Remove Add to Cart Button for WooCommerce Security & Risk Analysis

wordpress.org/plugins/remove-add-to-cart-button-for-woocommerce

Remove Add to Cart Button for WooCommerce plugin gives you a really easy interface to hide/remove the product Add to Cart button and product price.

500 active installs v2.1.8 PHP + WP 4.4+ Updated Dec 10, 2025
hide-add-to-carthide-add-to-cart-buttonhide-product-priceremove-add-to-cartremove-add-to-cart-woocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Remove Add to Cart Button for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Remove Add to Cart Button for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin "remove-add-to-cart-button-for-woocommerce" v2.1.8 exhibits a generally strong security posture, particularly in its handling of SQL queries and its limited attack surface. The absence of known CVEs and the use of prepared statements for all SQL queries are positive indicators. The presence of a single nonce check is a good practice for request verification.

However, a significant concern arises from the taint analysis, which reveals two flows with unsanitized paths. While the static analysis does not categorize these as critical or high severity, unsanitized paths are inherently risky and could potentially lead to vulnerabilities if not properly handled within the application context. Additionally, the relatively low percentage of properly escaped output (29%) suggests a potential for cross-site scripting (XSS) vulnerabilities, as user-supplied data might be outputted to the browser without adequate sanitization.

Given the lack of historical vulnerabilities and a small attack surface, the plugin appears to be developed with security in mind. Nevertheless, the identified unsanitized paths and the prevalence of unescaped output warrant careful investigation and remediation. The plugin's strengths lie in its secure SQL practices and minimal entry points, but its weaknesses are in the handling of data flow and output sanitization.

Key Concerns

  • Taint flows with unsanitized paths found
  • Low percentage of properly escaped output
Vulnerabilities
None known

Remove Add to Cart Button for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Remove Add to Cart Button for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
39
16 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

29% escaped55 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ratcw_admin_notice (remove-add-to-cart-button-woocommerce.php:127)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Remove Add to Cart Button for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 28
actionplugins_loadedincludes\class-remove-add-to-cart-button-woocommerce.php:130
actionadmin_enqueue_scriptsincludes\class-remove-add-to-cart-button-woocommerce.php:142
actionadmin_enqueue_scriptsincludes\class-remove-add-to-cart-button-woocommerce.php:143
filterwoocommerce_product_data_tabsincludes\class-remove-add-to-cart-button-woocommerce.php:145
actionadmin_headincludes\class-remove-add-to-cart-button-woocommerce.php:146
actionwoocommerce_product_data_panelsincludes\class-remove-add-to-cart-button-woocommerce.php:147
actionwoocommerce_process_product_metaincludes\class-remove-add-to-cart-button-woocommerce.php:148
actionwoocommerce_settings_tabs_arrayincludes\class-remove-add-to-cart-button-woocommerce.php:156
actionwoocommerce_settings_tabs_remove-add-to-cart-button-settingsincludes\class-remove-add-to-cart-button-woocommerce.php:162
actionwoocommerce_update_options_remove-add-to-cart-button-settingsincludes\class-remove-add-to-cart-button-woocommerce.php:163
actionwoocommerce_get_price_htmlincludes\class-remove-add-to-cart-button-woocommerce.php:182
filterwoocommerce_cart_item_priceincludes\class-remove-add-to-cart-button-woocommerce.php:189
filterwoocommerce_cart_item_subtotalincludes\class-remove-add-to-cart-button-woocommerce.php:196
filterwoocommerce_loop_add_to_cart_linkincludes\class-remove-add-to-cart-button-woocommerce.php:204
actionwoocommerce_simple_add_to_cartincludes\class-remove-add-to-cart-button-woocommerce.php:211
actionwoocommerce_variable_add_to_cartincludes\class-remove-add-to-cart-button-woocommerce.php:217
actionwoocommerce_grouped_add_to_cartincludes\class-remove-add-to-cart-button-woocommerce.php:223
actionwoocommerce_external_add_to_cartincludes\class-remove-add-to-cart-button-woocommerce.php:229
filterwoocommerce_blocks_product_grid_item_htmlincludes\class-remove-add-to-cart-button-woocommerce.php:235
actiontemplate_redirectincludes\class-remove-add-to-cart-button-woocommerce.php:245
filterwoocommerce_get_availability_textincludes\class-remove-add-to-cart-button-woocommerce.php:252
filterwoocommerce_show_variation_pricepublic\class-remove-add-to-cart-button-woocommerce-public.php:299
filterwoocommerce_show_variation_pricepublic\class-remove-add-to-cart-button-woocommerce-public.php:326
filterwoocommerce_show_variation_pricepublic\class-remove-add-to-cart-button-woocommerce-public.php:353
actionplugins_loadedremove-add-to-cart-button-woocommerce.php:88
actionadmin_noticesremove-add-to-cart-button-woocommerce.php:126
actionadmin_initremove-add-to-cart-button-woocommerce.php:169
actionadmin_noticesremove-add-to-cart-button-woocommerce.php:204
Maintenance & Trust

Remove Add to Cart Button for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version
Downloads16K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Remove Add to Cart Button for WooCommerce Developer Profile

WP Artisan

4 plugins · 780 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Remove Add to Cart Button for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/remove-add-to-cart-button-for-woocommerce/assets/css/ratcw-style.css/wp-content/plugins/remove-add-to-cart-button-for-woocommerce/assets/js/ratcw-script.js
Script Paths
/wp-content/plugins/remove-add-to-cart-button-for-woocommerce/assets/js/ratcw-script.js
Version Parameters
remove-add-to-cart-button-for-woocommerce/assets/css/ratcw-style.css?ver=remove-add-to-cart-button-for-woocommerce/assets/js/ratcw-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
ratcw-plugins-gopro
FAQ

Frequently Asked Questions about Remove Add to Cart Button for WooCommerce