NS Custom Add To Cart Button For Woocommerce Security & Risk Analysis

wordpress.org/plugins/ns-custom-add-to-cart-button-for-woocoomerce

This plugin help to change add to cart button text with no code required!

10 active installs v1.2.4 PHP + WP 4.3+ Updated Feb 9, 2022
add-to-cartbuttonbutton-add-to-cartcustom-add-to-cart-buttoncustom-cart-button
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NS Custom Add To Cart Button For Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

NS Custom Add To Cart Button For Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "ns-custom-add-to-cart-button-for-woocommerce" plugin, version 1.2.4, presents a moderate security risk due to several concerning findings in its static analysis. While the plugin demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerability history, its attack surface is notably exposed. It features two AJAX handlers, both of which lack authentication checks, creating a direct entry point for unauthenticated users. Furthermore, a significant portion of its output (85%) is not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities if malicious data is processed through these outputs. The taint analysis also identified two flows with unsanitized paths, indicating potential for directory traversal or other path-based attacks, although these were not classified as critical or high severity. The complete absence of nonce checks and capability checks on its AJAX endpoints exacerbates these risks, making it easier for attackers to trigger unintended actions. While the lack of known CVEs is a positive sign, the identified vulnerabilities in the code analysis suggest a need for immediate attention to secure the plugin's entry points and output handling.

Key Concerns

  • AJAX handlers without authentication
  • Significant amount of unescaped output
  • Taint flows with unsanitized paths
  • AJAX handlers without nonce checks
  • AJAX handlers without capability checks
Vulnerabilities
None known

NS Custom Add To Cart Button For Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NS Custom Add To Cart Button For Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

15% escaped27 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
pe_deactivation_ajax_function (plugineye\plugineye-ajax\plugineye_on_deactivation_function.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

NS Custom Add To Cart Button For Woocommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_pe_deactivation_ajax_functionplugineye\plugineye-ajax\plugineye_on_deactivation_function.php:2
noprivwp_ajax_pe_deactivation_ajax_functionplugineye\plugineye-ajax\plugineye_on_deactivation_function.php:3
WordPress Hooks 12
actionadmin_menuns-admin-options\ns-admin-options-setup.php:7
actionadmin_enqueue_scriptsns-admin-options\ns-admin-options-setup.php:13
actionadmin_initns-change-addcart-option.php:20
filterwoocommerce_product_add_to_cart_textns-change-addcart.php:61
filterwoocommerce_product_single_add_to_cart_textns-change-addcart.php:67
filterplugin_action_linksplugineye\plugineye-class.php:96
actionadmin_menuplugineye\plugineye-class.php:113
actionadmin_enqueue_scriptsplugineye\plugineye-class.php:125
actionadmin_enqueue_scriptsplugineye\plugineye-class.php:136
actionactivated_pluginplugineye\plugineye-class.php:147
actionin_admin_footerplugineye\plugineye-class.php:401
actionactivated_pluginplugineye\plugineye-class.php:440
Maintenance & Trust

NS Custom Add To Cart Button For Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 9, 2022
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

NS Custom Add To Cart Button For Woocommerce Developer Profile

NsThemes

24 plugins · 4K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NS Custom Add To Cart Button For Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ns-custom-add-to-cart-button-for-woocoomerce/css/ns-option-css-page.css/wp-content/plugins/ns-custom-add-to-cart-button-for-woocoomerce/css/ns-option-css-custom-page.css/wp-content/plugins/ns-custom-add-to-cart-button-for-woocoomerce/js/ns-option-js-page.js/wp-content/plugins/ns-custom-add-to-cart-button-for-woocoomerce/plugineye/assets/css/plugineye_style.css
Script Paths
/wp-content/plugins/ns-custom-add-to-cart-button-for-woocoomerce/js/ns-option-js-page.js
Version Parameters
ns-custom-add-to-cart-button-for-woocoomerce/css/ns-option-css-page.css?ver=ns-custom-add-to-cart-button-for-woocoomerce/css/ns-option-css-custom-page.css?ver=ns-custom-add-to-cart-button-for-woocoomerce/js/ns-option-js-page.js?ver=ns-custom-add-to-cart-button-for-woocoomerce/plugineye/assets/css/plugineye_style.css?ver=

HTML / DOM Fingerprints

CSS Classes
nscatblinkpremium
Data Attributes
id="nscatblinkpremium"
FAQ

Frequently Asked Questions about NS Custom Add To Cart Button For Woocommerce