Product Enquiry for WooCommerce Security & Risk Analysis

wordpress.org/plugins/product-enquiry-for-woocommerce

Product Enquiry allows prospective customers to "Make an Enquiry" about a product, or "Request a Quote" right from within the product page.

10K active installs v3.2.5.2 PHP 5.6+ WP 5.3+ Updated Jan 15, 2026
product-enquiry-for-woocommerceproduct-inquiry-for-woocommercerequest-a-quote-woocommercewoocommerce-enquirywoocommerce-inquiry
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 22, 2024
Safety Verdict

Is Product Enquiry for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Product Enquiry for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 22, 2024Updated 2mo ago
Risk Assessment

The 'product-enquiry-for-woocommerce' plugin version 3.2.5.2 exhibits a generally good security posture based on static analysis. The plugin demonstrates strong adherence to secure coding practices, with all identified entry points (AJAX handlers) appearing to have authentication checks. The extensive use of prepared statements for SQL queries, high percentage of properly escaped output, and the presence of nonce and capability checks further bolster its security. The absence of dangerous functions, file operations, and external HTTP requests also reduces the potential attack surface.

Key Concerns

  • One previously unpatched CVE
  • One medium severity vulnerability recorded
  • One recorded vulnerability in the past year
Vulnerabilities
1

Product Enquiry for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-3964medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product Enquiry for WooCommerce <= 3.1.7 - Authenticated (Admin+) Stored Cross-Site Scripting

Jun 22, 2024 Patched in 3.1.8 (49d)
Code Analysis
Analyzed Mar 16, 2026

Product Enquiry for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
251 escaped
Nonce Checks
14
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery

Output Escaping

98% escaped256 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
send_newsletter_mail (admin\class-pe-admin-newsletter-subcribe.php:41)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Product Enquiry for WooCommerce Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_pefree_dismiss_ai_banneradmin\class-pe-admin-ai-botkit-banner.php:51
authwp_ajax_wdm_sendadmin\class-pe-admin-enquiry-form-ajax.php:43
noprivwp_ajax_wdm_sendadmin\class-pe-admin-enquiry-form-ajax.php:44
authwp_ajax_wdm_pe_actionadmin\class-pe-admin-newsletter-subcribe.php:22
authwp_ajax_pe_notice_dismissadmin\class-pe-admin-settings.php:59
WordPress Hooks 33
actionadmin_noticesadmin\class-pe-admin-ai-botkit-banner.php:49
actionadmin_enqueue_scriptsadmin\class-pe-admin-ai-botkit-banner.php:50
actionadmin_menuadmin\class-pe-admin-settings-products.php:25
actionadmin_initadmin\class-pe-admin-settings.php:58
actionadmin_footeradmin\class-pe-admin-settings.php:61
actionadmin_noticesadmin\class-pe-admin-settings.php:62
actionadmin_enqueue_scriptsadmin\class-pe-admin-settings.php:63
filterplugin_row_metaadmin\class-pe-admin-settings.php:65
actionadmin_print_scriptsadmin\class-pe-admin-settings.php:249
actioninitadmin\class-pe-admin.php:36
actioninitadmin\class-pe-admin.php:37
actionadmin_initadmin\class-pe-admin.php:38
actionadmin_enqueue_scriptsadmin\class-pe-admin.php:44
actionadmin_enqueue_scriptsadmin\class-pe-admin.php:45
actionadmin_noticesincludes\class-product-enquiry-for-woocommerce.php:59
actioninitincludes\class-product-enquiry-for-woocommerce.php:74
actionadmin_initproduct-enquiry-for-woocommerce.php:52
actionplugins_loadedproduct-enquiry-for-woocommerce.php:70
actionbefore_woocommerce_initproduct-enquiry-for-woocommerce.php:86
actioninitpublic\class-pe-public-enquiry-button.php:38
actionwp_footerpublic\class-pe-public-enquiry-button.php:39
actionwoocommerce_single_product_summarypublic\class-pe-public-enquiry-button.php:50
actionwoocommerce_after_single_product_summarypublic\class-pe-public-enquiry-button.php:52
actionwoocommerce_single_product_summarypublic\class-pe-public-enquiry-button.php:55
actioninitpublic\class-pe-public.php:38
actionwp_enqueue_scriptspublic\class-pe-public.php:52
actionwp_enqueue_scriptstemplates\enq-photoswipe-zoom.php:12
actionwp_footertemplates\enq-photoswipe-zoom.php:68
actionwp_footertemplates\enq-photoswipe-zoom.php:112
filterwoocommerce_single_product_image_thumbnail_htmltemplates\enq-photoswipe-zoom.php:127
filterwp_mail_fromwisdm_sidebar\wisdm_sidebar.php:203
filterwp_mail_from_namewisdm_sidebar\wisdm_sidebar.php:204
filterwp_mail_content_typewisdm_sidebar\wisdm_sidebar.php:205
Maintenance & Trust

Product Enquiry for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 15, 2026
PHP min version5.6
Downloads346K

Community Trust

Rating82/100
Number of ratings67
Active installs10K
Developer Profile

Product Enquiry for WooCommerce Developer Profile

WisdmLabs

7 plugins · 15K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
147 days
View full developer profile
Detection Fingerprints

How We Detect Product Enquiry for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-enquiry-for-woocommerce/assets/admin/css/pro-banner.css/wp-content/plugins/product-enquiry-for-woocommerce/assets/admin/css/ai-botkit-banner.css/wp-content/plugins/product-enquiry-for-woocommerce/assets/admin/js/ai-botkit-banner.js
Script Paths
/wp-content/plugins/product-enquiry-for-woocommerce/assets/admin/js/ai-botkit-banner.js
Version Parameters
product-enquiry-for-woocommerce/assets/admin/css/pro-banner.css?ver=product-enquiry-for-woocommerce/assets/admin/css/ai-botkit-banner.css?ver=product-enquiry-for-woocommerce/assets/admin/js/ai-botkit-banner.js?ver=

HTML / DOM Fingerprints

CSS Classes
wdm-pe-formwdm_pe_form_wrapperwdm-pe-form-modal-headerwdm-pe-form-close-button
HTML Comments
<!-- PEFree Admin Functions --><!-- PEFree AI BotKit Promotional Banner --><!-- Ensures only one instance of class is loaded or can be loaded. --><!-- Constructor -->+7 more
Data Attributes
data-tip
JS Globals
wdm_pe_form_obj
FAQ

Frequently Asked Questions about Product Enquiry for WooCommerce