
Cart Analytics for WP e-Commerce Security & Risk Analysis
wordpress.org/plugins/cart-analytics-for-wp-e-commerceChecks how many products added to a WPeC Cart are actually purchased and stores informations in the database.
Is Cart Analytics for WP e-Commerce Safe to Use in 2026?
Generally Safe
Score 85/100Cart Analytics for WP e-Commerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "cart-analytics-for-wp-e-commerce" version 1.0 exhibits a mixed security posture. On the positive side, the static analysis reveals an extremely small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the absence of any recorded vulnerabilities in its history, including CVEs, suggests a potentially stable and well-maintained codebase. However, significant concerns arise from the code analysis. The complete lack of prepared statements for all SQL queries is a critical vulnerability, as it opens the door to SQL injection attacks. Similarly, the absence of proper output escaping for all identified outputs is a major risk, potentially leading to cross-site scripting (XSS) vulnerabilities. The single capability check suggests that privilege escalation might be a concern if the entry points were exploitable.
While the plugin's limited attack surface and clean vulnerability history are strengths, the identified coding practices are severe weaknesses. The reliance on raw SQL queries without prepared statements and the complete lack of output escaping are fundamental security flaws that could be easily exploited. Given the version number and the absence of vulnerabilities in its history, it's possible that this version has not been thoroughly tested for these common vulnerabilities or that they have not yet been discovered. Therefore, despite the seemingly clean slate, a cautious approach is warranted due to the significant coding issues.
Key Concerns
- SQL queries without prepared statements
- Output escaping not properly implemented
- Single capability check
Cart Analytics for WP e-Commerce Security Vulnerabilities
Cart Analytics for WP e-Commerce Code Analysis
SQL Query Safety
Output Escaping
Cart Analytics for WP e-Commerce Attack Surface
WordPress Hooks 5
Maintenance & Trust
Cart Analytics for WP e-Commerce Maintenance & Trust
Maintenance Signals
Community Trust
Cart Analytics for WP e-Commerce Alternatives
ShippingEasy for WP e-Commerce
shippingeasy-for-wp-ecommerce
ShippingEasy is a powerful online shipping platform that integrates seamlessly with your WordPress WP e-Commerce store to give you a complete end-to-e …
Content Shelf Shopping Cart
content-shelf-shopping-cart
Content Shelf is shopping cart software for selling digital content, tangible products, services, subscriptions and gift cards.
E-Commerce by SalesCart
e-commerce-by-salescart
SalesCart is a fully featured, complete Shopping Cart solution that can be added in under 15 mins to any WP theme. Use SalesCart for FREE today.
WP e-Commerce – Store Toolkit
store-toolkit-for-wp-e-commerce
This is a legacy Plugin, please see WP e-Commerce - Store Toolkit for the latest release.
Name: WP e-Commerce Free Checkout
wp-e-commerce-free-checkout
Allows for Free Checkout with WordPress e-Commerce Plugin.
Cart Analytics for WP e-Commerce Developer Profile
4 plugins · 50 total installs
How We Detect Cart Analytics for WP e-Commerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cart-analytics-for-wp-e-commerce/css/styles.css/wp-content/plugins/cart-analytics-for-wp-e-commerce/js/gchart.phphttps://www.google.com/jsapiHTML / DOM Fingerprints
chart_dateid="date_select"name="date_select"id="submit"name="submit"id="chart_div"