1

[c4d-woo-cart] c4d-woo-cart-icon.php:50
WordPress Hooks 15
actionwp_enqueue_scriptsc4d-woo-cart-icon.php:36
actionadmin_enqueue_scriptsc4d-woo-cart-icon.php:37
actionc4d-plugin-manager-sectionc4d-woo-cart-icon.php:38
actionplugins_loadedc4d-woo-cart-icon.php:43
filterplugin_row_metac4d-woo-cart-icon.php:46
filteradd_to_cart_fragmentsc4d-woo-cart-icon.php:47
actionwoocommerce_initc4d-woo-cart-icon.php:53
actionwp_footerc4d-woo-cart-icon.php:56
actionwoocommerce_single_product_summaryc4d-woo-cart-icon.php:59
actionwoocommerce_after_main_contentc4d-woo-cart-icon.php:60
filterc4d_woo_cart_woocommerce_cart_item_quantityc4d-woo-cart-icon.php:61
actionwoocommerce_widget_shopping_cart_buttonsc4d-woo-cart-icon.php:148
actionwoocommerce_widget_shopping_cart_buttons_popupc4d-woo-cart-icon.php:162
actionwoocommerce_widget_shopping_cart_buttons_popupc4d-woo-cart-icon.php:167
actionwoocommerce_widget_shopping_cart_buttons_popupc4d-woo-cart-icon.php:172
Maintenance & Trust

C4D Woo Cart Popup & Slide – Boost Sell Collections Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJul 5, 2019
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

C4D Woo Cart Popup & Slide – Boost Sell Collections Developer Profile

coffee4dev

18 plugins · 400 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect C4D Woo Cart Popup & Slide – Boost Sell Collections

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/c4d-woo-cart-icon/css/c4d-woo-cart-icon.css/wp-content/plugins/c4d-woo-cart-icon/js/c4d-woo-cart-icon.js
Version Parameters
c4d-woo-cart-icon/css/c4d-woo-cart-icon.css?ver=c4d-woo-cart-icon/js/c4d-woo-cart-icon.js?ver=

HTML / DOM Fingerprints

CSS Classes
c4d-woo-cart-icon-call-for-pricec4d-woo-cart-fly-add-to-cartblock-contentblock-imageblock-product-infoblock-titleblock-priceblock-rate+2 more
Data Attributes
data-product_id
JS Globals
c4d_woo_cart_paramsc4d_plugin_manager
Shortcode Output
[c4d-woo-cart]
FAQ

Frequently Asked Questions about C4D Woo Cart Popup & Slide – Boost Sell Collections