
Infusionsoft One-click Upsell Security & Risk Analysis
wordpress.org/plugins/infusionsoft-one-click-upsellEasily upsell Infusionsoft® customers from within WordPress using shortcodes.
Is Infusionsoft One-click Upsell Safe to Use in 2026?
Generally Safe
Score 85/100Infusionsoft One-click Upsell has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "infusionsoft-one-click-upsell" plugin v2.2.4 exhibits a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and has no recorded vulnerability history, several concerning aspects are present. The plugin has a small but notable attack surface with two AJAX handlers. Alarmingly, both of these AJAX handlers lack proper authentication checks, creating a direct entry point for unauthenticated users. The taint analysis reveals one flow with unsanitized paths, which, although not classified as critical or high severity in this analysis, still represents a potential risk of data manipulation or unintended code execution if an attacker can influence the unsanitized input. The low percentage of properly escaped output (5%) is another area of concern, suggesting that user-supplied data displayed on the frontend might be vulnerable to cross-site scripting (XSS) attacks. The lack of nonce checks on AJAX actions further exacerbates the risk associated with the unprotected AJAX handlers. While the absence of known CVEs is positive, the identified vulnerabilities in code analysis point to areas that require immediate attention to prevent potential exploitation.
Key Concerns
- AJAX handlers without authentication checks
- Flows with unsanitized paths
- Low percentage of properly escaped output
- Lack of nonce checks on AJAX
Infusionsoft One-click Upsell Security Vulnerabilities
Infusionsoft One-click Upsell Release Timeline
Infusionsoft One-click Upsell Code Analysis
Output Escaping
Data Flow Analysis
Infusionsoft One-click Upsell Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
Infusionsoft One-click Upsell Maintenance & Trust
Maintenance Signals
Community Trust
Infusionsoft One-click Upsell Alternatives
FunnelKit – Funnel Builder for WooCommerce Checkout
funnel-builder
Create high-converting WooCommerce checkout pages, WooCommerce thank you pages & sales funnels with the highest-rated WordPress funnel builder.
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
wpfunnels
WPFunnels is a powerful funnel builder for WooCommerce that helps store owners create high-converting WooCommerce checkout pages, sales funnels, one-c …
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups.
upsell-order-bump-offer-for-woocommerce
Upsell Funnel Builder lets you create WooCommerce Upsells, Order Bumps, One Click upsell, Cross-Sells, Frequently Bought, and Popups.
Infusionsoft Web Form JavaScript
infusionsoft-web-form-javascript
Easily add Infusionsoft web forms to your posts and pages. Automatically converts JavaScript to WordPress-friendly shortcodes.
CTS InfusionSoft Form Shortcode
cts-infusionsoft-form-shortcode
This plugin adds a shortcode to easily insert into posts and pages the javascript code required to embed an InfusionSoft web form.
Infusionsoft One-click Upsell Developer Profile
6 plugins · 380 total installs
How We Detect Infusionsoft One-click Upsell
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ns-one-click-upsell-buttondata-ns-upsell-idwindow.ns_one_click_upsell<form action="wp-admin/admin-ajax.php?action=process_upsellname="contact_id"name="order_id"