
Cart66 Lite Advance Sales Report Lite Security & Risk Analysis
wordpress.org/plugins/cart66-lite-advance-sales-report-liteCart66 Advance Sales Report Lite shows you all key sales information in one main Dashboard in very intuitive, easy to understand format which gives a …
Is Cart66 Lite Advance Sales Report Lite Safe to Use in 2026?
Generally Safe
Score 85/100Cart66 Lite Advance Sales Report Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "cart66-lite-advance-sales-report-lite" v1.0 presents a significant security concern due to its unprotected AJAX handler. While the plugin utilizes prepared statements for most SQL queries and has no known vulnerabilities, the presence of an unauthenticated AJAX endpoint creates a substantial attack surface. The lack of any capability or nonce checks on this entry point means that any user, even unauthenticated ones, could potentially trigger its functionality. This could lead to unintended actions, data exposure, or denial-of-service if the AJAX handler performs sensitive operations.
Furthermore, the static analysis reveals a critical weakness in output escaping, with 0% of outputs being properly escaped. This is a major concern as it exposes the plugin to potential Cross-Site Scripting (XSS) vulnerabilities. If any data processed by the AJAX handler is reflected back to the user without proper sanitization, an attacker could inject malicious scripts into the user's browser. The absence of any taint analysis flows doesn't negate these risks; it simply means that no such flows were detected in the analyzed code paths, not that they don't exist or are impossible.
The plugin's vulnerability history of zero CVEs is positive, suggesting a historically good security record or perhaps limited exposure. However, this historical data should not overshadow the immediate and evident security flaws identified in the current version's code. The combination of an unprotected AJAX endpoint and unescaped output creates a high-risk scenario that requires immediate attention.
Key Concerns
- Unprotected AJAX handler found
- No output escaping for 0% of outputs
- No nonce checks on entry points
- No capability checks on entry points
Cart66 Lite Advance Sales Report Lite Security Vulnerabilities
Cart66 Lite Advance Sales Report Lite Code Analysis
SQL Query Safety
Output Escaping
Cart66 Lite Advance Sales Report Lite Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Cart66 Lite Advance Sales Report Lite Maintenance & Trust
Maintenance Signals
Community Trust
Cart66 Lite Advance Sales Report Lite Alternatives
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Adminimize
adminimize
Adminimize that lets you hide 'unnecessary' items from the WordPress backend
Remove Dashboard Access
remove-dashboard-access-for-non-admins
Disable Dashboard access for users of a specific role or capability. Disallowed users are redirected to a chosen URL. Get set up in seconds.
Error Log Monitor
error-log-monitor
Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.
Automatic Domain Changer
automatic-domain-changer
Automatically detects a domain name change, and updates all the WordPress tables in the database to reflect this change.
Cart66 Lite Advance Sales Report Lite Developer Profile
6 plugins · 60 total installs
How We Detect Cart66 Lite Advance Sales Report Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cart66-lite-advance-sales-report-lite/assets/graph/scripts/graph.js/wp-content/plugins/cart66-lite-advance-sales-report-lite/assets/css/admin.css/wp-content/plugins/cart66-lite-advance-sales-report-lite/assets/graph/css/jquery.jqplot.min.css/wp-content/plugins/cart66-lite-advance-sales-report-lite/assets/graph/scripts/jquery.jqplot.min.js/wp-content/plugins/cart66-lite-advance-sales-report-lite/assets/graph/scripts/jqplot.pieRenderer.min.js/wp-content/plugins/cart66-lite-advance-sales-report-lite/assets/graph/scripts/jqplot.meterGaugeRenderer.min.js/wp-content/plugins/cart66-lite-advance-sales-report-lite/assets/graph/scripts/jqplot.pointLabels.min.js/wp-content/plugins/cart66-lite-advance-sales-report-lite/assets/graph/scripts/jqplot.dateAxisRenderer.min.jsHTML / DOM Fingerprints
ic_mis_reportic_cr_wrapwoo_cr-reports-wrapwoo_cr-reports-topThreeCol_BoxesLastBox_Marginid="today_order_count_meter_gauge"id="top_product_pie_chart"id="last_7_days_sales_order_amount"ajax_object