Viral Buy for Me for WooCommerce Increase Sales Security & Risk Analysis

wordpress.org/plugins/increase-sales

Go viral - Increase Sales for WooCommerce with Buy for me, inline cross sells, Add to Cart Button Custom Text, Continue Shopping, Sale Conversion repo …

10 active installs v1.2.6 PHP 7.4+ WP 5.0+ Updated Dec 17, 2025
add-to-cartbuy-for-meincrease-salesviralwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Viral Buy for Me for WooCommerce Increase Sales Safe to Use in 2026?

Generally Safe

Score 100/100

Viral Buy for Me for WooCommerce Increase Sales has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "increase-sales" plugin v1.2.6 exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices by exclusively using prepared statements for SQL queries and generally good output escaping, significant concerns arise from its attack surface. A substantial portion of its AJAX handlers (7 out of 15) lack authentication checks, creating a considerable risk of unauthorized access and potential exploitation. The taint analysis reveals two flows with unsanitized paths, classified as high severity, which could lead to serious security vulnerabilities if exploited.

Despite the lack of any recorded historical vulnerabilities, the current static analysis findings are troubling. The high number of unprotected AJAX endpoints and the presence of high-severity unsanitized taint flows indicate a need for immediate attention. The plugin's strengths lie in its SQL handling and output escaping, but these are overshadowed by the potential for attackers to leverage the unprotected entry points. A balanced conclusion is that while the plugin has some good security foundations, its current implementation presents notable risks that require remediation.

Key Concerns

  • Unprotected AJAX handlers
  • High severity unsanitized taint flows
  • Use of unseralize function
Vulnerabilities
None known

Viral Buy for Me for WooCommerce Increase Sales Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Viral Buy for Me for WooCommerce Increase Sales Release Timeline

v1.2.6Current
v1.2.5
v1.2.4
v1.2.1
v1.2.0
v1.1.0
v1.0.0
v0.9.9
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.2
Code Analysis
Analyzed Mar 17, 2026

Viral Buy for Me for WooCommerce Increase Sales Code Analysis

Dangerous Functions
4
Raw SQL Queries
0
10 prepared
Unescaped Output
74
323 escaped
Nonce Checks
6
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$qcld_cross_sell_order_fake_product = unserialize(get_option('qcld_cross_sell_order_fake_producinc\qcld-cross-sell-order-notification.php:74
unserialize$qcld_cross_sell_order_notification_customer_name = unserialize(get_option('qcld_cross_sell_order_inc\qcld-cross-sell-order-notification.php:75
unserialize$qcld_cross_sell_order_notification_customer_address = unserialize(get_option('qcld_cross_sell_ordeinc\qcld-cross-sell-order-notification.php:76
unserialize$qcld_cross_sell_order_notification_fake_sale_duration = unserialize( get_option('qcld_cross_sell_oinc\qcld-cross-sell-order-notification.php:77

SQL Query Safety

100% prepared10 total queries

Output Escaping

81% escaped397 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

7 flows2 with unsanitized paths
qcld_cross_sell_con_tracker_save_options (conversion-tracker\class-qc-conversion-tracker.php:73)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

