
Product Enquiry for WooCommerce Security & Risk Analysis
wordpress.org/plugins/gm-woocommerce-quote-popupAllow customers to request quotes, send product enquiries, and run WooCommerce in catalog mode by hiding prices and replacing the Add to Cart button.
Is Product Enquiry for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Product Enquiry for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'gm-woocommerce-quote-popup' plugin v3.2 exhibits a mixed security posture. On the positive side, the static analysis reveals a well-defined attack surface with all identified entry points (AJAX, REST API, shortcodes) protected by authentication or permission checks. Furthermore, the absence of dangerous functions and a complete lack of critical or high severity taint flows are encouraging signs. The plugin also demonstrates good practices by utilizing nonces and capability checks. However, several concerns remain. A significant portion of SQL queries are not using prepared statements, posing a risk of SQL injection. Similarly, a notable percentage of output is not properly escaped, increasing the likelihood of Cross-Site Scripting (XSS) vulnerabilities. The plugin also performs external HTTP requests, which could be leveraged in certain attack vectors if not handled securely.
The vulnerability history for this plugin is a significant red flag. With a total of 5 known CVEs, including one high and four medium severity vulnerabilities, it indicates a recurring pattern of security weaknesses. The common types of vulnerabilities (CSRF, XSS) further reinforce this. While there are currently no unpatched vulnerabilities, the past issues suggest a need for vigilance and prompt patching in the future. The last vulnerability was as recent as January 2024, indicating ongoing security challenges.
In conclusion, while the current version appears to have addressed its immediate vulnerabilities and implemented some good security practices, the plugin's historical record of multiple high and medium severity vulnerabilities, coupled with the static analysis findings regarding SQL query preparation and output escaping, warrants caution. Users should remain aware of its past security issues and the potential for undiscovered or reintroduced vulnerabilities.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
- High vulnerability history
- Medium vulnerability history
- External HTTP requests
Product Enquiry for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Product Enquiry for WooCommerce <= 3.1 - Reflected Cross-Site Scripting
Product Enquiry for WooCommerce <= 3.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Product Enquiry for WooCommerce <= 3.0 - Cross-Site Request Forgery
Product Enquiry for WooCommerce <= 3.0 - Unauthenticated Stored Cross-Site Scripting
Product Enquiry for WooCommerce <= 3.1 - Unauthenticated Stored Cross-Site Scripting via name
Product Enquiry for WooCommerce Release Timeline
Product Enquiry for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Product Enquiry for WooCommerce Attack Surface
AJAX Handlers 2
REST API Routes 6
Shortcodes 2
WordPress Hooks 19
Maintenance & Trust
Product Enquiry for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Product Enquiry for WooCommerce Alternatives
Product Enquiry for WooCommerce
product-enquiry-for-woocommerce
Product Enquiry allows prospective customers to "Make an Enquiry" about a product, or "Request a Quote" right from within the product page.
Hide price and add to cart Lite
hide-price-and-add-to-cart-for-woocommerce
Hide Price and Add to Cart Lite for WooCommerce allows you to hide product prices and the Add to Cart button using flexible rule-based control.
YITH WooCommerce Catalog Mode
yith-woocommerce-catalog-mode
YITH WooCommerce Catalog Mode, a plugin for disabling sales in your e-commerce and turn it into an e-commerce into an online catalogue.
ELEX WooCommerce Catalog Mode
elex-woocommerce-catalog-mode
Easily turn your WooCommerce store into catalog mode with the best plugin designed for efficiency and effectiveness.
CatalogX – Catalog Mode, Enquiry & Quotes for WooCommerce
woocommerce-catalog-enquiry
WooCommerce Catalog Mode, product enquiry, and request a quote plugin. Hide prices, disable cart, and collect enquiries easily.
Product Enquiry for WooCommerce Developer Profile
26 plugins · 12K total installs
How We Detect Product Enquiry for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gm-woocommerce-quote-popup/build/admin/admin.js/wp-content/plugins/gm-woocommerce-quote-popup/build/admin/admin.css/wp-content/plugins/gm-woocommerce-quote-popup/assents/css/style.css/wp-content/plugins/gm-woocommerce-quote-popup/assents/js/script.js/wp-content/plugins/gm-woocommerce-quote-popup/build/admin/admin.js/wp-content/plugins/gm-woocommerce-quote-popup/assents/js/script.jsgmwqp-react-admingmwqp-react-admin-stylegmwqp-styleegmwqp-scriptHTML / DOM Fingerprints
gmwqp-request-quote-button<!-- The content of the popup. --><!-- Content --><!-- End Content --><!-- Footer -->+21 moregmwqp_enquiry_single_productgmwqp_wp_ajaxgmwqp_translation/wp-json/gmwqp/v1/get-settings/wp-json/gmwqp/v1/get-enquiries/wp-json/gmwqp/v1/save-settings/wp-json/gmwqp/v1/deleteallenquirys/wp-json/gmwqp/v1/save-customfield/wp-json/gmwqp/v1/delete-customfield[gmwqp_enquiry_single_product]