
Easy PayPal Shopping Cart Security & Risk Analysis
wordpress.org/plugins/easy-paypal-shopping-cartAdd a PayPal Shopping Cart to your website and start selling today. No Coding Required. Official PayPal Partner.
Is Easy PayPal Shopping Cart Safe to Use in 2026?
Generally Safe
Score 99/100Easy PayPal Shopping Cart has a strong security track record. Known vulnerabilities have been patched promptly.
The "easy-paypal-shopping-cart" plugin version 1.1.12 exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no unprotected entry points, no dangerous functions, and all SQL queries using prepared statements. The presence of a nonce check and a capability check indicates some consideration for security best practices. However, a significant concern is the output escaping, where only 65% of outputs are properly escaped, leaving room for potential cross-site scripting (XSS) vulnerabilities, particularly since XSS is a common historical vulnerability type for this plugin.
The vulnerability history is a major red flag. The plugin has a history of two known CVEs, including one high-severity and one medium-severity vulnerability. The fact that these are currently unpatched is a critical concern, suggesting that users of this version are exposed to known security flaws. The common vulnerability types (XSS and CSRF) further align with the static analysis findings regarding output escaping and the historical context.
In conclusion, while the plugin has made some efforts towards secure coding practices, the unpatched historical vulnerabilities and the incomplete output escaping present substantial risks. Users should be aware of the potential for XSS and CSRF attacks, and ideally, this plugin should be updated to a version where these historical issues have been addressed.
Key Concerns
- Unpatched CVE history
- Output escaping concern (35% not escaped)
- Historical XSS vulnerability type
- Historical CSRF vulnerability type
Easy PayPal Shopping Cart Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Easy PayPal Shopping Cart <= 1.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Easy PayPal Shopping Cart <= 1.1.9 - Cross-Site Request Forgery to Cross-Site Scripting
Easy PayPal Shopping Cart Code Analysis
Output Escaping
Data Flow Analysis
Easy PayPal Shopping Cart Attack Surface
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
Easy PayPal Shopping Cart Maintenance & Trust
Maintenance Signals
Community Trust
Easy PayPal Shopping Cart Alternatives
Shopping Cart & eCommerce Store
wp-easycart
A FREE WordPress eCommerce & WordPress Shopping Cart plugin that can sell products, subscriptions, downloads, services, donations, and much more o …
BORICA Payments by BORICA AD
borica-payments
Simple way of receiving debit and credit card payments by virtual POS.
Monetbil – Mobile Money Gateway for WooCommerce
monetbil-woocommerce-gateway
This is the Mobile Money payment gateway for WooCommerce.
UI for WordPress Simple Paypal Shopping Cart
ui-for-wp-simple-paypal-shopping-cart
Generates the short code for WordPress Simple Paypal Shopping Cart.
OKPAY Payment gateway
okpay-payment-gateway
This payment module extends WooCommerce and allows you to accept payments via OKPAY.
Easy PayPal Shopping Cart Developer Profile
12 plugins · 44K total installs
How We Detect Easy PayPal Shopping Cart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.