
PBO Move to Wishlist for YITH WooCommerce Wishlist Security & Risk Analysis
wordpress.org/plugins/pbo-move-to-wishlist-for-yith-woocommerce-wishlistPBO Move to Wishlist for YITH WooCommerce Wishlist is a simple solution for adding functionality called 'Move to Wishlist' to Shopping Cart.
Is PBO Move to Wishlist for YITH WooCommerce Wishlist Safe to Use in 2026?
Generally Safe
Score 85/100PBO Move to Wishlist for YITH WooCommerce Wishlist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pbo-move-to-wishlist-for-yith-woocommerce-wishlist" plugin v1.0.2 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly minimizes the attack surface. Furthermore, the code signals show no dangerous functions, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, all of which are excellent security practices. The presence of a nonce check and a healthy percentage of properly escaped output are also positive indicators. The plugin also boasts a clean vulnerability history with zero known CVEs, suggesting a history of secure development and maintenance.
While the static analysis reveals a very low risk profile, the lack of any taint analysis flows makes it impossible to fully assess the impact of potential data manipulation or the use of unsanitized inputs, even if the attack surface is currently limited. The complete absence of capability checks is a notable concern; while there are no apparent entry points that currently require authorization, any future additions or modifications to the plugin's functionality could introduce vulnerabilities if access controls are not implemented. The 78% proper output escaping, while good, leaves room for improvement as 22% of outputs are not properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if those outputs handle user-supplied data.
Key Concerns
- Some output is not properly escaped
- No capability checks found
PBO Move to Wishlist for YITH WooCommerce Wishlist Security Vulnerabilities
PBO Move to Wishlist for YITH WooCommerce Wishlist Code Analysis
Output Escaping
PBO Move to Wishlist for YITH WooCommerce Wishlist Attack Surface
WordPress Hooks 5
Maintenance & Trust
PBO Move to Wishlist for YITH WooCommerce Wishlist Maintenance & Trust
Maintenance Signals
Community Trust
PBO Move to Wishlist for YITH WooCommerce Wishlist Alternatives
Wishlist for Woocommerce
wishlist-for-woocommerce
Wishlist Plugin lets your customers save the items that they would like to purchase, but in future. WooCommerce 2.4.6 compatible.
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
Better Wishlist
better-wishlist
Better Wishlist lets you display Wishlist anywhere on your WooCommerce shop so that your customers can easily bookmark their favourite products and fi …
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
Product Filter for WooCommerce by WBW
woo-product-filter
Filter products by categories, attributes, prices, and more. Elementor Compatibility. Shoppers easily find products with WooCommerce Product Filter
PBO Move to Wishlist for YITH WooCommerce Wishlist Developer Profile
1 plugin · 10 total installs
How We Detect PBO Move to Wishlist for YITH WooCommerce Wishlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
pbo_move_to_wishlistdata-cart_item_key