CI WooCommerce Minimum Maximum Quantity & Step Control Security & Risk Analysis

wordpress.org/plugins/min-max-quantity-for-woocommerce

CI WooCommerce Minimum Maximum Quantityallows you to define the minimum and maximum allowable product quantities per product or all products of your s …

40 active installs v1.0.0 PHP + WP 4.0+ Updated Nov 19, 2019
minimum-order-quantityquantitywoocommercewoocommerce-min-max-quantitieswoocommerce-minimum-quantity
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CI WooCommerce Minimum Maximum Quantity & Step Control Safe to Use in 2026?

Generally Safe

Score 85/100

CI WooCommerce Minimum Maximum Quantity & Step Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

Based on the provided static analysis, this version of the "min-max-quantity-for-woocommerce" plugin exhibits a strong security posture with no detected entry points that are unprotected. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a generally secure foundation. The fact that all SQL queries are using prepared statements is a significant positive indicator, demonstrating good practice in preventing SQL injection vulnerabilities.

However, there are some areas for concern. The analysis shows a complete lack of nonce checks and capability checks across all identified potential entry points, which are effectively zero. While there are no identified entry points, this indicates a potential blind spot if any were to be introduced in future updates. Furthermore, with 50 total outputs and only 60% being properly escaped, there's a 40% chance of unescaped output, which could lead to cross-site scripting (XSS) vulnerabilities if sensitive data is processed and displayed without adequate sanitization.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the static analysis, suggests that for this specific version (v1.0.0), the risk of exploitation is low. Nevertheless, the lack of comprehensive security checks like nonces and capability checks, along with the unescaped output rate, presents an opportunity for future vulnerabilities to arise if not addressed. The plugin's strengths lie in its SQL handling and avoidance of dangerous code patterns, but its weaknesses are in input validation and output sanitization practices, particularly concerning.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • 40% of outputs unescaped
Vulnerabilities
None known

CI WooCommerce Minimum Maximum Quantity & Step Control Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CI WooCommerce Minimum Maximum Quantity & Step Control Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
30 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped50 total outputs
Attack Surface

CI WooCommerce Minimum Maximum Quantity & Step Control Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_enqueue_scriptsinc\class.settings-api.php:30
actionadmin_initinc\options.php:16
actionadmin_menuinc\options.php:17
filterwoocommerce_product_data_tabsinc\wc-mmqty-admin.php:17
actionadmin_headinc\wc-mmqty-admin.php:49
actionwoocommerce_product_data_panelsinc\wc-mmqty-admin.php:53
actionwoocommerce_process_product_meta_simpleinc\wc-mmqty-admin.php:126
actionwoocommerce_process_product_meta_variableinc\wc-mmqty-admin.php:129
actionwoocommerce_after_add_to_cart_buttoninc\wc-mmqty-public.php:13
actionwoocommerce_after_shop_loop_iteminc\wc-mmqty-public.php:14
filterwoocommerce_quantity_input_argsinc\wc-mmqty-public.php:51
filterwoocommerce_loop_add_to_cart_linkinc\wc-mmqty-public.php:53
filterwoocommerce_add_to_cart_validationinc\wc-mmqty-public.php:204
actionwoocommerce_before_calculate_totalsinc\wc-mmqty-public.php:207
actionplugins_loadedwc-mmqty.php:75
actionplugins_loadedwc-mmqty.php:76
Maintenance & Trust

CI WooCommerce Minimum Maximum Quantity & Step Control Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedNov 19, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

CI WooCommerce Minimum Maximum Quantity & Step Control Developer Profile

Niloy - Codeixer

7 plugins · 29K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
856 days
View full developer profile
Detection Fingerprints

How We Detect CI WooCommerce Minimum Maximum Quantity & Step Control

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/min-max-quantity-for-woocommerce/css/style.css/wp-content/plugins/min-max-quantity-for-woocommerce/js/wc-mmqty-public.js/wp-content/plugins/min-max-quantity-for-woocommerce/js/wc-mmqty-admin.js
Script Paths
/wp-content/plugins/min-max-quantity-for-woocommerce/js/wc-mmqty-public.js/wp-content/plugins/min-max-quantity-for-woocommerce/js/wc-mmqty-admin.js
Version Parameters
min-max-quantity-for-woocommerce/css/style.css?ver=min-max-quantity-for-woocommerce/js/wc-mmqty-public.js?ver=min-max-quantity-for-woocommerce/js/wc-mmqty-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wcmmqty-input-group
Data Attributes
data-wcmmqty-iddata-wcmmqty-type
JS Globals
wc_mmqty_params
FAQ

Frequently Asked Questions about CI WooCommerce Minimum Maximum Quantity & Step Control