Kartly Sidecart for Woocommerce Security & Risk Analysis

wordpress.org/plugins/kartly-sidecart-for-woocommerce

A lightweight and customizable WooCommerce side cart plugin with Ajax functionality.

0 active installs v1.0.2 PHP 7.2+ WP 5.2+ Updated Sep 8, 2025
ajax-cartfloating-cartmini-cartshopping-cartwoocommerce-sidecart
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kartly Sidecart for Woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Kartly Sidecart for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The kartly-sidecart-for-woocommerce plugin exhibits a generally strong security posture, with excellent practices observed in its SQL query handling and output escaping. The absence of dangerous functions, file operations, and external HTTP requests is commendable. The plugin also has a clean vulnerability history, with no recorded CVEs, suggesting a history of secure development or diligent patching if issues have arisen in the past. The primary area of concern lies within its attack surface, specifically the presence of two AJAX handlers that lack authentication checks. While the total number of entry points is moderate, these unprotected handlers represent a direct avenue for potential unauthorized actions if they can be triggered by unauthenticated users. The limited number of taint flows analyzed and the absence of critical or high-severity issues within them is a positive sign, indicating that data processed by the plugin is likely handled securely. Despite the strength in core coding practices, the two unprotected AJAX handlers introduce a notable risk that warrants attention. The plugin's lack of known vulnerabilities is a positive indicator, but the attack surface needs to be hardened.

Key Concerns

  • AJAX handlers without authentication checks
Vulnerabilities
None known

Kartly Sidecart for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Kartly Sidecart for Woocommerce Release Timeline

v1.0.2Current
v1.0.1
Code Analysis
Analyzed Mar 17, 2026

Kartly Sidecart for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
1
286 escaped
Nonce Checks
9
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared5 total queries

Output Escaping

100% escaped287 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
wscart_save_basic_settings (admin\admin-ajax.php:28)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Kartly Sidecart for Woocommerce Attack Surface

Entry Points15
Unprotected2

AJAX Handlers 14

authwp_ajax_wscart_save_basic_settingsadmin\admin-ajax.php:16
authwp_ajax_wscart_reset_basic_settingsadmin\admin-ajax.php:17
authwp_ajax_wscart_save_settingsadmin\admin-ajax.php:19
authwp_ajax_wscart_reset_settingsadmin\admin-ajax.php:20
authwp_ajax_wscart_save_button_settingsadmin\admin-ajax.php:22
authwp_ajax_wscart_reset_button_settingsadmin\admin-ajax.php:23
authwp_ajax_delete_item_from_cartincludes\ajax.php:17
noprivwp_ajax_delete_item_from_cartincludes\ajax.php:18
authwp_ajax_get_updated_side_cartincludes\ajax.php:20
noprivwp_ajax_get_updated_side_cartincludes\ajax.php:21
authwp_ajax_update_cart_item_quantityincludes\ajax.php:23
noprivwp_ajax_update_cart_item_quantityincludes\ajax.php:24
authwp_ajax_get_cart_countincludes\ajax.php:27
noprivwp_ajax_get_cart_countincludes\ajax.php:28

Shortcodes 1

[ws-cart-button] kartly-sidecart-for-woocommerce.php:100
WordPress Hooks 8
actionadmin_menuadmin\admin.php:16
actionwp_enqueue_scriptsincludes\enqueue.php:25
actionadmin_enqueue_scriptsincludes\enqueue.php:28
actionwp_footerincludes\floating-cart.php:15
actionwp_footerincludes\side_cart_body.php:24
actioninitkartly-sidecart-for-woocommerce.php:73
actionadmin_noticeskartly-sidecart-for-woocommerce.php:77
actioninitkartly-sidecart-for-woocommerce.php:158
Maintenance & Trust

Kartly Sidecart for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 8, 2025
PHP min version7.2
Downloads382

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Kartly Sidecart for Woocommerce Developer Profile

Kazi Mahmud Al Azad

2 plugins · 0 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kartly Sidecart for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kartly-sidecart-for-woocommerce/assets/css/kartly-sidecart.css/wp-content/plugins/kartly-sidecart-for-woocommerce/assets/js/kartly-sidecart.js/wp-content/plugins/kartly-sidecart-for-woocommerce/assets/js/ws-customizer.js
Script Paths
/wp-content/plugins/kartly-sidecart-for-woocommerce/assets/js/kartly-sidecart.js/wp-content/plugins/kartly-sidecart-for-woocommerce/assets/js/ws-customizer.js
Version Parameters
kartly-sidecart-for-woocommerce/assets/css/kartly-sidecart.css?ver=kartly-sidecart-for-woocommerce/assets/js/kartly-sidecart.js?ver=kartly-sidecart-for-woocommerce/assets/js/ws-customizer.js?ver=

HTML / DOM Fingerprints

CSS Classes
cart-button-ws
Data Attributes
id="cart_button_ws_id"
JS Globals
wsCartToggle
Shortcode Output
<button class="cart-button-ws" id="cart_button_ws_id" onclick="wsCartToggle()">
FAQ

Frequently Asked Questions about Kartly Sidecart for Woocommerce