
Product Shortlist Security & Risk Analysis
wordpress.org/plugins/product-shortlistEnable your customers to shortlist their favorite products and let them buy later easily.
Is Product Shortlist Safe to Use in 2026?
Generally Safe
Score 85/100Product Shortlist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'product-shortlist' v1.0.4 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerability history, suggesting diligent maintenance or a lack of past exploits. However, significant concerns arise from the attack surface analysis. A substantial portion of its AJAX handlers (5 out of 12) lack authentication checks, presenting a clear risk of unauthorized actions. Furthermore, the taint analysis reveals 6 out of 7 flows with unsanitized paths, indicating a potential for various injection vulnerabilities despite the lack of reported critical or high severity taint issues in this specific analysis. The low percentage of properly escaped output (39%) is also a notable weakness, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities across multiple output points.
While the plugin benefits from a clean vulnerability history and secure SQL handling, the combination of unprotected AJAX endpoints, unsanitized data flows, and insufficient output escaping creates a considerable security risk. The absence of critical or high severity taint findings in the current analysis is a positive sign, but the presence of unsanitized paths and a large number of unescaped outputs suggests a latent risk that could be exploited. The plugin's strengths in SQL security and its vulnerability-free past are commendable, but these are overshadowed by the identified weaknesses in its attack surface and data handling, necessitating careful consideration for users.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint analysis
- Low percentage of properly escaped output
- Limited capability checks
- Limited nonce checks
Product Shortlist Security Vulnerabilities
Product Shortlist Release Timeline
Product Shortlist Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Product Shortlist Attack Surface
AJAX Handlers 12
Shortcodes 1
WordPress Hooks 27
Maintenance & Trust
Product Shortlist Maintenance & Trust
Maintenance Signals
Community Trust
Product Shortlist Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Limit Login Attempts Reloaded – Login Security, 2FA, Brute Force Protection & Firewall
limit-login-attempts-reloaded
Stop password guessing attacks, secure WooCommerce, block bad IPs, block by countries (Pro), and add email 2FA. Lightweight with better performance.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Product Shortlist Developer Profile
25 plugins · 5K total installs
How We Detect Product Shortlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-shortlist/assets/css/jquery.dataTables.min.css/wp-content/plugins/product-shortlist/assets/css/shortlist.css/wp-content/plugins/product-shortlist/assets/js/jquery.dataTables.min.js/wp-content/plugins/product-shortlist/assets/js/shortlist.js/wp-content/plugins/product-shortlist/assets/js/wooswipe.min.js/wp-content/plugins/product-shortlist/assets/js/jquery.dataTables.min.js/wp-content/plugins/product-shortlist/assets/js/shortlist.js/wp-content/plugins/product-shortlist/assets/js/wooswipe.min.jsproduct-shortlist/assets/css/jquery.dataTables.min.css?ver=product-shortlist/assets/css/shortlist.css?ver=product-shortlist/assets/js/jquery.dataTables.min.js?ver=product-shortlist/assets/js/shortlist.js?ver=product-shortlist/assets/js/wooswipe.min.js?ver=HTML / DOM Fingerprints
ced-ps-add-to-shortlistced-ps-buttonced-ps-dataTables_wrapperced-ps-shortlist-tableced-ps-remove-from-shortlist<!-- Add to Shortlist --><!-- Remove from Shortlist --><!-- Shortlist Product Data --><!-- Product Shortlist Data -->+7 moredata-product_iddata-cart-iddata-shortlist-iddata-user-iddata-noncedata-actionced_ps_ajax_object/wp-json/ced-ps/v1/add-to-shortlist/wp-json/ced-ps/v1/remove-from-shortlist/wp-json/ced-ps/v1/get-shortlist[ced_ps_shortlist_display][ced_ps_shortlist_button]