
CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links Security & Risk Analysis
wordpress.org/plugins/cartlink-generatorGenerate shareable direct-checkout & cart links with pre-filled products, quantities and custom prices. Perfect for WhatsApp & chat selling.
Is CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links Safe to Use in 2026?
Generally Safe
Score 100/100CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cartlink-generator plugin v1.0.3 exhibits a generally strong security posture based on the provided static analysis. All identified entry points, including AJAX handlers, appear to have proper authentication checks, which is a significant positive. Furthermore, the code demonstrates excellent security hygiene with 100% of SQL queries using prepared statements and 100% of outputs being properly escaped, mitigating common injection and cross-site scripting (XSS) vulnerabilities. The absence of known vulnerabilities in its history also suggests a well-maintained and secure codebase.
Despite these strengths, there are a couple of areas that warrant attention. The presence of two 'flows with unsanitized paths' in the taint analysis, even without critical or high severity, indicates a potential for path traversal vulnerabilities. While the file operation count is low, this warrants investigation. The lack of capability checks on any of its entry points is another concern, as it relies solely on AJAX authentication, which might not be granular enough for all use cases. The plugin does have nonce checks, which is good, but these should ideally be paired with capability checks for comprehensive security.
In conclusion, cartlink-generator v1.0.3 is well-defended against many common web vulnerabilities. However, the identified unsanitized paths and the absence of capability checks represent potential weaknesses that could be exploited if not addressed. The plugin's clean vulnerability history is a positive sign, but proactive measures against the identified code signals are recommended to maintain its security.
Key Concerns
- Taint flows with unsanitized paths detected
- No capability checks on entry points
CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links Security Vulnerabilities
CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links Release Timeline
CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links Code Analysis
Output Escaping
Data Flow Analysis
CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links Attack Surface
AJAX Handlers 3
WordPress Hooks 15
Maintenance & Trust
CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links Maintenance & Trust
Maintenance Signals
Community Trust
CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links Alternatives
Quick Buy Now Button for WooCommerce
quick-buy-now-button-for-woocommerce
WooCommerce Buy Now Button makes your customers' checkout process easier and faster.
WPC Buy Now Button for WooCommerce
wpc-buy-now-button
WPC Buy Now Button is the ultimate time-saving plugin that helps customers skip the cart page and get redirected straight to the checkout step.
WooCommerce Gateway Affirm
woocommerce-gateway-affirm
Affirm Payments for WooCommerce: Buy now, pay later for your business—but smarter. Increase conversions and AOV by offering shoppers flexible payment …
Quick Buy Now Button for WooCommerce
buy-now-woo
Buy Now Button for WooCommerce allowing customers to add products to the cart and proceed to checkout in one step.
Buy Now Button for WooCommerce
buy-now-button-for-woocommerce
Customers expect a fast and seamless shopping experience. Give shoppers the easiest way to make a purchase. The Buy Now Button for WooCommerce will he …
CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links Developer Profile
6 plugins · 720 total installs
How We Detect CartLink Generator for WooCommerce — Direct Checkout & Share Cart Links
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cartlink-generator/assets/admin-styles.css/wp-content/plugins/cartlink-generator/assets/admin-scripts.js/wp-content/plugins/cartlink-generator/assets/admin-scripts.jscartlink-generator/assets/admin-styles.css?ver=cartlink-generator/assets/admin-scripts.js?ver=HTML / DOM Fingerprints
clg_vars