
MyLiveCart Security & Risk Analysis
wordpress.org/plugins/mylivecartMylivecart is a live shopping app that allows businesses to host interactive live shopping shows directly from their online stores.
Is MyLiveCart Safe to Use in 2026?
Generally Safe
Score 100/100MyLiveCart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mylivecart plugin v1.0.4 exhibits a generally good security posture with several positive indicators. The plugin demonstrates strong practices regarding SQL query safety, with 100% of its queries utilizing prepared statements, and nearly all output is properly escaped, minimizing cross-site scripting (XSS) risks. The absence of dangerous functions, file operations, and known vulnerabilities (CVEs) further suggests a well-developed and secure codebase. The presence of nonce checks on all AJAX handlers is also a positive security control.
However, there are significant areas of concern that warrant attention. The plugin exposes 3 entry points without adequate authentication or permission checks: 2 AJAX handlers and 1 REST API route. While the taint analysis shows no critical or high severity issues, the presence of 9 flows with unsanitized paths suggests potential avenues for malicious input to be processed in unexpected ways, even if no immediate critical vulnerabilities were detected in this specific analysis. The large number of external HTTP requests (18) could also be a vector if any of those external services are compromised or if the plugin doesn't handle responses securely.
In conclusion, while the plugin has strengths in core security practices like SQL and output handling, the unprotected entry points and unsanitized path flows represent immediate risks that could be exploited. The lack of recorded vulnerabilities is a positive sign, but it doesn't negate the risks identified in the static analysis. Addressing the unprotected endpoints and investigating the unsanitized path flows should be the priority.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Flows with unsanitized paths
MyLiveCart Security Vulnerabilities
MyLiveCart Release Timeline
MyLiveCart Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MyLiveCart Attack Surface
AJAX Handlers 15
REST API Routes 1
Shortcodes 2
WordPress Hooks 25
Maintenance & Trust
MyLiveCart Maintenance & Trust
Maintenance Signals
Community Trust
MyLiveCart Alternatives
WpStream – Live Streaming, Video on Demand, Pay Per View
wpstream
WpStream is a Video Streaming Plugin that lets you broadcast live events and helps you sell tickets or recordings via WooCommerce.
Product Layouts for WooCommerce
product-layouts
Create impressive, lightweight, responsive WooCommerce product layouts. Compatible with popular themes & page builders.
Live Shopping & Shoppable Videos For WooCommerce
live-shopping-video-streams
Easy-to-install Plugin that adds Live Shopping, Shoppable Videos & Live Commerce as Sales Channels to WooCommerce Stores to Sell & Promote Products
Products Grid for Elementor
products-grid-for-elementor
Eye-catching Elementor Products Grid, presenting a captivating product showcase with over 20+ unique designs.
DigiPay Payment Gateway
digipay-payment-gateway
Accept credit card payments with full payment and installment.
MyLiveCart Developer Profile
3 plugins · 20 total installs
How We Detect MyLiveCart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mylivecart/assets/css/zt-font-family.css/wp-content/plugins/mylivecart/assets/css/zt-style.css/wp-content/plugins/mylivecart/assets/js/zt-script.jshttps://cdn.socket.io/4.3.2/socket.io.min.jsztcbl_font_familyztcbl_styleztcbl_js_fileHTML / DOM Fingerprints
zt-create-divzt-createzt-create-btnzt-create-spanzt-create-imgwrapFile: all-event.phpDescription: This file is responsible for show all events list and according to their status in admin side.Exit if accessed directlyCreate Eventdata-iddata-titledata-imgdata-descriptiondata-typedata-start+4 moreztcbl_qvztcbl_socket_urlztcbl_site_url/wp-json/api/v1/secret[ztcbl_EventsListPageContent