Quasar Variable Attributes Security & Risk Analysis

wordpress.org/plugins/quasar-variable-attributes

The Quasar Variable Attributes plugin will allow you to create a more complex and beautiful selection of options in a variable product.

10 active installs v2.2 PHP 5.6+ WP 4.8+ Updated Apr 4, 2023
improved-variable-product-attributesvariable-product-attributeswoocommerce-formwoocommerce-variable
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quasar Variable Attributes Safe to Use in 2026?

Generally Safe

Score 85/100

Quasar Variable Attributes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "quasar-variable-attributes" v2.2 plugin exhibits a generally good security posture based on the provided static analysis. The plugin has a small attack surface, with all identified entry points (AJAX handlers) correctly protected by authorization checks. This is further reinforced by the presence of nonce checks and capability checks for these handlers. The absence of dangerous functions, file operations, and external HTTP requests is also a positive indicator. However, there are areas for improvement. A significant portion of SQL queries (64%) are not using prepared statements, which can expose the plugin to SQL injection vulnerabilities if the inputs are not rigorously sanitized. Similarly, while a majority of output escaping is properly handled, the 33% that is not escaped presents a risk of cross-site scripting (XSS) vulnerabilities.

The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This suggests a strong commitment to security by the developers or that the plugin has not historically been a target. The lack of critical or high-severity taint flows further bolsters the confidence in its current security state. Despite the positive indicators, the potential for SQL injection and XSS due to incomplete prepared statements and output escaping, respectively, means the plugin is not entirely without risk. The developers should prioritize addressing these code quality concerns to further strengthen the plugin's security.

Key Concerns

  • SQL queries not using prepared statements
  • Output not properly escaped
Vulnerabilities
None known

Quasar Variable Attributes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Quasar Variable Attributes Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
4 prepared
Unescaped Output
193
399 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

36% prepared11 total queries

Output Escaping

67% escaped592 total outputs
Attack Surface

Quasar Variable Attributes Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_save_attr_setting_qquasar-variable-attributes-main.php:1083
authwp_ajax_save_attr_import_setting_qquasar-variable-attributes-main.php:1084
WordPress Hooks 15
actionadmin_menuquasar-variable-attributes-main.php:19
actionadmin_enqueue_scriptsquasar-variable-attributes-main.php:88
actionplugins_loadedquasar-variable-attributes-main.php:95
actionwp_footerquasar-variable-attributes-main.php:106
actionadmin_enqueue_scriptsquasar-variable-attributes-main.php:153
filterwoocommerce_product_data_tabsquasar-variable-attributes-main.php:172
actionwoocommerce_product_data_panelsquasar-variable-attributes-main.php:207
actionwoocommerce_admin_process_product_objectquasar-variable-attributes-main.php:216
actionwoocommerce_after_add_to_cart_buttonquasar-variable-attributes-main.php:951
actionwoocommerce_before_quantity_input_fieldquasar-variable-attributes-main.php:971
actionwoocommerce_single_product_summaryquasar-variable-attributes-main.php:989
actionwoocommerce_product_meta_endquasar-variable-attributes-main.php:1008
actionwoocommerce_after_shop_loop_itemquasar-variable-attributes-main.php:1028
actionwoocommerce_before_shop_loop_itemquasar-variable-attributes-main.php:1050
actionwp_footerquasar-variable-attributes-main.php:1073
Maintenance & Trust

Quasar Variable Attributes Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 4, 2023
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Quasar Variable Attributes Developer Profile

nucleusgenius

2 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quasar Variable Attributes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quasar-variable-attributes/assets/css/frontend.css/wp-content/plugins/quasar-variable-attributes/assets/js/frontend.js/wp-content/plugins/quasar-variable-attributes/assets/js/admin-all.js/wp-content/plugins/quasar-variable-attributes/assets/css/admin-all.css/wp-content/plugins/quasar-variable-attributes/assets/js/admin.js/wp-content/plugins/quasar-variable-attributes/assets/font-awesome/css/font-awesome.min.css/wp-content/plugins/quasar-variable-attributes/assets/css/admin.css/wp-content/plugins/quasar-variable-attributes/lib/wp-color-picker-alpha-master/dist/wp-color-picker-alpha.min.js
Script Paths
/wp-content/plugins/quasar-variable-attributes/assets/js/admin-all.js/wp-content/plugins/quasar-variable-attributes/assets/js/frontend.js/wp-content/plugins/quasar-variable-attributes/assets/js/admin.js/wp-content/plugins/quasar-variable-attributes/lib/wp-color-picker-alpha-master/dist/wp-color-picker-alpha.min.js
Version Parameters
quasar-variable-attributes/style.css?ver=quasar-variable-attributes/assets/js/admin-all.js?ver=quasar-variable-attributes/assets/css/admin-all.css?ver=quasar-variable-attributes/assets/js/frontend.js?ver=quasar-variable-attributes/assets/js/admin.js?ver=quasar-variable-attributes/assets/font-awesome/css/font-awesome.min.css?ver=quasar-variable-attributes/assets/css/admin.css?ver=quasar-variable-attributes/lib/wp-color-picker-alpha-master/dist/wp-color-picker-alpha.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
quasar-attribute-frontend-stylequasar-attribute-admin-stylequasar-attr-variable
Data Attributes
data-localize="add-cart"data-localize="select-option"data-localize="option-not-available"data-localize="choose-option"data-localize="fill-all"
JS Globals
quasar_variable_free_attributes_urlparamswp
FAQ

Frequently Asked Questions about Quasar Variable Attributes