
Cross/Upsell Popup for WooCommerce Security & Risk Analysis
wordpress.org/plugins/cross-upsell-popup-for-woocommerceA simple plugin to boost your sales with WooCommerce Upsell and Cross-Sell offers upon purchase of particular products on any page.
Is Cross/Upsell Popup for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Cross/Upsell Popup for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "cross-upsell-popup-for-woocommerce" v1.0.0 presents a concerning security posture primarily due to a significant number of unprotected AJAX endpoints. The static analysis reveals 4 AJAX handlers, all of which lack authentication checks. This creates a wide attack surface where unauthenticated users could potentially interact with sensitive plugin functionality. While the code demonstrates good practices in other areas, such as using prepared statements for all SQL queries and a high percentage of properly escaped output, the absence of proper authorization on AJAX endpoints is a critical oversight. The plugin has no known vulnerability history, which is a positive sign, but it does not mitigate the immediate risks identified in the code. The taint analysis found two flows with unsanitized paths, although these did not reach critical or high severity, they still warrant attention. In conclusion, while the plugin avoids common pitfalls like raw SQL or unescaped output, the unprotected AJAX endpoints represent a substantial security weakness that needs immediate remediation.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths (minor)
Cross/Upsell Popup for WooCommerce Security Vulnerabilities
Cross/Upsell Popup for WooCommerce Release Timeline
Cross/Upsell Popup for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Cross/Upsell Popup for WooCommerce Attack Surface
AJAX Handlers 4
WordPress Hooks 11
Maintenance & Trust
Cross/Upsell Popup for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Cross/Upsell Popup for WooCommerce Alternatives
Leo Product Recommendations for WooCommerce
leo-product-recommendations
Boost WooCommerce sales with smart product recommendation popups on add to cart.
Frequently Bought Together Product For Woocommerce
frequently-bought-together-product-for-woocommerce
Boost WooCommerce sales with a Frequently Bought Together widget — display product bundles with per-product discounts on any product page.
UpsellWP – WooCommerce Upsell and Related Products Offers
checkout-upsell-and-order-bumps
Best WooCommerce Upsell plugin to create checkout upsells, cross-sells, order bumps and frequently bought together bundles to increase AOV.
Product Recommendations – Custom Locations
product-recommendations-custom-locations
Feature plugin for the official Product Recommendations extension that allows you to use shortcodes to recommend products in custom WooCommerce store …
Boost Sales for WooCommerce – Set up Up-Sells & Cross-Sells Popups & Auto Apply Coupon
woo-boost-sales
Boost Sales for WooCommerce with dynamic upsell popups, cross-sell bundles, and 'Frequently Bought Together' suggestions
Cross/Upsell Popup for WooCommerce Developer Profile
2 plugins · 50 total installs
How We Detect Cross/Upsell Popup for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cross-upsell-popup-for-woocommerce/assets/css/admin.css/wp-content/plugins/cross-upsell-popup-for-woocommerce/assets/css/popup.css/wp-content/plugins/cross-upsell-popup-for-woocommerce/assets/js/popup.js/wp-content/plugins/cross-upsell-popup-for-woocommerce/assets/js/popup.jscross-upsell-popup-for-woocommerce/assets/css/admin.css?ver=cross-upsell-popup-for-woocommerce/assets/css/popup.css?ver=cross-upsell-popup-for-woocommerce/assets/js/popup.js?ver=HTML / DOM Fingerprints
Cross_Up_Sell_Popup_For_WC