Remove Add to Cart WooCommerce Security & Risk Analysis

wordpress.org/plugins/remove-add-to-cart-woocommerce

How to Remove/disable Add to cart And Replace Cart button with Inquiry Us button in WooCommerce.

5K active installs v1.4.8 PHP + WP 4.6+ Updated Oct 24, 2025
add-to-cartremove-buttonwoocommerce
100
A · Safe
CVEs total1
Unpatched0
Last CVEOct 25, 2023
Safety Verdict

Is Remove Add to Cart WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Remove Add to Cart WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 25, 2023Updated 5mo ago
Risk Assessment

The "remove-add-to-cart-woocommerce" plugin exhibits a generally positive security posture, with a strong emphasis on secure coding practices. The absence of unprotected entry points and the consistent use of prepared statements for SQL queries are commendable. Nonce and capability checks are also present on key interaction points, indicating an awareness of common WordPress security threats. Furthermore, the plugin has no currently unpatched vulnerabilities, which is a good sign of maintenance.

However, there are areas for improvement. The presence of two taint flows with unsanitized paths, even if not classified as critical or high severity, warrants attention. While the output escaping is at 71%, a significant portion (29%) remains unescaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled properly. The bundled Freemius library, while not explicitly stated as outdated, is an external dependency that could potentially introduce risks if not kept up-to-date.

Given the plugin's history of a single medium-severity CSRF vulnerability in the past, combined with the identified taint flows and unescaped output, a cautious approach is recommended. The plugin demonstrates good fundamental security but has minor weaknesses that could be exploited. Continued vigilance and addressing the identified code signals are important for maintaining a secure plugin.

Key Concerns

  • Taint flows with unsanitized paths detected
  • 29% of outputs are not properly escaped
  • Bundled Freemius v1.0 library (potential for outdatedness)
Vulnerabilities
1

Remove Add to Cart WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-46629medium · 4.3Cross-Site Request Forgery (CSRF)

Remove Add to Cart WooCommerce <= 1.4.4 - Cross-Site Request Forgery to Settings Modification

Oct 25, 2023 Patched in 1.4.5 (142d)
Code Analysis
Analyzed Mar 16, 2026

Remove Add to Cart WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
34
84 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

Select2Freemius1.0

SQL Query Safety

100% prepared1 total queries

Output Escaping

71% escaped118 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
ratcwprolebase_save_data (admin\class-ratcwp-admin.php:161)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Remove Add to Cart WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_cspsearchProductsadmin\class-ratcwp-admin.php:36
authwp_ajax_cspsearchUsersadmin\class-ratcwp-admin.php:37
WordPress Hooks 51
actionadmin_menuadmin\class-ratcwp-admin.php:34
actionadmin_enqueue_scriptsadmin\class-ratcwp-admin.php:35
actionadmin_noticesadmin\class-ratcwp-admin.php:42
filterwoocommerce_loop_add_to_cart_linkfront\class-ratcwp-front.php:41
actionwoocommerce_single_product_summaryfront\class-ratcwp-front.php:44
actionwoocommerce_before_add_to_cart_buttonfront\class-ratcwp-front.php:252
actionwoocommerce_after_add_to_cart_buttonfront\class-ratcwp-front.php:253
actionwoocommerce_single_variationfront\class-ratcwp-front.php:254
actionwoocommerce_before_add_to_cart_buttonfront\class-ratcwp-front.php:259
actionwoocommerce_after_add_to_cart_buttonfront\class-ratcwp-front.php:260
actionwoocommerce_single_product_summaryfront\class-ratcwp-front.php:261
actionwoocommerce_before_add_to_cart_buttonfront\class-ratcwp-front.php:285
actionwoocommerce_after_add_to_cart_buttonfront\class-ratcwp-front.php:286
actionwoocommerce_single_variationfront\class-ratcwp-front.php:287
actionwoocommerce_before_add_to_cart_buttonfront\class-ratcwp-front.php:291
actionwoocommerce_after_add_to_cart_buttonfront\class-ratcwp-front.php:292
actionwoocommerce_single_product_summaryfront\class-ratcwp-front.php:293
actionwoocommerce_before_add_to_cart_buttonfront\class-ratcwp-front.php:303
actionwoocommerce_after_add_to_cart_buttonfront\class-ratcwp-front.php:304
actionwoocommerce_single_variationfront\class-ratcwp-front.php:305
actionwoocommerce_before_add_to_cart_buttonfront\class-ratcwp-front.php:309
actionwoocommerce_after_add_to_cart_buttonfront\class-ratcwp-front.php:310
actionwoocommerce_single_product_summaryfront\class-ratcwp-front.php:311
actionwoocommerce_before_add_to_cart_buttonfront\class-ratcwp-front.php:328
actionwoocommerce_after_add_to_cart_buttonfront\class-ratcwp-front.php:329
actionwoocommerce_before_add_to_cart_buttonfront\class-ratcwp-front.php:332
actionwoocommerce_after_add_to_cart_buttonfront\class-ratcwp-front.php:333
actionwoocommerce_before_add_to_cart_buttonfront\class-ratcwp-front.php:352
actionwoocommerce_after_add_to_cart_buttonfront\class-ratcwp-front.php:353
actionwoocommerce_before_add_to_cart_buttonfront\class-ratcwp-front.php:356
actionwoocommerce_after_add_to_cart_buttonfront\class-ratcwp-front.php:357
actionproduct_cat_edit_form_fieldsindex.php:51
actionproduct_cat_add_form_fieldsindex.php:52
actionadmin_enqueue_scriptsindex.php:64
actionedited_product_catindex.php:128
actioncreated_product_catindex.php:129
filterdeleted_term_taxonomyindex.php:164
filtermanage_edit-product_cat_columnsindex.php:184
filtermanage_product_cat_custom_columnindex.php:185
actionwoocommerce_after_shop_loop_itemindex.php:275
filterwoocommerce_loop_add_to_cart_linkindex.php:338
actionwoocommerce_before_single_product_summaryindex.php:399
actionwoocommerce_after_add_to_cart_formindex.php:441
actionwoocommerce_before_add_to_cart_buttonindex.php:447
actionwoocommerce_after_add_to_cart_buttonindex.php:448
actionwoocommerce_process_product_metaindex.php:508
filterwoocommerce_product_data_tabsindex.php:542
actionwoocommerce_product_data_panelsindex.php:588
actionadmin_headindex.php:602
actionadmin_noticesratcwp-hide-price.php:49
actionwp_loadedratcwp-hide-price.php:61
Maintenance & Trust

Remove Add to Cart WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 24, 2025
PHP min version
Downloads127K

Community Trust

Rating60/100
Number of ratings26
Active installs5K
Developer Profile

Remove Add to Cart WooCommerce Developer Profile

themelocation

6 plugins · 10K total installs

64
trust score
Avg Security Score
78/100
Avg Patch Time
111 days
View full developer profile
Detection Fingerprints

How We Detect Remove Add to Cart WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/remove-add-to-cart-woocommerce/woo-inquire-us-and-disable-add-to-cart-button.js
Version Parameters
remove-add-to-cart-woocommerce/woo-inquire-us-and-disable-add-to-cart-button.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpiudacb_inqure_us_link_field
Data Attributes
wpiudacb_category_disable_add_to_cartwpiudacb_inqure_us_link
FAQ

Frequently Asked Questions about Remove Add to Cart WooCommerce