
Multiple Carts, Persistent Carts, Abandoned Carts, MultiVendors for Woo – Free by WP Masters Security & Risk Analysis
wordpress.org/plugins/multiple-carts-for-woo-free-by-wp-mastersMultiCart gives customers a feature to save different cart items and shipping address. Reminders for not finished order.
Is Multiple Carts, Persistent Carts, Abandoned Carts, MultiVendors for Woo – Free by WP Masters Safe to Use in 2026?
Generally Safe
Score 85/100Multiple Carts, Persistent Carts, Abandoned Carts, MultiVendors for Woo – Free by WP Masters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "multiple-carts-for-woo-free-by-wp-masters" v1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having all identified entry points protected by authorization checks, no unescaped output, and no file operations or external HTTP requests. The high percentage of SQL queries using prepared statements is also commendable, and the absence of any known vulnerabilities in its history suggests a generally stable codebase. However, significant concerns arise from the static analysis. The presence of the `unserialize` function, a known dangerous function, along with two taint flows identified as high severity and having unsanitized paths, presents a critical risk. These findings indicate potential for code injection or unauthorized data manipulation if the plugin handles user-supplied data that is then passed to `unserialize` without proper sanitization. The single nonce check is also insufficient for the number of potential entry points, leaving room for Cross-Site Request Forgery (CSRF) attacks.
Key Concerns
- High severity unsanitized taint flows
- Use of dangerous function: unserialize
- Insufficient nonce checks for entry points
- No capability checks on AJAX handlers
Multiple Carts, Persistent Carts, Abandoned Carts, MultiVendors for Woo – Free by WP Masters Security Vulnerabilities
Multiple Carts, Persistent Carts, Abandoned Carts, MultiVendors for Woo – Free by WP Masters Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Multiple Carts, Persistent Carts, Abandoned Carts, MultiVendors for Woo – Free by WP Masters Attack Surface
AJAX Handlers 1
WordPress Hooks 21
Scheduled Events 1
Maintenance & Trust
Multiple Carts, Persistent Carts, Abandoned Carts, MultiVendors for Woo – Free by WP Masters Maintenance & Trust
Maintenance Signals
Community Trust
Multiple Carts, Persistent Carts, Abandoned Carts, MultiVendors for Woo – Free by WP Masters Alternatives
Lean Cart Share and Save for Later for WooCommerce
lean-cart-share-and-save
Lightweight cart sharing and saving for WooCommerce - let customers share carts via URLs and save carts for later.
Unagui Save Cart for WooCommerce
unagui-save-cart-for-woocommerce
Allows logged-in users to save their current WooCommerce cart and restore it later.
Multiple Carts, Persistent Carts, Abandoned Carts, MultiVendors for Woo – Free by WP Masters Developer Profile
7 plugins · 1K total installs
How We Detect Multiple Carts, Persistent Carts, Abandoned Carts, MultiVendors for Woo – Free by WP Masters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multiple-carts-for-woo-free-by-wp-masters/assets/css/wpm-multicart-style.css/wp-content/plugins/multiple-carts-for-woo-free-by-wp-masters/assets/js/wpm-multicart-script.js/wp-content/plugins/multiple-carts-for-woo-free-by-wp-masters/assets/js/wpm-multicart-script.jsmultiple-carts-for-woo-free-by-wp-masters/assets/css/wpm-multicart-style.css?ver=multiple-carts-for-woo-free-by-wp-masters/assets/js/wpm-multicart-script.js?ver=HTML / DOM Fingerprints
wpm-multicart-cart-list<!-- Start Carts List --><!-- End Carts List --><!-- Start Select Cart Session --><!-- End Select Cart Session -->data-cart-iddata-product-idWPM_Multicart_Ajax