
Every Page Shopify Cart Tab Security & Risk Analysis
wordpress.org/plugins/every-page-shopify-cartDescription: Shopify is a leading eCommerce Platform. WordPress is the #1 website platform. But what happens if you want to add your Shopify Buy Butto …
Is Every Page Shopify Cart Tab Safe to Use in 2026?
Generally Safe
Score 100/100Every Page Shopify Cart Tab has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "every-page-shopify-cart" v1.0 plugin exhibits a mixed security posture. On the positive side, there are no identified AJAX handlers, REST API routes, shortcodes, or cron events that constitute an attack surface, and the plugin does not perform file operations or external HTTP requests. Crucially, all SQL queries utilize prepared statements, and there is no known vulnerability history.
However, significant concerns arise from the static analysis. The complete absence of capability checks and nonce checks, combined with 0% of output escaping, presents a notable risk. While the taint analysis shows no critical or high severity flows, the presence of 2 flows with unsanitized paths indicates potential vulnerabilities that could be exploited if they interact with user-controlled input, especially given the lack of output escaping. The absence of any security checks (capability, nonce) on its entry points, though currently numbering zero, leaves it highly vulnerable should any be introduced or discovered in future versions.
In conclusion, while the plugin's current attack surface is minimal and it lacks a history of public vulnerabilities, the code analysis reveals critical weaknesses in output handling and a complete lack of authorization and integrity checks. This means that even minor inputs could lead to issues, and any future expansion of the plugin's functionality without addressing these fundamental security gaps would be highly risky.
Key Concerns
- Output escaping is not implemented
- Missing capability checks on all entry points
- Missing nonce checks on all entry points
- Taint flows with unsanitized paths
Every Page Shopify Cart Tab Security Vulnerabilities
Every Page Shopify Cart Tab Code Analysis
Output Escaping
Data Flow Analysis
Every Page Shopify Cart Tab Attack Surface
WordPress Hooks 4
Maintenance & Trust
Every Page Shopify Cart Tab Maintenance & Trust
Maintenance Signals
Community Trust
Every Page Shopify Cart Tab Alternatives
Multi Page Auto Advance for Gravity Forms
auto-advance-for-gravity-forms
Description: The Auto Advance plugin for Gravity Forms makes the form filling process quicker and more user friendly for visitors.
Real Time Validation for Gravity Forms
real-time-validation-for-gravity-forms
Real Time Validation for Gravity Forms increases conversion rates of your Gravity Form using inline validation messages as user types in field.
Retrigger Notifications Gravity Forms
retrigger-notifications-gravity-forms
Resend Gravity Forms entry data to Zapier and Webhook feeds with one click -- no need to resubmit the form.
WP Gravity Forms HubSpot
gf-hubspot
Gravity Forms HubSpot Add-on sends Gravity Forms entries to HubSpot.
WP-Stateless – Gravity Forms Addon
wp-stateless-gravity-forms-addon
Provides compatibility between the Gravity Forms and the WP-Stateless plugins.
Every Page Shopify Cart Tab Developer Profile
3 plugins · 3K total installs
How We Detect Every Page Shopify Cart Tab
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/every-page-shopify-cart/js/custom-script.jsHTML / DOM Fingerprints
name="shopify_domain"name="shopify_access_token"name="cart_tab_button_color"name="cart_tab_button_hover_color"name="cart_tab_button_text_color"window.ShopifyBuy