eCommerce Shopping Cart by Inventory.com Security & Risk Analysis

wordpress.org/plugins/ecommerce-shopping-cart-by-inventorycom

eCommerce Shopping Cart plugin backed by a powerful order and inventory management service.

10 active installs v1.0.2 PHP + WP 3.5+ Updated Jan 27, 2014
commercedashboarde-commerceecommercereportin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is eCommerce Shopping Cart by Inventory.com Safe to Use in 2026?

Generally Safe

Score 85/100

eCommerce Shopping Cart by Inventory.com has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "ecommerce-shopping-cart-by-inventorycom" plugin v1.0.2 presents a mixed security posture. On one hand, the static analysis indicates a very small attack surface with no apparent direct entry points like AJAX handlers, REST API routes, or shortcodes that lack authorization checks. The absence of known CVEs and a history of vulnerabilities further suggests a potentially stable and secure plugin. However, significant concerns arise from the code analysis.

The plugin utilizes raw SQL queries without prepared statements, which is a common vector for SQL injection vulnerabilities. Furthermore, a critical finding is that none of the observed output operations are properly escaped. This lack of output escaping makes the plugin highly susceptible to Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected and executed in the user's browser.

While the plugin has a clean vulnerability history and a limited attack surface, the presence of unescaped output and raw SQL queries represents serious security weaknesses. The taint analysis revealing a flow with unsanitized paths, even if not classified as critical or high severity in this report, combined with the other code signals, points to potential risks that could be exploited. The strengths in attack surface minimization are heavily counteracted by the weaknesses in output handling and data sanitization.

Key Concerns

  • Raw SQL queries without prepared statements
  • No properly escaped output detected
  • Flow with unsanitized paths (taint analysis)
Vulnerabilities
None known

eCommerce Shopping Cart by Inventory.com Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

eCommerce Shopping Cart by Inventory.com Release Timeline

v1.0.2Current
v1.0.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

eCommerce Shopping Cart by Inventory.com Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
114
0 escaped
Nonce Checks
2
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

0% escaped114 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<main.tpl> (views\main.tpl.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

eCommerce Shopping Cart by Inventory.com Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filtertemplate_includeplugin.php:24
Maintenance & Trust

eCommerce Shopping Cart by Inventory.com Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJan 27, 2014
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

eCommerce Shopping Cart by Inventory.com Developer Profile

pluginventoryteam

2 plugins · 80 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect eCommerce Shopping Cart by Inventory.com

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ecommerce-shopping-cart-by-inventorycom/js/ec-cart.js/wp-content/plugins/ecommerce-shopping-cart-by-inventorycom/js/ec-checkout.js/wp-content/plugins/ecommerce-shopping-cart-by-inventorycom/js/ec-single-product.js/wp-content/plugins/ecommerce-shopping-cart-by-inventorycom/css/ec-main.css/wp-content/plugins/ecommerce-shopping-cart-by-inventorycom/css/ec-single-product.css/wp-content/plugins/ecommerce-shopping-cart-by-inventorycom/css/ec-checkout.css
Script Paths
/wp-content/plugins/ecommerce-shopping-cart-by-inventorycom/js/ec-cart.js/wp-content/plugins/ecommerce-shopping-cart-by-inventorycom/js/ec-checkout.js/wp-content/plugins/ecommerce-shopping-cart-by-inventorycom/js/ec-single-product.js
Version Parameters
ecommerce-shopping-cart-by-inventorycom/js/ec-cart.js?ver=ecommerce-shopping-cart-by-inventorycom/js/ec-checkout.js?ver=ecommerce-shopping-cart-by-inventorycom/js/ec-single-product.js?ver=ecommerce-shopping-cart-by-inventorycom/css/ec-main.css?ver=ecommerce-shopping-cart-by-inventorycom/css/ec-single-product.css?ver=ecommerce-shopping-cart-by-inventorycom/css/ec-checkout.css?ver=

HTML / DOM Fingerprints

CSS Classes
ec_product_fullec_swipeGalleryec_product_titleec_eanec_matrixec_stockec_hide_mobile
Data Attributes
id="ec_swipeGallery"
FAQ

Frequently Asked Questions about eCommerce Shopping Cart by Inventory.com