
Min Max Step Quantity Limits Manager for WooCommerce Security & Risk Analysis
wordpress.org/plugins/product-quantity-for-woocommerceDefine a min/max, step, decimal & default quantity for products, show a dropdown and much more on WooCommerce stores.
Is Min Max Step Quantity Limits Manager for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Min Max Step Quantity Limits Manager for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "product-quantity-for-woocommerce" version 5.2.4 demonstrates a generally good security posture with no critical or high severity taint flows identified and a high percentage of properly escaped output. The static analysis indicates a well-defined attack surface, with all entry points either protected by AJAX handlers or shortcodes, and no unprotected REST API routes. The absence of file operations and external HTTP requests further strengthens its security profile. However, a significant concern arises from the complete lack of prepared statements for SQL queries, which presents a substantial risk of SQL injection vulnerabilities if the data involved is not meticulously sanitized elsewhere.
The vulnerability history, while showing no currently unpatched CVEs, reveals a past medium-severity vulnerability, specifically a Cross-Site Request Forgery (CSRF). The fact that a CSRF vulnerability existed in the past, even if patched, suggests a need for continued vigilance in handling user interactions and ensuring proper CSRF protection mechanisms are consistently implemented. The presence of only two nonce checks for seven total entry points might be a contributing factor, especially if these checks are not strategically placed to cover all sensitive operations.
In conclusion, while the plugin excels in many areas of secure coding practice, the unmitigated SQL queries are a critical weakness that demands immediate attention. The historical CSRF vulnerability, though resolved, serves as a reminder of potential attack vectors. Addressing the SQL query sanitization and ensuring comprehensive nonce checks across all entry points would significantly improve the overall security of this plugin.
Key Concerns
- Raw SQL queries without prepared statements
- Bundled outdated library: Select2 v3.4.8
- No capability checks on entry points
- Past medium severity vulnerability (CSRF)
Min Max Step Quantity Limits Manager for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 - Reflected Cross-Site Scripting
Min Max Step Quantity Limits Manager for WooCommerce <= 5.1.0 - Cross-Site Request Forgery
Min Max Step Quantity Limits Manager for WooCommerce Release Timeline
Min Max Step Quantity Limits Manager for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Min Max Step Quantity Limits Manager for WooCommerce Attack Surface
AJAX Handlers 2
Shortcodes 5
WordPress Hooks 80
Maintenance & Trust
Min Max Step Quantity Limits Manager for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Min Max Step Quantity Limits Manager for WooCommerce Alternatives
Minimum and Maximum Quantity for WooCommerce
min-and-max-quantity-for-woocommerce
Allow you to set a minimum or maximum purchase quantity for the WooCommerce store.
Product Quantity Dropdown For Woocommerce
product-quantity-dropdown-for-woocommerce
Woocommerce Product Quantity Dropdown Plugin modify your single product page, shop page, and category page on convert qty text box to the dropdown.
Min Max Quantity – Minimum/Maximum Quantity, Step Control & Price Limit for WooCommerce
minmax-quantities-for-woocommerce
Control product min max quantity along with quantity steps. Also set quantity and amount limits for cart and order.
WCS Store Rules – Minimum and Maximum Purchase Rules for WooCommerce
store-rules
Ultimate Solution for Store-Wide Rules, Restrictions & Customization in WooCommerce.
PiWeb Min/Max Quantity & Minimum Order Limits for WooCommerce
pisol-mmq
Set Product Quantity, Minimum Maximum Quantity, Minimum Order Amount, Minimum order size for WooCommerce
Min Max Step Quantity Limits Manager for WooCommerce Developer Profile
64 plugins · 137K total installs
How We Detect Min Max Step Quantity Limits Manager for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-quantity-for-woocommerce/assets/css/frontend.css/wp-content/plugins/product-quantity-for-woocommerce/assets/js/frontend.js/wp-content/plugins/product-quantity-for-woocommerce/assets/css/frontend-legacy.css/wp-content/plugins/product-quantity-for-woocommerce/assets/js/frontend-legacy.js/wp-content/plugins/product-quantity-for-woocommerce/assets/js/frontend.js/wp-content/plugins/product-quantity-for-woocommerce/assets/js/frontend-legacy.jsproduct-quantity-for-woocommerce/assets/css/frontend.css?ver=product-quantity-for-woocommerce/assets/js/frontend.js?ver=product-quantity-for-woocommerce/assets/css/frontend-legacy.css?ver=product-quantity-for-woocommerce/assets/js/frontend-legacy.js?ver=HTML / DOM Fingerprints
alg-wc-pq-quantity-wrapperalg-wc-pq-quantity-inputdata-alg-wc-pq-product-iddata-alg-wc-pq-max-qtydata-alg-wc-pq-min-qtydata-alg-wc-pq-step-qtydata-alg-wc-pq-qty-incrementdata-alg-wc-pq-qty-decrementalg_wc_pq_frontend_params