
LetsRecover – WooCommerce Abandoned Cart Notifications Security & Risk Analysis
wordpress.org/plugins/letsrecover-woocommerce-abandoned-cartRecover your lost revenue and abandoned carts using multiple automated Web Push Notification reminder by WooCommerce Abandoned Cart Recovery Notificat …
Is LetsRecover – WooCommerce Abandoned Cart Notifications Safe to Use in 2026?
Mostly Safe
Score 81/100LetsRecover – WooCommerce Abandoned Cart Notifications is generally safe to use though it hasn't been updated recently. 3 past CVEs were resolved. Keep it updated.
The 'letsrecover-woocommerce-abandoned-cart' plugin version 1.2.0 exhibits a concerning security posture, primarily due to a large number of unprotected AJAX endpoints. While the plugin utilizes prepared statements for most SQL queries and has a high rate of output escaping, the presence of six AJAX handlers without authentication checks presents a significant attack surface. The taint analysis further amplifies these concerns, revealing eight flows with unsanitized paths classified as high severity. The plugin's vulnerability history, which includes three past CVEs with a critical and two high-severity issues, particularly a critical SQL injection from late 2022, suggests a pattern of past exploitable weaknesses. Although there are no currently unpatched vulnerabilities, the historical trend and the current code analysis findings indicate a need for significant security improvements to mitigate potential risks.
Key Concerns
- 6 AJAX handlers without auth checks
- 8 high severity unsanitized taint flows
- 1 critical past CVE
- 2 high past CVEs
- Dangerous function 'unserialize' found
- Only 2 nonce checks for 6 AJAX handlers
- Only 2 capability checks for 6 AJAX handlers
LetsRecover – WooCommerce Abandoned Cart Notifications Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
LetsRecover <= 1.1.0 - Unauthenticated SQL Injection via AJAX action
LetsRecover <= 1.1.0 - Authenticated (Admin+) SQL Injection
LetsRecover <= 1.1.0 - Authenticated (Admin+) SQL Injection
LetsRecover – WooCommerce Abandoned Cart Notifications Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
LetsRecover – WooCommerce Abandoned Cart Notifications Attack Surface
AJAX Handlers 6
WordPress Hooks 24
Scheduled Events 1
Maintenance & Trust
LetsRecover – WooCommerce Abandoned Cart Notifications Maintenance & Trust
Maintenance Signals
Community Trust
LetsRecover – WooCommerce Abandoned Cart Notifications Alternatives
Abandoned Cart Recovery for WooCommerce
woo-abandoned-cart-recovery
A simple, effective solution to capture abandoned carts and auto-send reminders. Track logs and generate reports on carts, emails, and more
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD
cart-lift
Track abandoned carts and send automated, customizable abandoned cart recovery emails. Get more leads, reduce cart abandonment, and increase revenue.
ShopMagic – email automation
shopmagic-for-woocommerce
Flexible email automation and workflows triggered by customer and site events.
NS Recover Abandoned Cart
ns-recover-abandoned-cart
Helps to find out how many lost carts your store has by keeping track when users abandon them. It also sends an mail to those users to help recover th …
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
woocommerce-jetpack
Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.
LetsRecover – WooCommerce Abandoned Cart Notifications Developer Profile
1 plugin · 0 total installs
How We Detect LetsRecover – WooCommerce Abandoned Cart Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/letsrecover-woocommerce-abandoned-cart/assets/css/letsrecover_admin.min.css/wp-content/plugins/letsrecover-woocommerce-abandoned-cart/assets/js/letsrecover_admin.min.js/wp-content/plugins/letsrecover-woocommerce-abandoned-cart/assets/css/emojionearea.min.css/wp-content/plugins/letsrecover-woocommerce-abandoned-cart/assets/js/emojionearea.min.js/wp-content/plugins/letsrecover-woocommerce-abandoned-cart/assets/js/letsrecover_service_worker.min.jsletsrecover-css?ver=1.0.0letsrecover-admin-js?ver=1.0.0emojionearea-css?ver=3.4.0emojionearea-js?ver=3.4.0HTML / DOM Fingerprints
wplrp-wrapCompatibility for Super PWA PluginPlugin's action buttoninitalize plugin's classesdata-pagedata-tabWPLRP_URLWPLRP_VERSIONwplrp_admin_params/wp-json/wplrp/v1/push-data