
Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Security & Risk Analysis
wordpress.org/plugins/custom-add-to-cart-button-for-woocommerceUltimate Custom Add To Cart Button For WooCommerce let you fully customize the add to cart button on your WooCommerce store.
Is Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Safe to Use in 2026?
Mostly Safe
Score 71/100Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "custom-add-to-cart-button-for-woocommerce" plugin v1.222.17 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and includes a reasonable number of capability checks and nonce checks. There are no identified dangerous functions or critical/high severity taint flows, indicating a generally well-developed core. However, significant concerns arise from the attack surface analysis, specifically the presence of four AJAX handlers with three lacking proper authentication checks. This presents a substantial risk for unauthorized actions on the site. Additionally, a significant portion of output escaping is not properly implemented, potentially leading to cross-site scripting vulnerabilities.
The vulnerability history further exacerbates these concerns. The existence of one currently unpatched medium severity CVE, with the common vulnerability type being "Missing Authorization," directly correlates with the observed unprotected AJAX handlers. This suggests a recurring and potentially unresolved issue within the plugin's authorization logic. While the plugin has strengths in its database interaction and some security checks, the combination of a large unprotected attack surface and past authorization-related vulnerabilities creates a notable risk profile. Users should exercise caution until these issues are addressed.
Key Concerns
- Unpatched CVE (Medium Severity)
- Unprotected AJAX Handlers (3/4)
- Low Output Escaping Percentage (21%)
Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter <= 1.222.17 - Missing Authorization
Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Code Analysis
Output Escaping
Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Attack Surface
AJAX Handlers 4
WordPress Hooks 18
Maintenance & Trust
Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Maintenance & Trust
Maintenance Signals
Community Trust
Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Alternatives
Custom Add to Cart Button Label and Link for WooCommerce
woo-custom-cart-button
Custom Add to Cart Button Label and Link for WooCommerce is the ultimate plugin to personalize your WooCommerce store's add to cart experience.
Custom WooCommerce Add to Cart
custom-text-on-add-to-cart-button-for-woocommerce
Customize the WooCommerce "Add to Cart" button text on a per-product basis.
Add to Cart Button Pro for WooCommerce
add-to-cart-button-for-woocommerce
Customize the Add to Cart button text, color, size, and other styles for different products. Add a floated or sticky Add to Cart button on the screen
Order auto complete for WooCommerce
order-auto-complete-for-woocommerce
It is a simple woocommerce addon or extension.If Enable the plugin, then your all woocommerce order will be automatically completed.
Remove Add to Cart Button for WooCommerce
remove-add-to-cart-button-for-woocommerce
Remove Add to Cart Button for WooCommerce plugin gives you a really easy interface to hide/remove the product Add to Cart button and product price.
Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Developer Profile
7 plugins · 3K total installs
How We Detect Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-add-to-cart-button-for-woocommerce/assets/js/bc-atc-admin.js/wp-content/plugins/custom-add-to-cart-button-for-woocommerce/assets/css/bc-atc-admin.css/wp-content/plugins/custom-add-to-cart-button-for-woocommerce/assets/js/bc-atc-frontend.js/wp-content/plugins/custom-add-to-cart-button-for-woocommerce/assets/css/bc-atc-frontend.csscustom-add-to-cart-button-for-woocommerce/assets/js/bc-atc-admin.js?ver=custom-add-to-cart-button-for-woocommerce/assets/css/bc-atc-admin.css?ver=custom-add-to-cart-button-for-woocommerce/assets/js/bc-atc-frontend.js?ver=custom-add-to-cart-button-for-woocommerce/assets/css/bc-atc-frontend.css?ver=HTML / DOM Fingerprints
btc-uatc-max-qtybc-atc-qty-containerbc-atc-qtybc-atc-page-singlebc-atc-qty-changerbc-atc-qty-decreasebc-atc-text-inputbc-atc-qty-input+6 morepro 2.45.5free 1.122add support for woocommerce deposit products, by default, products with deposit enabledhave the text select option+3 moredata-product_idbc_uatc_current_pagebc_uatc_settingsbc_atc_save_options/wp-json/bc-uatc/v1/settings