
Clicklease Buttons Security & Risk Analysis
wordpress.org/plugins/clicklease-buttonsIncrease your sales by adding a "finance with Clicklease button".
Is Clicklease Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Clicklease Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "clicklease-buttons" v2.0.4 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions, exclusively using prepared statements for SQL queries, and achieving a high percentage of properly escaped output. The absence of known CVEs and a clean vulnerability history further contribute to its positive security profile. However, there are significant areas of concern. The plugin lacks any nonce checks or capability checks, which is a major oversight, especially concerning file operations and external HTTP requests. With 88 output operations, even a 90% escape rate leaves a small percentage potentially vulnerable to cross-site scripting (XSS). The presence of file operations and four external HTTP requests without any authentication or authorization checks presents a substantial risk, as these could be exploited by unauthenticated users. The plugin's strength lies in its clean code regarding SQL and its lack of past vulnerabilities, but the absence of fundamental security checks like nonces and capability checks on critical operations is a significant weakness that could lead to serious security incidents.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Potential for unescaped output (10% of 88)
- File operations without auth checks
- External HTTP requests without auth checks
Clicklease Buttons Security Vulnerabilities
Clicklease Buttons Code Analysis
Output Escaping
Clicklease Buttons Attack Surface
WordPress Hooks 22
Maintenance & Trust
Clicklease Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Clicklease Buttons Alternatives
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce
cartflows
1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.
PiWeb Live sales notification for WooCommerce
live-sales-notifications-for-woocommerce
Fake sales alert for WooCommerce or Live sales notification for WooCommerce. Boost sales by encouraging your visitors to buy when they see your live n …
FunnelKit – Funnel Builder for WooCommerce Checkout
funnel-builder
Create high-converting WooCommerce checkout pages, WooCommerce thank you pages & sales funnels with the highest-rated WordPress funnel builder.
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar
notificationx
Want to boost business trust & conversions? 97% of visitors hesitate to buy because of credibility. Instantly succeed with WooCommerce Sales Alert!
SALERT – Fake Sales Notification WooCommerce
salert
Display beautiful popup sales notification on your website with just few clicks.
Clicklease Buttons Developer Profile
1 plugin · 10 total installs
How We Detect Clicklease Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clicklease-buttons/dist/public.bundle.js/wp-content/plugins/clicklease-buttons/dist/admin.bundle.js/wp-content/plugins/clicklease-buttons/dist/public.bundle.js/wp-content/plugins/clicklease-buttons/dist/admin.bundle.jsHTML / DOM Fingerprints
CLS_PLUGIN_URLCL_SVGS_URL