
Finch Cart — Added-to-Cart Popup for WooCommerce Security & Risk Analysis
wordpress.org/plugins/finch-cart-product-recommendationsThe Finch cart displays WooCommerce product recommendations in a popup when a product is added to the cart. Added to cart notification popup.
Is Finch Cart — Added-to-Cart Popup for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Finch Cart — Added-to-Cart Popup for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'finch-cart-product-recommendations' v1.03 exhibits a generally good security posture with several strengths. The absence of any recorded vulnerabilities (CVEs) and a low number of SQL queries, all of which are properly prepared, are positive indicators. Furthermore, the vast majority of output is correctly escaped, and there are no observed file operations or external HTTP requests, significantly reducing common attack vectors. The presence of nonces and capability checks further bolsters its security.
However, the plugin does present some areas for concern. A notable weakness is the presence of 12 AJAX handlers, with a significant portion (4) lacking any authentication checks. This represents a considerable attack surface that could be exploited if specific conditions are met within these unprotected AJAX endpoints. While taint analysis did not reveal any unsanitized paths, the unprotected AJAX endpoints could still be a point of entry for unintended actions or information disclosure depending on their functionality.
In conclusion, while the plugin demonstrates strong practices in areas like SQL handling and output escaping, the unprotected AJAX endpoints are a critical security weakness that needs immediate attention. The lack of historical vulnerabilities is encouraging, but it does not negate the inherent risks posed by the identified unprotected entry points. Addressing these unprotected AJAX handlers should be the priority to improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
Finch Cart — Added-to-Cart Popup for WooCommerce Security Vulnerabilities
Finch Cart — Added-to-Cart Popup for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Finch Cart — Added-to-Cart Popup for WooCommerce Attack Surface
AJAX Handlers 12
WordPress Hooks 64
Maintenance & Trust
Finch Cart — Added-to-Cart Popup for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Finch Cart — Added-to-Cart Popup for WooCommerce Alternatives
Cart Popup for WooCommerce
woo-cart-popup
Adds Cart icon accross site at bottom that contains list of added cart items and cart button, Empty Cart Button and proceed to checkout button.
Cart Popup for WooCommerce
added-to-cart-popup-woocommerce
Cart Popup for WooCommerce enables Ajax add-to-cart and displays an instant popup showing the added product.
Leo Product Recommendations for WooCommerce
leo-product-recommendations
Boost WooCommerce sales with smart product recommendation popups on add to cart.
Ajax Side Cart Button for WooCommerce eshop
custom-woo-cart-button
Add a custom cart button for WooCommerce eshop to boost you sales and help your customers speedup checkout process
Side Cart Woocommerce | Woocommerce Cart
side-cart-woocommerce
Manage your cart from just a click away with an interactive design
Finch Cart — Added-to-Cart Popup for WooCommerce Developer Profile
25 plugins · 40K total installs
How We Detect Finch Cart — Added-to-Cart Popup for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/finch-cart-product-recommendations/assets/css/jBox.min.css/wp-content/plugins/finch-cart-product-recommendations/assets/js/jBox.min.js/wp-content/plugins/finch-cart-product-recommendations/assets/swiper/swiper-bundle.min.css/wp-content/plugins/finch-cart-product-recommendations/assets/swiper/swiper-bundle.min.js/wp-content/plugins/finch-cart-product-recommendations/assets/css/finch-cart-frontend.css/wp-content/plugins/finch-cart-product-recommendations/assets/js/finch-cart-frontend.js/wp-content/plugins/finch-cart-product-recommendations/assets/js/jBox.min.js/wp-content/plugins/finch-cart-product-recommendations/assets/swiper/swiper-bundle.min.js/wp-content/plugins/finch-cart-product-recommendations/assets/js/finch-cart-frontend.jsfinch-cart-jBoxfinch-cart-jBoxfinch-cart-swiperjsfinch-cart-swiperjsfinch-cart-frontendfinch-cart-frontendHTML / DOM Fingerprints
FinchCartVars