Advanced Mini Cart – Floating AJAX Cart & Sidebar Security & Risk Analysis

wordpress.org/plugins/mcfwc-mini-cart-for-woocommerce

AJAX-powered mini cart with floating icon, live updates, sidebar display mode, and real-time total calculations.

0 active installs v1.1.5 PHP 7.0+ WP 4.7+ Updated Unknown
ajax-cartcart-iconminicartsidebar-cart
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Advanced Mini Cart – Floating AJAX Cart & Sidebar Safe to Use in 2026?

Generally Safe

Score 100/100

Advanced Mini Cart – Floating AJAX Cart & Sidebar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'mcfwc-mini-cart-for-woocommerce' v1.1.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, exclusively using prepared statements for SQL queries, and having a very high percentage of properly escaped output. The absence of known CVEs and critical taint flows further suggests a generally robust codebase. However, a significant concern lies in its attack surface, with 4 out of 9 entry points lacking authentication checks. This presents a notable risk of unauthorized access or actions if these unprotected AJAX handlers are not properly secured by other means, such as WordPress's built-in capabilities checks or server-level access controls. The limited number of nonce and capability checks, coupled with the unprotected AJAX handlers, indicates an area that requires careful attention and potential hardening.

The plugin's vulnerability history is impressively clean, with no recorded CVEs. This suggests a generally responsible development approach or perhaps a lack of previous targeted attacks. However, it's important to note that a clean history is not a guarantee of future security, especially when considering the identified attack surface. The plugin's strengths lie in its clean handling of data interactions like SQL and output, but its primary weakness is the exposure of several AJAX endpoints without explicit authorization. A balanced conclusion would be that the plugin is well-developed in certain areas but has critical vulnerabilities in its access control for AJAX handlers that need to be addressed.

Key Concerns

  • AJAX handlers without auth checks
  • Large attack surface without auth
Vulnerabilities
None known

Advanced Mini Cart – Floating AJAX Cart & Sidebar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Advanced Mini Cart – Floating AJAX Cart & Sidebar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
97 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped107 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<mcfwc-admin> (admin\mcfwc-admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Advanced Mini Cart – Floating AJAX Cart & Sidebar Attack Surface

Entry Points9
Unprotected4

AJAX Handlers 8

authwp_ajax_mcfwc_amc_quanity_updatemcfwc-cart_info.php:35
noprivwp_ajax_mcfwc_amc_quanity_updatemcfwc-cart_info.php:36
authwp_ajax_mcfwc_remove_cart_itemmcfwc-cart_info.php:38
noprivwp_ajax_mcfwc_remove_cart_itemmcfwc-cart_info.php:39
authwp_ajax_mcfwc_get_cart_countmcfwc-cart_info.php:41
noprivwp_ajax_mcfwc_get_cart_countmcfwc-cart_info.php:42
authwp_ajax_mcfwc_get_empty_cart_htmlmcfwc-cart_info.php:44
noprivwp_ajax_mcfwc_get_empty_cart_htmlmcfwc-cart_info.php:45

Shortcodes 1

[mcfwc-minicart] mcfwc-cart_info.php:32
WordPress Hooks 8
actionadmin_menumcfwc-cart_info.php:19
actionadmin_enqueue_scriptsmcfwc-cart_info.php:21
actionwp_footermcfwc-cart_info.php:24
filterwoocommerce_add_to_cart_fragmentsmcfwc-cart_info.php:27
actionwp_enqueue_scriptsmcfwc-cart_info.php:29
actionadmin_noticesmcfwc-mini-cart-for-woocommerce.php:56
actionadmin_enqueue_scriptsmcfwc-mini-cart-for-woocommerce.php:82
actionplugins_loadedmcfwc-mini-cart-for-woocommerce.php:97
Maintenance & Trust

Advanced Mini Cart – Floating AJAX Cart & Sidebar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.0
Downloads607

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Advanced Mini Cart – Floating AJAX Cart & Sidebar Developer Profile

Kirtikumar Solanki

13 plugins · 120 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Mini Cart – Floating AJAX Cart & Sidebar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mcfwc-mini-cart-for-woocommerce/assets/css/all.min.css/wp-content/plugins/mcfwc-mini-cart-for-woocommerce/assets/css/mcfwc-default-template.css/wp-content/plugins/mcfwc-mini-cart-for-woocommerce/assets/js/mcfwc-minicart.js
Script Paths
/wp-content/plugins/mcfwc-mini-cart-for-woocommerce/assets/js/mcfwc-admin.js
Version Parameters
/mcfwc-mini-cart-for-woocommerce/assets/css/all.min.css?ver=/mcfwc-mini-cart-for-woocommerce/assets/css/mcfwc-default-template.css?ver=/mcfwc-mini-cart-for-woocommerce/assets/js/mcfwc-minicart.js?ver=/mcfwc-mini-cart-for-woocommerce/assets/js/mcfwc-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
mcfwc-minicart-menu-itemmcfwc-top-rightmcfwc-icon-1
Data Attributes
data-mcfwc-nonce
JS Globals
mcfwcVars
REST Endpoints
/wp-json/mcfwc-mini-cart-for-woocommerce/v1/cart
Shortcode Output
[mcfwc-minicart]
FAQ

Frequently Asked Questions about Advanced Mini Cart – Floating AJAX Cart & Sidebar