Cart Bounce – Cart Recovery for WooCommerce, Gravity Forms, WPForms, EDD, PMPro and more Security & Risk Analysis

wordpress.org/plugins/cart-bounce

The universal abandoned cart recovery plugin.

0 active installs v1.0.6 PHP 7.2+ WP 6.2+ Updated Dec 8, 2024
abandoned-cartcart-recoverygravity-formswoocommercewpforms
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cart Bounce – Cart Recovery for WooCommerce, Gravity Forms, WPForms, EDD, PMPro and more Safe to Use in 2026?

Generally Safe

Score 92/100

Cart Bounce – Cart Recovery for WooCommerce, Gravity Forms, WPForms, EDD, PMPro and more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "cart-bounce" plugin v1.0.6 exhibits a generally good security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries without prepared statements (86% use prepared statements), and a high percentage of properly escaped output (93%) are positive indicators. The plugin also demonstrates an awareness of security by including nonce checks and capability checks. The lack of any recorded vulnerabilities, including CVEs, further strengthens this assessment, suggesting a history of responsible development or a lack of targeted attacks.

However, a few areas warrant careful consideration. The presence of file operations and external HTTP requests, while not inherently insecure, represent potential entry points for attack if not meticulously handled. The static analysis did not reveal any taint flows, which is a strong positive, but the absence of any AJAX handlers, REST API routes, or shortcodes means the attack surface is currently very small. This could change with future updates, and the security of these components will be crucial. The current data suggests a low risk profile, but ongoing vigilance and secure coding practices for any new features are essential.

Key Concerns

  • File operations present, needs careful handling
  • External HTTP requests present, requires validation
  • Low attack surface; future expansion needs careful security
Vulnerabilities
None known

Cart Bounce – Cart Recovery for WooCommerce, Gravity Forms, WPForms, EDD, PMPro and more Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Cart Bounce – Cart Recovery for WooCommerce, Gravity Forms, WPForms, EDD, PMPro and more Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
38 prepared
Unescaped Output
12
167 escaped
Nonce Checks
5
Capability Checks
1
File Operations
1
External Requests
4
Bundled Libraries
0

SQL Query Safety

86% prepared44 total queries

Output Escaping

93% escaped179 total outputs
Attack Surface

Cart Bounce – Cart Recovery for WooCommerce, Gravity Forms, WPForms, EDD, PMPro and more Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
actioninitadmin\class-idea-cb-post-type.php:49
actionadd_meta_boxesadmin\class-idea-cb-post-type.php:50
actionmanage_posts_custom_columnadmin\class-idea-cb-post-type.php:53
actionadmin_menuadmin\class-idea-cb-reports.php:30
actioninitadmin\class-idea-cb-settings.php:46
actionadmin_menuadmin\class-idea-cb-settings.php:47
actionadmin_noticesadmin\class-idea-cb-settings.php:48
filterwpsf_register_settings_idea_cbadmin\settings.php:13
actioninitincludes\class-idea-cart-bounce.php:130
actionadmin_enqueue_scriptsincludes\class-idea-cart-bounce.php:201
actionadmin_enqueue_scriptsincludes\class-idea-cart-bounce.php:202
actioncb_cart_bounce_cronincludes\class-idea-cart-bounce.php:204
actionwp_loadedincludes\class-idea-cart-bounce.php:215
actionwp_enqueue_scriptsincludes\class-idea-cart-bounce.php:216
actionwp_enqueue_scriptsincludes\class-idea-cart-bounce.php:217
actionedd_insert_paymentincludes\class-idea-cb-edd.php:57
actiongform_after_submissionincludes\class-idea-cb-gravityforms.php:56
filtergform_entry_metaincludes\class-idea-cb-gravityforms.php:57
actionadmin_menuincludes\class-idea-cb-leads.php:29
filterupload_dirincludes\class-idea-cb-notifications.php:582
actionpmpro_added_orderincludes\class-idea-cb-pmp.php:57
actionwoocommerce_new_orderincludes\class-idea-cb-woo.php:57
actionwpforms_process_completeincludes\class-idea-cb-wpforms.php:203
Maintenance & Trust

Cart Bounce – Cart Recovery for WooCommerce, Gravity Forms, WPForms, EDD, PMPro and more Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 8, 2024
PHP min version7.2
Downloads861

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Cart Bounce – Cart Recovery for WooCommerce, Gravity Forms, WPForms, EDD, PMPro and more Developer Profile

IdeaWP

2 plugins · 20 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cart Bounce – Cart Recovery for WooCommerce, Gravity Forms, WPForms, EDD, PMPro and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cart-bounce/admin/css/idea-cb-admin.css/wp-content/plugins/cart-bounce/admin/css/daterangepicker.css/wp-content/plugins/cart-bounce/admin/js/idea-cb-admin.js/wp-content/plugins/cart-bounce/admin/js/daterangepicker.min.js
Script Paths
admin/js/idea-cb-admin.jsadmin/js/daterangepicker.min.js
Version Parameters
idea-cb-admin?ver=daterangepicker?ver=idea-cb-admin?ver=idea_cb_daterange?ver=

HTML / DOM Fingerprints

CSS Classes
idea_cb_settingsidea_cb_date_range
Data Attributes
name='idea_cb_settings[general_settings_consider_abandoned][number]'name='idea_cb_settings[general_settings_consider_abandoned][interval]'data-nonce='idea_cb_ajax_nonce'
JS Globals
idea_cbidea_cb
FAQ

Frequently Asked Questions about Cart Bounce – Cart Recovery for WooCommerce, Gravity Forms, WPForms, EDD, PMPro and more