
Enquiry Cart For WooCommerce – Request a Quote Security & Risk Analysis
wordpress.org/plugins/product-quote-cart-for-wcSupport: https://www.codesmade.com/contact-us/ Documentation: https://www.codesmade.com/enquiry-cart-for-woocommerce-request-a-quote-plugin-documentat …
Is Enquiry Cart For WooCommerce – Request a Quote Safe to Use in 2026?
Generally Safe
Score 100/100Enquiry Cart For WooCommerce – Request a Quote has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "product-quote-cart-for-wc" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good security practices by implementing nonce checks for all identified AJAX endpoints and permission callbacks for all REST API routes, effectively limiting its attack surface from unauthorized access. Furthermore, it has a clean vulnerability history with no recorded CVEs, suggesting a generally stable and well-maintained codebase. However, the static analysis reveals potential weaknesses that warrant attention.
The taint analysis indicates two flows with unsanitized paths, both classified as high severity. This is a significant concern as unsanitized input can lead to various vulnerabilities, including cross-site scripting (XSS) or SQL injection, depending on the context of the data flow. Additionally, the plugin's output escaping is only properly implemented in 39% of cases, which is a substantial weakness and a common vector for XSS attacks. The presence of a bundled, outdated library (Select2 v3.4.8) also introduces a potential risk, as older versions of libraries may contain known vulnerabilities that could be exploited if not patched.
In conclusion, while the plugin benefits from strong access control mechanisms and a clean vulnerability history, the identified high-severity taint flows and insufficient output escaping represent critical security concerns. The outdated bundled library adds another layer of potential risk. These issues suggest that while the plugin is protected against direct unauthorized access, it may be vulnerable to attacks that leverage unsanitized input or unescaped output.
Key Concerns
- High severity unsanitized taint flows found
- Low percentage of properly escaped output
- Bundled outdated library (Select2 v3.4.8)
Enquiry Cart For WooCommerce – Request a Quote Security Vulnerabilities
Enquiry Cart For WooCommerce – Request a Quote Release Timeline
Enquiry Cart For WooCommerce – Request a Quote Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Enquiry Cart For WooCommerce – Request a Quote Attack Surface
AJAX Handlers 2
REST API Routes 10
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Enquiry Cart For WooCommerce – Request a Quote Maintenance & Trust
Maintenance Signals
Community Trust
Enquiry Cart For WooCommerce – Request a Quote Alternatives
Product Enquiry for WooCommerce
product-enquiry-for-woocommerce
Product Enquiry allows prospective customers to "Make an Enquiry" about a product, or "Request a Quote" right from within the product page.
Product Enquiry for WooCommerce
gm-woocommerce-quote-popup
Allow customers to request quotes, send product enquiries, and run WooCommerce in catalog mode by hiding prices and replacing the Add to Cart button.
Hide Cart Functions
hide-cart-functions
Hide the product's price, add-to-cart button, quantity, and options on any product and order. Inject an optional message.
PiWeb Product Enquiry or product catalog for WooCommerce
enquiry-quotation-for-woocommerce
Product enquiry for WooCommerce and quote request plugin that can save enquiries and email the WooCommerce product enquiry as well
Remove Add to Cart Button for WooCommerce
remove-add-to-cart-button-for-woocommerce
Remove Add to Cart Button for WooCommerce plugin gives you a really easy interface to hide/remove the product Add to Cart button and product price.
Enquiry Cart For WooCommerce – Request a Quote Developer Profile
26 plugins · 12K total installs
How We Detect Enquiry Cart For WooCommerce – Request a Quote
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-quote-cart-for-wc/build/admin/admin.js/wp-content/plugins/product-quote-cart-for-wc/build/admin/admin.css/wp-content/plugins/product-quote-cart-for-wc/build/admin/admin.jsproduct-quote-cart-for-wc/build/admin/admin.js?ver=product-quote-cart-for-wc/build/admin/admin.css?ver=HTML / DOM Fingerprints
GMPQCW-admin-rootid="GMPQCW-admin-root"gmpqcw_wp_ajaxgmpqcw_translation/gmpqcw/v1/get-settings/gmpqcw/v1/get-enquiries/gmpqcw/v1/save-settings/gmpqcw/v1/deleteallenquirys/gmpqcw/v1/save-customfield/gmpqcw/v1/delete-customfield