
OLLITS Wishlist for WooCommerce Security & Risk Analysis
wordpress.org/plugins/ollits-woo-wishlistEnable WooCommerce customers to effortlessly manage their personal wishlists, improving their shopping experience!
Is OLLITS Wishlist for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100OLLITS Wishlist for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ollits-woo-wishlist" plugin v3.17 demonstrates a generally good security posture, with several positive indicators. The absence of any known CVEs, coupled with a clean vulnerability history, suggests a well-maintained codebase. The plugin also utilizes prepared statements for all its SQL queries and performs output escaping on a high percentage (91%) of its outputs, which are strong defenses against common web vulnerabilities. Furthermore, the analysis shows no dangerous functions, file operations, or external HTTP requests, further bolstering its security profile. The presence of nonce and capability checks on many of its AJAX handlers is also a positive sign of secure development practices.
Despite these strengths, a closer look at the static analysis reveals a minor concern. The taint analysis identified one flow with an unsanitized path. While the severity is not classified as critical or high, and there are no indications of direct exploitation paths in the provided data, an unsanitized path is a potential entry point for attackers to manipulate data flow, which could lead to unintended consequences or be chained with other vulnerabilities. The presence of 8 AJAX handlers, although all protected by authentication checks, contributes to the overall attack surface. The plugin's strength lies in its robust handling of SQL and output, but the single unsanitized path warrants attention for complete security.
In conclusion, "ollits-woo-wishlist" v3.17 appears to be a secure plugin with a strong focus on preventing common vulnerabilities like SQL injection and XSS through prepared statements and output escaping. Its clean vulnerability history is a significant positive. The primary area for improvement is the resolution of the identified unsanitized path in the taint analysis to eliminate any potential for unexpected data manipulation. Overall, the plugin's security is good, with this one area needing minor attention.
Key Concerns
- Flow with unsanitized path identified
OLLITS Wishlist for WooCommerce Security Vulnerabilities
OLLITS Wishlist for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
OLLITS Wishlist for WooCommerce Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
OLLITS Wishlist for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
OLLITS Wishlist for WooCommerce Alternatives
YITH WooCommerce Wishlist
yith-woocommerce-wishlist
YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 10.6.x compatible.
Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later
flexible-wishlist
Lightweight and simple WooCommerce wishlist. Increases sales. Fits any theme. Customizes texts and icons. Add to ecommerce wishlist with just 1 click.
Wishlist for WooCommerce
wt-woocommerce-wishlist
This WooCommerce wishlist plugin adds a wishlist feature to your WooCommerce store. Let the users easily add and manage products from their wishlist p …
Wishlist for WooCommerce
jvm-woocommerce-wishlist
Supercharge your sales with WooCommerce Wishlist - a powerful tool that empowers customers to create wishlists and enhances their shopping experience.
Wishlist and Save for later for Woocommerce
aco-wishlist-for-woocommerce
Wishlist for WooCommerce helps to manage Wishlist and save for later feature in a WooCommerce store
OLLITS Wishlist for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect OLLITS Wishlist for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ollits-woo-wishlist/assets/css/olwooaw-styles.css/wp-content/plugins/ollits-woo-wishlist/assets/css/olwooaw-admin-styles.css/wp-content/plugins/ollits-woo-wishlist/assets/font-awesome-4.7.0/css/font-awesome.min.css/wp-content/plugins/ollits-woo-wishlist/assets/js/olwooaw-scripts.js/wp-content/plugins/ollits-woo-wishlist/assets/js/olwooaw-admin-scripts.jsassets/js/olwooaw-scripts.jsassets/js/olwooaw-admin-scripts.jsollits-woo-wishlist/assets/css/olwooaw-styles.css?ver=ollits-woo-wishlist/assets/font-awesome-4.7.0/css/font-awesome.min.css?ver=ollits-woo-wishlist/assets/js/olwooaw-scripts.js?ver=ollits-woo-wishlist/assets/css/olwooaw-admin-styles.css?ver=ollits-woo-wishlist/assets/js/olwooaw-admin-scripts.js?ver=HTML / DOM Fingerprints
ollitsaw-font-heartadd-to-wishlistremove-from-wishlistdata-product_iddata-variation_iddata-user_idaw_ajax[ollits_wishlist]