
ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons Security & Risk Analysis
wordpress.org/plugins/elex-abandoned-cart-recovery-with-dynamic-couponsRecover abandoned carts with a series of predetermined, rule-based reminder emails that include dynamically generated smart discount coupons.
Is ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons Safe to Use in 2026?
Generally Safe
Score 100/100ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "elex-abandoned-cart-recovery-with-dynamic-coupons" v1.1.6 plugin exhibits a mixed security posture. On one hand, it demonstrates good practices with a high percentage of prepared SQL statements and properly escaped output. The presence of nonce checks and capability checks (though none are recorded as being actively enforced for certain entry points) is also a positive sign. The vulnerability history shows no previously recorded CVEs, which could indicate a history of secure development or simply a lack of past scrutiny.
However, significant concerns arise from the static analysis. The plugin has a substantial attack surface with 27 AJAX handlers, and critically, 2 of these lack any authentication checks. This creates direct entry points for unauthenticated attackers. The taint analysis reveals 4 high-severity flows with unsanitized paths, indicating potential for injection vulnerabilities if these flows are reachable by attackers. The absence of recorded capability checks for the identified AJAX handlers further exacerbates this risk, as it implies these handlers might be executed without proper authorization.
In conclusion, while the plugin avoids common pitfalls like widespread raw SQL queries or consistently unescaped output, the presence of unprotected AJAX handlers and high-severity unsanitized paths presents a clear and present danger. The lack of historical vulnerabilities is a positive but cannot override the immediate risks identified in the current code. A careful review and remediation of these specific entry points and taint flows are strongly recommended.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized paths in taint analysis
- No recorded capability checks for entry points
ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons Security Vulnerabilities
ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons Attack Surface
AJAX Handlers 27
WordPress Hooks 41
Scheduled Events 1
Maintenance & Trust
ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons Maintenance & Trust
Maintenance Signals
Community Trust
ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons Alternatives
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
woocommerce-jetpack
Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.
Abandoned Cart Recovery for WooCommerce
woo-abandoned-cart-recovery
A simple, effective solution to capture abandoned carts and auto-send reminders. Track logs and generate reports on carts, emails, and more
ShopMagic Abandoned Cart Recovery for WooCommerce
shopmagic-abandoned-carts
Allows saving customer details on partial WooCommerce purchases and sending abandoned cart emails.
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD
cart-lift
Track abandoned carts and send automated, customizable abandoned cart recovery emails. Get more leads, reduce cart abandonment, and increase revenue.
SMS Abandoned Cart Recovery ✦ CartBoss
cartboss
Boost your sales by recovering abandoned carts with pre-prepared & translated text messages!
ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons Developer Profile
22 plugins · 28K total installs
How We Detect ELEX WooCommerce Abandoned Cart Recovery with Dynamic Coupons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/elex-abandoned-cart-recovery-with-dynamic-coupons/assets/js/cart-scripts.js/wp-content/plugins/elex-abandoned-cart-recovery-with-dynamic-coupons/assets/css/cart-styles.css/wp-content/plugins/elex-abandoned-cart-recovery-with-dynamic-coupons/assets/js/admin-scripts.js/wp-content/plugins/elex-abandoned-cart-recovery-with-dynamic-coupons/assets/css/admin-styles.csselex-abandoned-cart-recovery-with-dynamic-coupons/assets/js/cart-scripts.js?ver=elex-abandoned-cart-recovery-with-dynamic-coupons/assets/css/cart-styles.css?ver=elex-abandoned-cart-recovery-with-dynamic-coupons/assets/js/admin-scripts.js?ver=elex-abandoned-cart-recovery-with-dynamic-coupons/assets/css/admin-styles.css?ver=HTML / DOM Fingerprints
elex-abandoned-cart-recovery-messageelex-abandoned-cart-recovery-buttonelex-abandoned-cart-recovery-form<!-- ELEX Abandoned Cart Recovery Plugin --><!-- This is a comment added by the ELEX Abandoned Cart Recovery plugin -->data-elex-cart-iddata-elex-actionwindow.elexAbandonedCartConfigvar elex_cart_settingsvar elex_cart_ajax_url/wp-json/elex-abandoned-cart/v1/track/wp-json/elex-abandoned-cart/v1/submit[elex_abandoned_cart_form][elex_abandoned_cart_button]