
ingenidev Gift Unlocker for woocommerce Security & Risk Analysis
wordpress.org/plugins/ingenidev-gift-unlocker-for-woocommerceNEW Plugin! A powerful WooCommerce plugin that allows you to offer gift products to customers when they reach specific cart total thresholds.
Is ingenidev Gift Unlocker for woocommerce Safe to Use in 2026?
Generally Safe
Score 100/100ingenidev Gift Unlocker for woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'ingenidev-gift-unlocker-for-woocommerce' v1.0.0 exhibits a generally strong security posture based on the provided static analysis. All identified AJAX entry points have authorization checks, and there are no known vulnerabilities in its history. The code demonstrates good practices with a high percentage of properly escaped outputs and a significant number of nonce and capability checks. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design.
However, a notable concern arises from the handling of SQL queries. All four identified SQL queries are not using prepared statements. This is a significant risk as it makes the plugin vulnerable to SQL injection attacks, especially if any of the data used in these queries originates from user input. While no taint flows with unsanitized paths were detected in this specific analysis, the raw SQL usage presents a latent vulnerability that could be exploited with crafted input. The vulnerability history being clear is positive, but it does not negate the inherent risks posed by insecure database interactions.
In conclusion, the plugin has several strengths, including a well-protected attack surface and good output sanitization. The lack of past vulnerabilities is encouraging. The primary weakness, and a critical one, is the universal lack of prepared statements for SQL queries. This requires immediate attention to prevent potential data breaches and ensure the integrity of the WordPress site. Addressing this SQL query issue would significantly improve the overall security of the plugin.
Key Concerns
- All SQL queries lack prepared statements
ingenidev Gift Unlocker for woocommerce Security Vulnerabilities
ingenidev Gift Unlocker for woocommerce Code Analysis
SQL Query Safety
Output Escaping
ingenidev Gift Unlocker for woocommerce Attack Surface
AJAX Handlers 11
WordPress Hooks 38
Maintenance & Trust
ingenidev Gift Unlocker for woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
ingenidev Gift Unlocker for woocommerce Alternatives
Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails
woo-cart-abandonment-recovery
Every store loses sales to cart abandonment. But with Cart Abandonment Recovery for WooCommerce, you can win them back—automatically.
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution
shopengine
WooCommerce builder for Elementor and Gutenberg. It offers product templates, product sliders, shopping cart, quick view, Woo wishlist, product filter …
Side Cart Woocommerce | Woocommerce Cart
side-cart-woocommerce
Manage your cart from just a click away with an interactive design
Direct Checkout for WooCommerce
woocommerce-direct-checkout
Formerly "WooCommerce Direct Checkout". This plugin simplifies the entire WooCommerce checkout process to improve your sales rate.
Menu Cart for WooCommerce
woocommerce-menu-bar-cart
Automatically displays a shopping cart in your menu bar. Works with WooCommerce and Easy Digital Downloads (EDD)
ingenidev Gift Unlocker for woocommerce Developer Profile
11 plugins · 1K total installs
How We Detect ingenidev Gift Unlocker for woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ingenidev-gift-unlocker-for-woocommerce/assets/css/gift-unlocker-admin.css/wp-content/plugins/ingenidev-gift-unlocker-for-woocommerce/assets/js/gift-unlocker-admin.js/wp-content/plugins/ingenidev-gift-unlocker-for-woocommerce/assets/js/gift-unlocker-frontend.jsingenidev-gift-unlocker-for-woocommerce/assets/css/gift-unlocker-admin.css?ver=ingenidev-gift-unlocker-for-woocommerce/assets/js/gift-unlocker-admin.js?ver=ingenidev-gift-unlocker-for-woocommerce/assets/js/gift-unlocker-frontend.js?ver=HTML / DOM Fingerprints
ingenidev-gift-unlocker-settingsPrevent direct accessAdmin Interface ClassHandles the admin interface for managing gift productsGift Admin Class+28 moredata-gift-product-iddata-min-cart-totaldata-max-quantitydata-categoriesingenidev_gift_unlocker_admin_paramsingenidev_gift_unlocker_frontend_params/wp-json/ingenidev-gift-unlocker/v1/gift-products