
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD Security & Risk Analysis
wordpress.org/plugins/cart-liftTrack abandoned carts and send automated, customizable abandoned cart recovery emails. Get more leads, reduce cart abandonment, and increase revenue.
Is Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD Safe to Use in 2026?
Generally Safe
Score 99/100Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD has a strong security track record. Known vulnerabilities have been patched promptly.
The "cart-lift" v3.1.55 plugin presents a mixed security posture. While it demonstrates some good practices, such as a high percentage of SQL queries using prepared statements and a decent number of nonce and capability checks, significant concerns exist. The plugin has a broad attack surface, with 14 AJAX handlers, 12 of which lack authorization checks, creating a substantial risk of unauthorized actions. Furthermore, the taint analysis reveals 7 high-severity flows with unsanitized paths, indicating a strong possibility of code injection or data manipulation vulnerabilities. The presence of the "unserialize" function is also a red flag, as it can be a vector for deserialization vulnerabilities if not handled with extreme care and proper input validation.
The vulnerability history shows 2 previously disclosed medium-severity CVEs, specifically related to Cross-site Scripting and Missing Authorization. While there are currently no unpatched vulnerabilities, the recurring pattern of missing authorization and input handling issues, as seen in both historical CVEs and current taint analysis, suggests a persistent weakness in how user input is processed and secured. The fact that 26% of outputs are not properly escaped also contributes to the XSS risk.
In conclusion, while "cart-lift" v3.1.55 has some strengths, the high number of unprotected AJAX handlers, significant high-severity taint flows, and past vulnerabilities in authorization and XSS point to a considerable risk. The use of `unserialize` without further context is also a concern. Recommendations should focus on strengthening authorization checks for all AJAX endpoints and thoroughly sanitizing all input that is passed to dangerous functions like `unserialize` and used in output.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Dangerous function usage (unserialize)
- Low output escaping percentage
- Medium severity CVEs in history
- Bundled library (Select2)
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD <= 3.1.5 - Reflected Cross-Site Scripting via cart_search
Appsero <= 1.2.1 - Missing Authorization
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD Attack Surface
AJAX Handlers 14
WordPress Hooks 72
Scheduled Events 2
Maintenance & Trust
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD Maintenance & Trust
Maintenance Signals
Community Trust
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD Alternatives
Abandoned Cart Recovery for WooCommerce
woo-abandoned-cart-recovery
A simple, effective solution to capture abandoned carts and auto-send reminders. Track logs and generate reports on carts, emails, and more
LetsRecover – WooCommerce Abandoned Cart Notifications
letsrecover-woocommerce-abandoned-cart
Recover your lost revenue and abandoned carts using multiple automated Web Push Notification reminder by WooCommerce Abandoned Cart Recovery Notificat …
ShopMagic – email automation
shopmagic-for-woocommerce
Flexible email automation and workflows triggered by customer and site events.
Bulk Edit Posts and Products in Spreadsheet
wp-sheet-editor-bulk-spreadsheet-editor-for-posts-and-pages
Modern Bulk Editor for Posts and Pages, create and edit hundreds of posts at once in a spreadsheet inside wp-admin. Search and quick edits.
AffiliateWP – Affiliate Product Rates
affiliatewp-affiliate-product-rates
Allows you to set product referral rates on a per-affiliate level in AffiliateWP.
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD Developer Profile
3 plugins · 21K total installs
How We Detect Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cart-lift/admin/js//wp-content/plugins/cart-lift/admin/assets/admin/js/includes/aes-encryption/includes/cart-lift/cart-lift.php?ver=cart-lift/includes/aes-encryption/class-cart-lift-aes.php?ver=cart-lift/includes/aes-encryption/class-cart-lift-aes-counter.php?ver=cart-lift/includes/actions.php?ver=cart-lift/includes/class-cart-lift-dependency-checker.php?ver=cart-lift/includes/helper.php?ver=cart-lift/includes/class-cart-lift-activator.php?ver=cart-lift/includes/class-cart-lift-deactivator.php?ver=cart-lift/includes/class-cart-lift.php?ver=HTML / DOM Fingerprints
cartlift-admin-global-stylecart_lift_security_keyCART_LIFT_VERSIONCART_LIFT_FILECART_LIFT_BASECART_LIFT_DIRCART_LIFT_URLCART_LIFT_DEV_MODE+9 more