Content Shelf Shopping Cart Security & Risk Analysis

wordpress.org/plugins/content-shelf-shopping-cart

Content Shelf is shopping cart software for selling digital content, tangible products, services, subscriptions and gift cards.

10 active installs v1.0.0 PHP + WP 2.8+ Updated Feb 25, 2016
content-shelfecommerceshopping-cartwordpress-ecommercewp-e-commerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Content Shelf Shopping Cart Safe to Use in 2026?

Generally Safe

Score 85/100

Content Shelf Shopping Cart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "content-shelf-shopping-cart" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing any dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities or CVEs. This indicates a developer who is likely aware of common security pitfalls.

However, significant concerns arise from the static analysis. The complete absence of output escaping for all 34 identified outputs is a critical weakness. This means that any user-supplied data that is displayed by the plugin is likely vulnerable to cross-site scripting (XSS) attacks. Furthermore, the lack of any nonce checks or capability checks on the identified entry points (shortcodes) is a major oversight. This could allow unauthorized users to trigger plugin functionalities, potentially leading to unintended consequences or further exploitation.

While the vulnerability history is clean, it does not mitigate the risks identified in the code. The absence of vulnerabilities might simply reflect a lack of exploitation attempts rather than inherent security. The plugin's strengths lie in its clean SQL practices and lack of historical issues, but these are overshadowed by the severe lack of output sanitization and authorization checks on its entry points.

Key Concerns

  • No output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Content Shelf Shopping Cart Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Content Shelf Shopping Cart Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped34 total outputs
Attack Surface

Content Shelf Shopping Cart Attack Surface

Entry Points7
Unprotected0

Shortcodes 7

[contentshelf] contentshelf-shopping-cart.php:834
[contentshelf_cart_count] contentshelf-shopping-cart.php:835
[contentshelf_categories] contentshelf-shopping-cart.php:836
[contentshelf_language] contentshelf-shopping-cart.php:837
[contentshelf_search] contentshelf-shopping-cart.php:838
[contentshelf_store] contentshelf-shopping-cart.php:839
[contentshelf_store_page] contentshelf-shopping-cart.php:840
WordPress Hooks 5
actionadmin_initcontentshelf-shopping-cart.php:819
actionadmin_initcontentshelf-shopping-cart.php:820
actionadmin_menucontentshelf-shopping-cart.php:822
actionadmin_menucontentshelf-shopping-cart.php:823
actionwidgets_initcontentshelf-shopping-cart.php:826
Maintenance & Trust

Content Shelf Shopping Cart Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedFeb 25, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Content Shelf Shopping Cart Developer Profile

contentshelf

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Content Shelf Shopping Cart

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/content-shelf-shopping-cart/css/contentshelf-product-search.css/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-search.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-cart.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-product-details.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-checkout.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-shipping-calculator.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-product-list.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-cart-count.js+1 more
Script Paths
/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-search.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-cart.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-product-details.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-checkout.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-shipping-calculator.js/wp-content/plugins/content-shelf-shopping-cart/js/contentshelf-product-list.js+2 more
Version Parameters
content-shelf-shopping-cart/css/contentshelf-product-search.css?ver=content-shelf-shopping-cart/js/contentshelf-search.js?ver=content-shelf-shopping-cart/js/contentshelf-cart.js?ver=content-shelf-shopping-cart/js/contentshelf-product-details.js?ver=content-shelf-shopping-cart/js/contentshelf-checkout.js?ver=content-shelf-shopping-cart/js/contentshelf-shipping-calculator.js?ver=content-shelf-shopping-cart/js/contentshelf-product-list.js?ver=content-shelf-shopping-cart/js/contentshelf-cart-count.js?ver=content-shelf-shopping-cart/js/contentshelf-language.js?ver=

HTML / DOM Fingerprints

CSS Classes
contentshelf-cart-widgetcontentshelf-cart-countcontentshelf-language-widgetcontentshelf-search-widgetcontentshelf-product-search-form
Data Attributes
data-contentshelf-product-iddata-contentshelf-store-iddata-contentshelf-add-to-cart-url
JS Globals
contentshelf_cart_datacontentshelf_currency_symbolcontentshelf_product_details_objcontentshelf_checkout_objcontentshelf_shipping_calculator_objcontentshelf_product_list_obj+2 more
Shortcode Output
[contentshelf_product_details][contentshelf_cart][contentshelf_checkout][contentshelf_shipping_calculator]
FAQ

Frequently Asked Questions about Content Shelf Shopping Cart