
Productive Commerce – Wishlist, Compare, Quick View, & MiniCart Security & Risk Analysis
wordpress.org/plugins/productive-commerceIntegrate Wishlists, Product Comparison, Quick View, and Mini-Cart on your WooCommerce sites.
Is Productive Commerce – Wishlist, Compare, Quick View, & MiniCart Safe to Use in 2026?
Mostly Safe
Score 76/100Productive Commerce – Wishlist, Compare, Quick View, & MiniCart is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "productive-commerce" plugin v1.1.39 exhibits a mixed security posture. While it demonstrates good practices in SQL query handling with 100% prepared statements and a significant portion of output escaping, several concerning areas are present. The static analysis highlights a substantial attack surface with 54 entry points, notably including 2 AJAX handlers that lack authentication checks. This presents a direct vulnerability for unauthorized execution of plugin functions.
Taint analysis further exacerbates these concerns, revealing 6 flows with unsanitized paths, all categorized as high severity. This indicates that untrusted input can be used to influence critical operations within the plugin, potentially leading to various forms of code execution or data manipulation if not properly handled downstream. The plugin's vulnerability history is also a significant red flag, with one high-severity unpatched CVE related to SQL injection. This suggests a recurring issue with input sanitization, and the fact that it remains unpatched is a critical indicator of an ongoing risk.
In conclusion, while the plugin has strengths in its database interaction security, the combination of unprotected entry points, high-severity unsanitized taint flows, and an unpatched historical vulnerability creates a considerable security risk. The unpatched CVE and the identified taint flows are particularly alarming and require immediate attention. The lack of authentication on AJAX handlers also broadens the potential attack vectors.
Key Concerns
- Unpatched High Severity CVE
- High Severity Taint Flows
- AJAX Handlers Without Auth Checks
- Unsanitized Paths in Taint Analysis
- Output Escaping Below 100%
Productive Commerce – Wishlist, Compare, Quick View, & MiniCart Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Productive Commerce <= 1.1.22 - Unauthenticated SQL Injection
Productive Commerce – Wishlist, Compare, Quick View, & MiniCart Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Productive Commerce – Wishlist, Compare, Quick View, & MiniCart Attack Surface
AJAX Handlers 42
Shortcodes 12
WordPress Hooks 99
Maintenance & Trust
Productive Commerce – Wishlist, Compare, Quick View, & MiniCart Maintenance & Trust
Maintenance Signals
Community Trust
Productive Commerce – Wishlist, Compare, Quick View, & MiniCart Alternatives
YITH WooCommerce Wishlist
yith-woocommerce-wishlist
YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 10.6.x compatible.
Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later
flexible-wishlist
Lightweight and simple WooCommerce wishlist. Increases sales. Fits any theme. Customizes texts and icons. Add to ecommerce wishlist with just 1 click.
Wishlist for WooCommerce
wt-woocommerce-wishlist
This WooCommerce wishlist plugin adds a wishlist feature to your WooCommerce store. Let the users easily add and manage products from their wishlist p …
Wishlist for WooCommerce
jvm-woocommerce-wishlist
Supercharge your sales with WooCommerce Wishlist - a powerful tool that empowers customers to create wishlists and enhances their shopping experience.
Wishlist and Save for later for Woocommerce
aco-wishlist-for-woocommerce
Wishlist for WooCommerce helps to manage Wishlist and save for later feature in a WooCommerce store
Productive Commerce – Wishlist, Compare, Quick View, & MiniCart Developer Profile
9 plugins · 200 total installs
How We Detect Productive Commerce – Wishlist, Compare, Quick View, & MiniCart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/productive-commerce/assets/css/style.css/wp-content/plugins/productive-commerce/assets/js/main.js/wp-content/plugins/productive-commerce/assets/js/main.jsproductive-commerce/assets/css/style.css?ver=productive-commerce/assets/js/main.js?ver=HTML / DOM Fingerprints
productive-commerce-wrapdata-pc-product-idproductive_commerce_paramsPRODUCTIVE_GLOBAL_PRODUCTIVE_PLUGIN_COMMERCE_TEXT_DOMAINPRODUCTIVE_GLOBAL_PRODUCTIVE_PLUGIN_COMMERCE_TITLEPRODUCTIVE_GLOBAL_PRODUCTIVE_PLUGIN_COMMERCE_REPO_URLPRODUCTIVE_GLOBAL_PRODUCTIVE_PLUGIN_COMMERCE_OUR_URLPRODUCTIVE_GLOBAL_PRODUCTIVE_PLUGIN_COMMERCE_ADMIN_OPTIONS_LINK/wp-json/productive_commerce/v1/add_to_cart/wp-json/productive_commerce/v1/update_cart[productive_commerce_wishlist][productive_commerce_compare][productive_commerce_quickview]