QuickSwish – WooCommerce Product Quick View Security & Risk Analysis

wordpress.org/plugins/quickswish

QuickSwish is an ultimate and exclusive WooCommerce plugin that allows you to create stunning quickview button for your WooCommerce store.

300 active installs v1.1.2 PHP + WP 5.0+ Updated Dec 4, 2025
product-popupproduct-quick-viewquick-viewwoocommercewoocommerce-quick-view
100
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 28, 2023
Safety Verdict

Is QuickSwish – WooCommerce Product Quick View Safe to Use in 2026?

Generally Safe

Score 100/100

QuickSwish – WooCommerce Product Quick View has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 28, 2023Updated 4mo ago
Risk Assessment

The "quickswish" plugin v1.1.2 presents a mixed security posture. On the positive side, the code analysis reveals a complete absence of dangerous functions, no file operations, and no external HTTP requests, which significantly reduces the potential attack surface. Furthermore, all SQL queries are properly prepared, and there are a healthy number of nonce and capability checks in place. This indicates good development practices in these areas.

However, there are concerning aspects. The static analysis shows that 62% of output is not properly escaped. This leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks where unescaped data could be rendered in the browser. While taint analysis did not reveal any issues, the high percentage of unescaped output is a significant concern that could be exploited if an attacker can inject malicious scripts.

The plugin's vulnerability history shows a single past medium-severity Cross-Site Request Forgery (CSRF) vulnerability, which has since been patched. While the absence of currently unpatched vulnerabilities is a good sign, the past occurrence of CSRF highlights the need for continuous vigilance and adherence to secure coding practices. Overall, the plugin has strengths in its handling of SQL and authentication mechanisms, but the significant amount of unescaped output poses a notable risk.

Key Concerns

  • Significant portion of output is not properly escaped
  • Past medium severity CSRF vulnerability
Vulnerabilities
1

QuickSwish – WooCommerce Product Quick View Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-0499medium · 4.3Cross-Site Request Forgery (CSRF)

QuickSwish <= 1.0.9 - Cross-Site Request Forgery to Arbitrary Plugin Activation

Feb 28, 2023 Patched in 1.1.0 (329d)
Code Analysis
Analyzed Mar 16, 2026

QuickSwish – WooCommerce Product Quick View Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
73 escaped
Nonce Checks
3
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

62% escaped118 total outputs
Attack Surface

QuickSwish – WooCommerce Product Quick View Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_quickswish_productincludes\classes\Ajax.php:33
noprivwp_ajax_quickswish_productincludes\classes\Ajax.php:34
authwp_ajax_quickswish_insert_to_cartincludes\classes\Ajax.php:38
noprivwp_ajax_quickswish_insert_to_cartincludes\classes\Ajax.php:39

Shortcodes 1

[quickswish_button] includes\classes\Frontend\Shortcode.php:30
WordPress Hooks 33
actioninitincludes\classes\Actions.php:32
actionadmin_initincludes\classes\Admin\Admin_Fields.php:37
actionadmin_menuincludes\classes\Admin\Dashboard.php:50
actionadmin_initincludes\classes\Admin\Dashboard.php:54
actioninitincludes\classes\Admin\Dashboard.php:57
actionadmin_enqueue_scriptsincludes\classes\Admin\Dashboard.php:119
actionadmin_noticesincludes\classes\Admin\Notices.php:24
actionadmin_menuincludes\classes\Admin\Recommended_Plugins.php:78
actionadmin_enqueue_scriptsincludes\classes\Admin\Recommended_Plugins.php:79
actionadmin_enqueue_scriptsincludes\classes\Admin\Settings_Api.php:23
actioninitincludes\classes\Frontend\Button_Manager.php:29
actionwoocommerce_after_shop_loop_itemincludes\classes\Frontend\Button_Manager.php:44
actionwoocommerce_before_shop_loop_itemincludes\classes\Frontend\Button_Manager.php:48
actionwoocommerce_after_shop_loop_itemincludes\classes\Frontend\Button_Manager.php:52
actionwp_footerincludes\classes\Frontend\Popup_Manager.php:32
filterwoocommerce_add_to_cart_form_actionincludes\classes\Frontend\Popup_Manager.php:38
actioninitincludes\classes\Frontend\Popup_Manager.php:94
actionquickswish_product_contentincludes\classes\Frontend\Popup_Manager.php:99
actionquickswish_product_contentincludes\classes\Frontend\Popup_Manager.php:101
actionquickswish_product_contentincludes\classes\Frontend\Popup_Manager.php:142
actionquickswish_product_contentincludes\classes\Frontend\Popup_Manager.php:146
actionquickswish_product_contentincludes\classes\Frontend\Popup_Manager.php:150
actionquickswish_product_contentincludes\classes\Frontend\Popup_Manager.php:154
actionquickswish_product_contentincludes\classes\Frontend\Popup_Manager.php:158
actionquickswish_product_contentincludes\classes\Frontend\Popup_Manager.php:163
actionquickswish_product_imageincludes\classes\Frontend\Popup_Manager.php:179
actionquickswish_product_imageincludes\classes\Frontend\Popup_Manager.php:180
actionquickswish_product_imageincludes\classes\Frontend\Popup_Manager.php:184
actionquickswish_product_imageincludes\classes\Frontend\Popup_Manager.php:185
actionwp_footerincludes\classes\Frontend\Shortcode.php:48
actionwp_enqueue_scriptsincludes\classes\Scripts.php:30
actionadmin_enqueue_scriptsincludes\classes\Scripts.php:31
actionbefore_woocommerce_initquickswish.php:48
Maintenance & Trust

QuickSwish – WooCommerce Product Quick View Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version
Downloads10K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

QuickSwish – WooCommerce Product Quick View Developer Profile

HT Plugins

23 plugins · 64K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
124 days
View full developer profile
Detection Fingerprints

How We Detect QuickSwish – WooCommerce Product Quick View

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quickswish/assets/css/quickswish-admin.css/wp-content/plugins/quickswish/assets/js/quickswish-admin.js
Script Paths
/wp-content/plugins/quickswish/vendor/autoload.php
Version Parameters
quickswish/assets/css/quickswish-admin.css?ver=quickswish/assets/js/quickswish-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
quickswish-admin-wrapper
HTML Comments
<!-- wp:quickswish/quick-view --><!-- /wp:quickswish/quick-view --><!-- quickswish-settings-wrapper --><!-- /quickswish-settings-wrapper -->
Data Attributes
data-quickswish-product-id
JS Globals
quickSwishAjax
REST Endpoints
/wp-json/quickswish/v1/products
Shortcode Output
[quickswish_products_category]
FAQ

Frequently Asked Questions about QuickSwish – WooCommerce Product Quick View