Viral Buy for Me for WooCommerce Increase Sales Attack Surface

Entry Points15
Unprotected7

AJAX Handlers 15

authwp_ajax_qcld_increase_sales_con_tracker_insertconversion-tracker\class-qc-conversion-tracker.php:38
noprivwp_ajax_qcld_increase_sales_con_tracker_insertconversion-tracker\class-qc-conversion-tracker.php:39
authwp_ajax_qcld_increase_sales_con_tracker_custom_action_dataconversion-tracker\class-qc-conversion-tracker.php:45
authwp_ajax_qcld_cross_sell_reset_all_optionsinc\qcld-cross-sell-admin-data-in.php:374
noprivwp_ajax_qcld_cross_sell_reset_all_optionsinc\qcld-cross-sell-admin-data-in.php:375
authwp_ajax_qcld_woo_cross_sell_sp_add_to_cartinc\qcld-cross-sell-ajax.php:10
noprivwp_ajax_qcld_woo_cross_sell_sp_add_to_cartinc\qcld-cross-sell-ajax.php:11
authwp_ajax_qcld_cross_sell_product_detailsinc\qcld-cross-sell-ajax.php:41
noprivwp_ajax_qcld_cross_sell_product_detailsinc\qcld-cross-sell-ajax.php:42
authwp_ajax_qcld_cross_sell_single_ajax_add_to_cartinc\qcld-cross-sell-ajax.php:201
noprivwp_ajax_qcld_cross_sell_single_ajax_add_to_cartinc\qcld-cross-sell-ajax.php:202
authwp_ajax_qcld_increase_sales_buy_for_me_send_messageinc\qcld-cross-sell-buy-for-me.php:226
noprivwp_ajax_qcld_increase_sales_buy_for_me_send_messageinc\qcld-cross-sell-buy-for-me.php:227
authwp_ajax_qcld_cross_sell_get_sold_productsinc\qcld-cross-sell-order-notification.php:67
noprivwp_ajax_qcld_cross_sell_get_sold_productsinc\qcld-cross-sell-order-notification.php:68
WordPress Hooks 31
actionadmin_enqueue_scriptsconversion-tracker\class-qc-conversion-tracker.php:31
actionadmin_footerconversion-tracker\class-qc-conversion-tracker.php:32
actionwp_enqueue_scriptsconversion-tracker\class-qc-conversion-tracker.php:35
actionwoocommerce_order_status_completedconversion-tracker\class-qc-conversion-tracker.php:42
actionwoocommerce_order_status_processingconversion-tracker\class-qc-conversion-tracker.php:43
actionadmin_initconversion-tracker\class-qc-conversion-tracker.php:47
actioninitconversion-tracker\class-qc-conversion-tracker.php:606
filteradd_to_cart_textinc\qcld-cross-sell-add-to-cart.php:8
filterwoocommerce_product_add_to_cart_textinc\qcld-cross-sell-add-to-cart.php:9
filterwoocommerce_product_single_add_to_cart_textinc\qcld-cross-sell-add-to-cart.php:10
filterwoocommerce_booking_single_add_to_cart_textinc\qcld-cross-sell-add-to-cart.php:11
actionadmin_initinc\qcld-cross-sell-admin-data-in.php:368
actionqcld_cross_sell_product_variationsinc\qcld-cross-sell-ajax.php:33
actionwp_enqueue_scriptsinc\qcld-cross-sell-assets.php:74
actionadmin_enqueue_scriptsinc\qcld-cross-sell-assets.php:114
actionwoocommerce_after_add_to_cart_buttoninc\qcld-cross-sell-buy-for-me.php:8
actionwp_footerinc\qcld-cross-sell-buy-for-me.php:9
filterwp_mail_content_typeinc\qcld-cross-sell-buy-for-me.php:219
actionqcld_cross_sell_product_variationsinc\qcld-cross-sell-buy-for-me.php:275
actionwoocommerce_before_cart_tableinc\qcld-cross-sell-continue-shopping.php:6
actionwp_footerinc\qcld-cross-sell-order-notification.php:6
actionadmin_noticesqcld-cross-sell-main.php:64
actionplugins_loadedqcld-cross-sell-main.php:130
actionadmin_menuqcld-cross-sell-main.php:154
filterwoocommerce_cart_item_nameqcld-cross-sell-main.php:177
actionwoocommerce_before_cart_tableqcld-cross-sell-main.php:184
actionwoocommerce_after_cart_tableqcld-cross-sell-main.php:191
actiontemplate_redirectqcld-cross-sell-main.php:204
filterwoocommerce_get_image_size_gallery_thumbnailqcld-cross-sell-main.php:219
filterwoocommerce_get_image_size_gallery_thumbnailqcld-cross-sell-main.php:284
actionadmin_initqcld-cross-sell-main.php:389
Maintenance & Trust

Viral Buy for Me for WooCommerce Increase Sales Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 17, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Viral Buy for Me for WooCommerce Increase Sales Developer Profile

QuantumCloud

29 plugins · 26K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
243 days
View full developer profile
Detection Fingerprints

How We Detect Viral Buy for Me for WooCommerce Increase Sales

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Viral Buy for Me for WooCommerce Increase Sales