
FS Product Inquiry Security & Risk Analysis
wordpress.org/plugins/fs-product-inquiryFS Product Inquiry Plugin is useful for the product inquiry that looks great and keeps your site loading fast.
Is FS Product Inquiry Safe to Use in 2026?
High Risk
Score 43/100FS Product Inquiry carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The "fs-product-inquiry" plugin v1.1.1 presents a mixed security posture with several concerning findings despite some good practices. While the absence of dangerous functions and the use of prepared statements for SQL queries are positive indicators, the significant number of unprotected AJAX handlers (4 out of 4) and the complete lack of nonce and capability checks on these entry points are major security liabilities. The taint analysis showing a high percentage of flows with unsanitized paths, although not reaching critical or high severity, suggests a potential for subtle input validation issues that could be exploited.
The plugin's vulnerability history is a significant concern, with two known medium severity CVEs, both currently unpatched. The recurring nature of Cross-Site Scripting vulnerabilities indicates a pattern of inadequate input sanitization and output escaping, especially considering that only 37% of outputs are properly escaped. This, combined with the unprotected AJAX handlers, creates a fertile ground for XSS attacks that could compromise user sessions or inject malicious content.
In conclusion, while the plugin demonstrates some secure coding practices like prepared SQL statements, the high number of unprotected entry points and the unpatched historical vulnerabilities, particularly XSS, outweigh these strengths. The risk assessment points to a medium to high-risk profile, requiring immediate attention to secure the AJAX handlers and address the underlying causes of past vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Missing capability checks
- Unescaped output
- Unpatched CVEs (2 x medium)
- Flows with unsanitized paths
FS Product Inquiry Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
FS Product Inquiry <= 1.1.1 - Unauthenticated Stored Cross-Site Scripting
FS Product Inquiry <= 1.1.1 - Reflected Cross-Site Scripting
FS Product Inquiry Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
FS Product Inquiry Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 17
Maintenance & Trust
FS Product Inquiry Maintenance & Trust
Maintenance Signals
Community Trust
FS Product Inquiry Alternatives
Product Enquiry for WooCommerce
product-enquiry-for-woocommerce
Product Enquiry allows prospective customers to "Make an Enquiry" about a product, or "Request a Quote" right from within the product page.
PiWeb Product Enquiry or product catalog for WooCommerce
enquiry-quotation-for-woocommerce
Product enquiry for WooCommerce and quote request plugin that can save enquiries and email the WooCommerce product enquiry as well
Product Catalog Mode For WooCommerce
product-catalog-mode-for-woocommerce
Product Catalog Mode for WooCommerce TURN INTO your online store as CATALOG ONLY MODE hiding by product price, Add to Cart button on a single click.
NSWP – Product Inquiry Form
nswp-product-inquiry-form
The WooCommerce product inquiry plugin adds a product enquiry button to every WooCommerce Product detail Page. Using this button, a potential customer …
OhmTang RFQ
ohmtang-rfq
OhmTang RFQ is a fully open-source and free RFQ (Request for Quotation) form plugin for WooCommerce that streamlines B2B inquiries.
FS Product Inquiry Developer Profile
3 plugins · 10 total installs
How We Detect FS Product Inquiry
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fs-product-inquiry/assets/admin/css/fspi-form.css/wp-content/plugins/fs-product-inquiry/assets/admin/js/fspi-admin-script.js/wp-content/plugins/fs-product-inquiry/assets/admin/js/fspi-admin-script.jsfs-product-inquiry/assets/admin/css/fspi-form.css?ver=fs-product-inquiry/assets/admin/js/fspi-admin-script.js?ver=HTML / DOM Fingerprints
fspi-main-settingfspi-form-groupfspi-form-lablefspi-form-inputnamevalueFSProductInquiryfspi_active_tab[fspi-show-products-list]