
MoceanAPI Abandoned Carts for WooCommerce Security & Risk Analysis
wordpress.org/plugins/moceanapi-abandoned-cartsA plugin to save abandoned carts and send SMS notification to both admin and customer after received abandoned carts in WooCommerce.
Is MoceanAPI Abandoned Carts for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100MoceanAPI Abandoned Carts for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "moceanapi-abandoned-carts" plugin v1.2.0 presents a mixed security posture. While it demonstrates good practices in SQL query handling and a clean vulnerability history, significant concerns arise from its attack surface. A substantial number of AJAX handlers (6) lack authentication checks, creating a direct entry point for potential attackers. Furthermore, the presence of four high-severity taint flows with unsanitized paths is a critical red flag, indicating that user-supplied data is being processed in a way that could lead to exploitation, such as arbitrary code execution or data leakage. The use of the `unserialize` function, a known source of vulnerabilities when handling untrusted data, further amplifies this risk.
The absence of any recorded CVEs is positive, suggesting a history of diligent security maintenance or a lack of public discovery of vulnerabilities. However, the current static analysis results, particularly the high-severity taint flows and the large number of unprotected AJAX endpoints, overshadow this positive history. The plugin's strengths lie in its use of prepared statements for SQL and a decent rate of output escaping. Nevertheless, the identified critical risks in data handling and attack surface management necessitate immediate attention to mitigate potential security breaches.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
- Dangerous function 'unserialize' used
- Only 64% of outputs properly escaped
- Bundled outdated Freemius library
MoceanAPI Abandoned Carts for WooCommerce Security Vulnerabilities
MoceanAPI Abandoned Carts for WooCommerce Release Timeline
MoceanAPI Abandoned Carts for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MoceanAPI Abandoned Carts for WooCommerce Attack Surface
AJAX Handlers 6
WordPress Hooks 29
Scheduled Events 5
Maintenance & Trust
MoceanAPI Abandoned Carts for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
MoceanAPI Abandoned Carts for WooCommerce Alternatives
MoceanAPI Order SMS Notification for WooCommerce
moceansms-order-sms-notification-for-woocommerce
A plugin to send SMS notification to both buyer and seller after an order is placed in WooCommerce. SMS notification can be sent on all order statuses …
Email Marketing for WooCommerce by Omnisend
omnisend-connect
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS, Abandoned Cart made easy for WordPress & WooCommerce by Omnisend
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
CartBounty – Save and recover abandoned carts for WooCommerce
woo-save-abandoned-carts
Save abandoned carts and send automated abandoned cart recovery messages. Get more leads, reduce cart abandonment, and increase sales.
MoceanAPI Abandoned Carts for WooCommerce Developer Profile
5 plugins · 60 total installs
How We Detect MoceanAPI Abandoned Carts for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/moceanapi-abandoned-carts/assets/css/general.css/wp-content/plugins/moceanapi-abandoned-carts/assets/css/modal.css/wp-content/plugins/moceanapi-abandoned-carts/assets/css/settings.css/wp-content/plugins/moceanapi-abandoned-carts/assets/js/exit_intent.js/wp-content/plugins/moceanapi-abandoned-carts/assets/js/main.js/wp-content/plugins/moceanapi-abandoned-carts/assets/js/settings.js/wp-content/plugins/moceanapi-abandoned-carts/assets/js/exit_intent.js/wp-content/plugins/moceanapi-abandoned-carts/assets/js/main.js/wp-content/plugins/moceanapi-abandoned-carts/assets/js/settings.js/wp-content/plugins/moceanapi-abandoned-carts/assets/css/general.css?ver=/wp-content/plugins/moceanapi-abandoned-carts/assets/css/modal.css?ver=/wp-content/plugins/moceanapi-abandoned-carts/assets/css/settings.css?ver=/wp-content/plugins/moceanapi-abandoned-carts/assets/js/exit_intent.js?ver=/wp-content/plugins/moceanapi-abandoned-carts/assets/js/main.js?ver=/wp-content/plugins/moceanapi-abandoned-carts/assets/js/settings.js?ver=HTML / DOM Fingerprints
moceanapi-abandoned-carts-settings-pagemoceanapi-abandoned-carts-wrapmoceanapi-abandoned-carts-exit-intent-formmoceanapi-abandoned-carts-exit-intent-modal<!-- MoceanAPI Abandoned Carts Settings --><!-- MoceanAPI Abandoned Carts Exit Intent Settings -->data-moceanapi-abandoned-carts-settingsdata-moceanapi-abandoned-carts-exit-intentmoceanapi_abandoned_carts_ajax_object/wp-json/moceanapi-abandoned-carts/v1/settings/wp-json/moceanapi-abandoned-carts/v1/exit-intent