
CoCart JWT Authentication Security & Risk Analysis
wordpress.org/plugins/cocart-jwt-authenticationJWT Authentication for CoCart API.
Is CoCart JWT Authentication Safe to Use in 2026?
Generally Safe
Score 100/100CoCart JWT Authentication has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cocart-jwt-authentication v3.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and properly escaping all outputs. The absence of file operations, external HTTP requests, and known past vulnerabilities suggests a generally well-maintained codebase. However, significant concerns arise from the static analysis. The presence of two dangerous `exec` functions is a critical red flag, as these can be exploited to execute arbitrary code on the server if user input is not rigorously sanitized. Furthermore, one of the two REST API routes lacks permission callbacks, creating an unprotected entry point that could be leveraged for unauthorized actions or information disclosure. The lack of nonce checks on AJAX handlers, although there are no AJAX handlers to check, is a potential weakness if the plugin were to introduce them in the future without proper security measures. The vulnerability history being clean is a positive indicator, but it doesn't negate the inherent risks identified in the current code.
Key Concerns
- REST API route without permission callbacks
- Dangerous function 'exec' found
CoCart JWT Authentication Security Vulnerabilities
CoCart JWT Authentication Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
CoCart JWT Authentication Attack Surface
REST API Routes 2
WordPress Hooks 24
Scheduled Events 2
Maintenance & Trust
CoCart JWT Authentication Maintenance & Trust
Maintenance Signals
Community Trust
CoCart JWT Authentication Alternatives
CoCart – Headless REST API for WooCommerce
cart-rest-api-for-woocommerce
A developer-first REST API to decouple WooCommerce on the frontend to help build modern and scalable storefronts. Fast, secure, customizable, easy.
CoCart CORS Support
cocart-cors
Enables support for CORS to allow CoCart to work across multiple domains.
CoCart – Cart API Enhanced
cocart-get-cart-enhanced
Enhances CoCart's cart REST API response.
CoCart – Rate Limiting
cocart-rate-limiting
Enables the rate limiting feature for CoCart.
Hippoo Auth
hippoo-auth
Extend your WooCommerce Store API with secure authentication endpoints for social and manual login. Ideal for custom apps, headless themes, or fronten …
CoCart JWT Authentication Developer Profile
5 plugins · 2K total installs
How We Detect CoCart JWT Authentication
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cocart-jwt-authentication/assets/js/jwt-setup.js/wp-content/plugins/cocart-jwt-authentication/assets/js/jwt-setup.jscocart-jwt-authentication/assets/js/jwt-setup.js?ver=HTML / DOM Fingerprints
cocart-jwt-setupcocart_jwt_setup