
Light Wishlist Security & Risk Analysis
wordpress.org/plugins/light-wishlistLightweight and customizable wishlist for WooCommerce. Add wishlist functionality with support for AJAX, Elementor, Oxygen, and more.
Is Light Wishlist Safe to Use in 2026?
Generally Safe
Score 100/100Light Wishlist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "light-wishlist" plugin v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, using prepared statements exclusively, and has a high percentage of properly escaped output, indicating an awareness of common web vulnerabilities. The absence of any recorded vulnerabilities in its history is also a strong indicator of diligent development and maintenance.
However, several critical concerns arise from the static analysis. The presence of an unprotected AJAX handler represents a significant attack vector, as it allows any unauthenticated user to trigger functionality within the plugin, potentially leading to unintended actions. Furthermore, the taint analysis revealing two flows with unsanitized paths, both categorized as high severity, is a serious red flag. These unsanitized paths, especially in conjunction with an unprotected AJAX handler, suggest a high likelihood of severe vulnerabilities such as cross-site scripting (XSS) or other forms of code injection.
While the plugin has no known CVEs, this does not guarantee future security. The identified unsanitized taint flows are internal code quality issues that could be exploited even without prior public disclosure. The lack of nonce checks and capability checks on entry points further exacerbates the risks, making it easier for attackers to leverage any identified weaknesses. In conclusion, the plugin has strengths in its data handling but possesses critical vulnerabilities related to input validation and authorization, which require immediate attention.
Key Concerns
- AJAX handler without authentication
- High severity unsanitized taint flows (2)
- No nonce checks
- No capability checks
- File operations present
Light Wishlist Security Vulnerabilities
Light Wishlist Release Timeline
Light Wishlist Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Light Wishlist Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 18
Maintenance & Trust
Light Wishlist Maintenance & Trust
Maintenance Signals
Community Trust
Light Wishlist Alternatives
YITH Essential Kit for WooCommerce #1
yith-essential-kit-for-woocommerce-1
The YITH Essential Kit for WooCommerce #1 plugin enhance your WordPress site with this group of impressive features for WooCommerce.
Wishlist and Compare for WooCommerce
wishlist-and-compare
Enhance your WooCommerce store with our Wishlist & Compare Plugin. Let customers save favorite products and compare features for informed decisions.
Velocity Wishlist – WooCommerce Wishlist Plugin
velocity-wishlist
Powerful, lightweight wishlist functionality for WooCommerce. Supports guest users, product variations, social sharing, and fully customizable buttons …
AICOSO Wishlist for WooCommerce
aicoso-wishlist-for-woocommerce
Comprehensive wishlist solution for WooCommerce with AI-powered recommendations, social sharing, and advanced analytics.
ReaganM Customer Wishlist for WooCommerce
rgnmhn-customer-wishlist
Create a fast, translation-ready WooCommerce wishlist. Support for variable products, guest users, and fully customizable styles.
Light Wishlist Developer Profile
1 plugin · 0 total installs
How We Detect Light Wishlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/light-wishlist/includes/js/wishlist.js/wp-content/plugins/light-wishlist/assets/css/all.min.css/wp-content/plugins/light-wishlist/includes/css/add-wishlist-button.css/wp-content/plugins/light-wishlist/includes/css/wishlist-table.css/wp-content/plugins/light-wishlist/includes/js/wishlist.jslight-wishlist/includes/js/wishlist.js?ver=light-wishlist/assets/css/all.min.css?ver=light-wishlist/includes/css/add-wishlist-button.css?ver=light-wishlist/includes/css/wishlist-table.css?ver=HTML / DOM Fingerprints
light-wishlist-button<!-- Plugin Name: Light Wishlist --><!-- Version: 1.0.1 -->data-product_idwishlistAjax[light-wishlist-add-item][wishlist-user-table]