Floating cart for WooCommerce Security & Risk Analysis

wordpress.org/plugins/floating-cart-for-woo

Custom mini cart for WooCommerce. You can add to cart, update quantity in this cart via ajax. Also you can edit the style from the customizer.

10 active installs v1.1.3 PHP 7.2+ WP 5.2+ Updated Mar 3, 2022
ajax-cartajax-mini-cartfloating-cartmini-cartwoo-floating-cart
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Floating cart for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Floating cart for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "floating-cart-for-woo" plugin version 1.1.3 exhibits a generally good security posture regarding core WordPress security practices. The absence of SQL injection vulnerabilities, high percentage of properly escaped output, and zero external HTTP requests are positive indicators. Furthermore, the lack of any recorded historical vulnerabilities, including critical or high severity ones, suggests a consistent effort towards maintaining security over time.

However, the plugin presents a notable concern with its attack surface. With 8 AJAX handlers identified, a significant half (4) lack any authentication checks. This creates potential entry points for attackers to exploit if subsequent code within these handlers is not robustly secured. While no dangerous functions or unsanitized taint flows were detected in the static analysis, the unauthenticated AJAX handlers represent a tangible risk that could be exploited by malicious actors to trigger unintended actions within the plugin or WordPress site.

In conclusion, while the plugin benefits from clean code regarding database queries and output sanitization, the presence of unauthenticated AJAX endpoints is a significant weakness. This is the primary area of concern, and if exploited, could lead to various security issues depending on the functionality of those handlers. Addressing these unprotected AJAX handlers should be a priority for improving the plugin's overall security.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

Floating cart for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Floating cart for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
67 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped70 total outputs
Attack Surface
4 unprotected

Floating cart for WooCommerce Attack Surface

Entry Points8
Unprotected4

AJAX Handlers 8

authwp_ajax_fcfw_get_cartclasses\class-fcfw-public.php:22
noprivwp_ajax_fcfw_get_cartclasses\class-fcfw-public.php:23
authwp_ajax_fcfw_quanity_updateclasses\class-fcfw-public.php:24
noprivwp_ajax_fcfw_quanity_updateclasses\class-fcfw-public.php:25
authwp_ajax_fcfw_delete_itemclasses\class-fcfw-public.php:26
noprivwp_ajax_fcfw_delete_itemclasses\class-fcfw-public.php:27
authwp_ajax_fcfw_add_to_cartclasses\class-fcfw-public.php:29
noprivwp_ajax_fcfw_add_to_cartclasses\class-fcfw-public.php:30
WordPress Hooks 8
actioncustomize_registerclasses\class-fcfw-customizer.php:12
actioncustomize_controls_enqueue_scriptsclasses\class-fcfw-customizer.php:13
actionwp_headclasses\class-fcfw-public.php:18
actionwp_enqueue_scriptsclasses\class-fcfw-public.php:19
actionwp_footerclasses\class-fcfw-public.php:20
filterwc_add_to_cart_message_htmlclasses\class-fcfw-public.php:32
actionadmin_noticesfloating-cart-for-woo.php:69
actionplugins_loadedfloating-cart-for-woo.php:139
Maintenance & Trust

Floating cart for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 3, 2022
PHP min version7.2
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Floating cart for WooCommerce Developer Profile

Burhan Nasir

3 plugins · 2K total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Floating cart for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/floating-cart-for-woo/build/customizer.js
Version Parameters
floating-cart-for-woo/build/customizer.js?ver=

HTML / DOM Fingerprints

JS Globals
FCFW_VERSION
FAQ

Frequently Asked Questions about Floating cart for WooCommerce