
TG Product Quantity Plus Minus Button Security & Risk Analysis
wordpress.org/plugins/product-quantity-updaterThis plugin will add quantity increment and decrement buttons with the product quantity input control.
Is TG Product Quantity Plus Minus Button Safe to Use in 2026?
Generally Safe
Score 92/100TG Product Quantity Plus Minus Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "product-quantity-updater" v1.1.4 plugin exhibits a seemingly strong security posture. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-item attack surface. Furthermore, the plugin avoids dangerous functions, performs all SQL queries using prepared statements, and makes no external HTTP requests. The absence of any known CVEs and a clean vulnerability history also contribute to a positive security outlook.
However, the analysis does reveal areas for improvement. A significant concern is the low percentage of properly escaped output (12%). This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where unescaped data displayed to users could be manipulated to execute malicious scripts. While the taint analysis shows no flows with unsanitized paths, this might be due to the limited number of flows analyzed or the absence of complex data processing within the plugin that would trigger such analysis. The lack of nonce checks, while not directly on an attack surface, is a general security practice that could strengthen the plugin's defenses against certain types of attacks.
In conclusion, the plugin benefits from a small attack surface and secure database interactions. Nevertheless, the prevalent unescaped output is a critical weakness that needs immediate attention to prevent potential XSS attacks. The limited taint analysis and absence of nonce checks are minor points to consider for future hardening, but the output escaping issue is the most pressing concern for this version.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks found
TG Product Quantity Plus Minus Button Security Vulnerabilities
TG Product Quantity Plus Minus Button Code Analysis
Output Escaping
TG Product Quantity Plus Minus Button Attack Surface
WordPress Hooks 13
Maintenance & Trust
TG Product Quantity Plus Minus Button Maintenance & Trust
Maintenance Signals
Community Trust
TG Product Quantity Plus Minus Button Alternatives
Quantity Plus Minus Button for WooCommerce
wc-quantity-plus-minus-button
Easily add plus, minus button for WooCommerce Quantity Input box in everywhere. Such: Single Page, In Loop Quantity input, Cart page , everywhere.
SMNTCS Quantity Increment Buttons for WooCommerce
smntcs-woocommerce-quantity-buttons
Display the quantity increment buttons on the WooCommerce product page and the WooCommerce cart page.
Conditional Discounts for WooCommerce – A simple yet complete woocommerce dynamic pricing plugin
woo-advanced-discounts
A powerful WooCommerce dynamic pricing plugin for bulk discounts, free gifts, BOGOs, customer role or groups based deals and much more.
Min Max Control – Min Max Quantity & Step Control for WooCommerce
woo-min-max-quantity-step-control-single
Min Max Control plugin offers to set product's minimum, maximum quantity and step of each product individually.
Default Quantity for WooCommerce
default-quantity-for-woocommerce
Discover the simplest method to establish default quantities for your WooCommerce store effortlessly.
TG Product Quantity Plus Minus Button Developer Profile
2 plugins · 210 total installs
How We Detect TG Product Quantity Plus Minus Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-quantity-updater/css/tgqb-admin.css/wp-content/plugins/product-quantity-updater/js/tgqb-admin.js/wp-content/plugins/product-quantity-updater/admin/js/tgqb-admin.jstgqb-admin?ver=tgqb-admin.js?ver=HTML / DOM Fingerprints
switchslidername="tgqb_settings[tgqb_field_cart_page]"name="tgqb_settings[tgqb_field_product_page]"name="tgqb_settings[tgqb_field_update_cart]"