Quotify | Product Quotation – Request a Quote for WooCommerce Security & Risk Analysis

wordpress.org/plugins/product-quotation-for-woocommerce

Allow your customer to add products to Quotation Cart and ask for price or any information regarding the order by submitting a Quotation form.

100 active installs v2.7.7 PHP + WP 4.0+ Updated Jun 9, 2026
price-quotequote-cartrequest-a-quoterfqwoocommerce-quote
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quotify | Product Quotation – Request a Quote for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Quotify | Product Quotation – Request a Quote for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "product-quotation-for-woocommerce" plugin v2.5.0 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and a very high percentage of properly escaped output. The attack surface, while present with 18 AJAX handlers, appears to be well-protected with authentication checks. Crucially, there are no recorded vulnerabilities (CVEs) for this plugin, and the taint analysis revealed no high-severity issues, indicating a history of secure development or diligent patching by developers. The presence of a "unserialize" function is a potential concern, as it can lead to code execution vulnerabilities if not handled with extreme care, especially with untrusted input. However, the absence of taint flows with unsanitized paths or critical/high severity issues suggests that this function is likely used in a controlled environment or with sanitized data.

Key Concerns

  • Presence of dangerous function unserialize
Vulnerabilities
None known

Quotify | Product Quotation – Request a Quote for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Quotify | Product Quotation – Request a Quote for WooCommerce Release Timeline

v2.7.7Current
v2.7.6
v2.7.5
v2.6.0
v2.5.0
v2.0.5
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Quotify | Product Quotation – Request a Quote for WooCommerce Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
3 prepared
Unescaped Output
4
225 escaped
Nonce Checks
13
Capability Checks
9
File Operations
2
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize<?php $quoteProducts = unserialize( get_post_meta( $quotation->ID, 'pqfw_products_info', true ) ); ?includes\views\quotation-products-detail.php:25

SQL Query Safety

100% prepared3 total queries

Output Escaping

98% escaped229 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save (includes\classes\settings.php:139)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Quotify | Product Quotation – Request a Quote for WooCommerce Attack Surface

Entry Points19
Unprotected0

AJAX Handlers 18

authwp_ajax_quotify/addons/get_allincludes\addons.php:31
authwp_ajax_quotify/addons/saveincludes\addons.php:32
authwp_ajax_quotify/ajax/cart/loadincludes\ajax\cart.php:28
noprivwp_ajax_quotify/ajax/cart/loadincludes\ajax\cart.php:29
authwp_ajax_pqfw_remove_productincludes\ajax\cart.php:31
noprivwp_ajax_pqfw_remove_productincludes\ajax\cart.php:32
authwp_ajax_quotify/ajax/cart/updateincludes\ajax\cart.php:34
noprivwp_ajax_quotify/ajax/cart/updateincludes\ajax\cart.php:35
authwp_ajax_quotify/product/addincludes\ajax\product.php:26
noprivwp_ajax_quotify/product/addincludes\ajax\product.php:27
authwp_ajax_quotify/ajax/loadincludes\ajax\quotations.php:28
authwp_ajax_quotify/quotation/getincludes\ajax\quotations.php:29
authwp_ajax_quotify/quotations/deleteincludes\ajax\quotations.php:30
authwp_ajax_quotify/quotations/restoreincludes\ajax\quotations.php:31
authwp_ajax_pqfw_quotation_submissionincludes\classes\form-handler.php:28
noprivwp_ajax_pqfw_quotation_submissionincludes\classes\form-handler.php:29
authwp_ajax_quotify/settings/saveincludes\classes\settings.php:53
authwp_ajax_pqfw_cart_get_permalinkincludes\classes\settings.php:54

Shortcodes 1

[pqfw_quotations_cart] includes\classes\shortcode.php:26
WordPress Hooks 21
actioninitincludes\classes\admin.php:43
actionadmin_enqueue_scriptsincludes\classes\admin.php:44
actionadmin_initincludes\classes\admin.php:45
actionadmin_enqueue_scriptsincludes\classes\assets.php:29
actionwp_enqueue_scriptsincludes\classes\assets.php:30
actionwp_enqueue_scriptsincludes\classes\form.php:42
actionquotify/templates/cart/formincludes\classes\form.php:43
filterwoocommerce_loop_add_to_cart_linkincludes\classes\frontend.php:28
filterwoocommerce_get_price_htmlincludes\classes\frontend.php:32
filterwoocommerce_get_variation_price_htmlincludes\classes\frontend.php:33
filterthe_contentincludes\classes\frontend.php:36
actionquotify/quotations/after_insertincludes\classes\hooks.php:39
filterwp_mail_from_nameincludes\classes\mail.php:33
filterwp_mail_fromincludes\classes\mail.php:34
actionadmin_menuincludes\classes\menu.php:37
actionadmin_headincludes\classes\menu.php:38
filterbody_classincludes\classes\shortcode.php:27
actionwoocommerce_initincludes\PQFW.php:160
actionadmin_initincludes\PQFW.php:195
actionquotify/templates/formincludes\PQFW.php:196
actionplugins_loadedproduct-quotation-for-woocommerce.php:54
Maintenance & Trust

Quotify | Product Quotation – Request a Quote for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedJun 9, 2026
PHP min version
Downloads7K

Community Trust

Rating86/100
Number of ratings8
Active installs100
Developer Profile

Quotify | Product Quotation – Request a Quote for WooCommerce Developer Profile

Mahafuz

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quotify | Product Quotation – Request a Quote for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-quotation-for-woocommerce/assets/css/pqfw-quotations.css/wp-content/plugins/product-quotation-for-woocommerce/assets/css/pqfw-admin.css/wp-content/plugins/product-quotation-for-woocommerce/assets/build/backend.css/wp-content/plugins/product-quotation-for-woocommerce/assets/build/frontend.css
Script Paths
/wp-content/plugins/product-quotation-for-woocommerce/assets/build/backend.js/wp-content/plugins/product-quotation-for-woocommerce/assets/build/frontend.js
Version Parameters
product-quotation-for-woocommerce/assets/css/pqfw-quotations.css?ver=product-quotation-for-woocommerce/assets/css/pqfw-admin.css?ver=product-quotation-for-woocommerce/assets/build/backend.css?ver=product-quotation-for-woocommerce/assets/build/frontend.css?ver=product-quotation-for-woocommerce/assets/build/backend.js?ver=product-quotation-for-woocommerce/assets/build/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
pqfw-quotationspqfw-admin-quotationspqfw-adminpqfw-web-fontpqfw-frontend-stylepqfw-quotation-form
Data Attributes
data-pqfw-formdata-pqfw-variation-id
JS Globals
pqfw_frontend_params
REST Endpoints
/wp-json/pqfw/v1/get-product-quotation-form
Shortcode Output
[pqfw_quotation_form]
FAQ

Frequently Asked Questions about Quotify | Product Quotation – Request a Quote for WooCommerce