
Floating Wishlist for WooCommerce Security & Risk Analysis
wordpress.org/plugins/floating-wishlist-for-wooEasy to use, always on display, floating Wishlist for your WooCommerce store.
Is Floating Wishlist for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Floating Wishlist for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "floating-wishlist-for-woo" plugin v1.2 exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, making all SQL queries with prepared statements, and having no recorded vulnerabilities, significant concerns arise from its attack surface.
The plugin has two AJAX handlers, both of which lack any authentication checks. This presents a substantial risk, as any unauthenticated user could potentially trigger these actions, leading to unintended consequences depending on the functionality of these handlers. The lack of nonce checks further exacerbates this issue, as it makes the AJAX endpoints vulnerable to Cross-Site Request Forgery (CSRF) attacks. Furthermore, the plugin has a low percentage of properly escaped outputs, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed.
Despite the absence of past vulnerabilities, the current static analysis reveals critical weaknesses in authentication and output sanitization. The plugin's security is heavily reliant on the assumption that the underlying WordPress environment will enforce permissions, which is not always a robust defense. Therefore, while the plugin has a clean history, the current implementation's unprotected entry points and poor output escaping practices necessitate immediate attention to mitigate potential security risks.
Key Concerns
- AJAX handlers without authentication checks
- AJAX handlers without nonce checks
- Low percentage of properly escaped output
Floating Wishlist for WooCommerce Security Vulnerabilities
Floating Wishlist for WooCommerce Code Analysis
Output Escaping
Floating Wishlist for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
Floating Wishlist for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Floating Wishlist for WooCommerce Alternatives
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
Wishlist for WooCommerce
wt-woocommerce-wishlist
This WooCommerce wishlist plugin adds a wishlist feature to your WooCommerce store. Let the users easily add and manage products from their wishlist p …
Premmerce Wishlist for WooCommerce
premmerce-woocommerce-wishlist
This plugin provides the possibility for your customers to create wishlists with the further possibility to share them with friends.
Productive Commerce – Wishlist, Compare, Quick View, & MiniCart
productive-commerce
Integrate Wishlists, Product Comparison, Quick View, and Mini-Cart on your WooCommerce sites.
Categorize your Wishlist for Woocomerce,Posts & Custom Post Types
categorize-your-wishlist-for-woocomerceposts-custom-post-types
With this WooCommerce wishlist you can add any product to your wish list. Why should such an amazing feature only be restricted to the eCommerce websi …
Floating Wishlist for WooCommerce Developer Profile
2 plugins · 1K total installs
How We Detect Floating Wishlist for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/floating-wishlist-for-woo/admin/css/woo-floating-wishlist-admin.css/wp-content/plugins/floating-wishlist-for-woo/admin/js/woo-floating-wishlist-admin.js/wp-content/plugins/floating-wishlist-for-woo/admin/js/woo-floating-wishlist-admin.jswoo-floating-wishlist/admin/css/woo-floating-wishlist-admin.css?ver=woo-floating-wishlist/admin/js/woo-floating-wishlist-admin.js?ver=HTML / DOM Fingerprints
fwf-wishlist-containerfwf-wishlist-linkdata-fwf-wishlist-idfwf_wishlist_ajax_object