
sleekStore lite Security & Risk Analysis
wordpress.org/plugins/sleekstoresleekStore - instant way to start sales and launch online store powered by WordPress. Functional, convenient, hyper-flexlible.
Is sleekStore lite Safe to Use in 2026?
Generally Safe
Score 85/100sleekStore lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sleekstore v2.3 plugin exhibits a mixed security posture. On the positive side, it has a relatively small attack surface with all identified entry points (shortcodes) appearing to have some form of authentication or capability checks, and there are no known historical vulnerabilities. This suggests a degree of attention to common security pitfalls.
However, significant concerns arise from the static analysis. The presence of dangerous functions like `create_function` and `unserialize` is a major red flag, as these can be exploited for remote code execution or deserialization vulnerabilities if user-supplied data is not rigorously sanitized. Furthermore, the extremely low percentage of properly escaped output (1%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, where untrusted data displayed to users could be manipulated to execute malicious scripts. While taint analysis shows no critical or high-severity unsanitized flows, the overall lack of output escaping creates a strong potential for such issues.
In conclusion, while the plugin benefits from a clean vulnerability history and protected entry points, the use of dangerous functions and the severe lack of output escaping present substantial security risks that require immediate attention. These code-level weaknesses outweigh the strengths, suggesting a plugin that requires careful review and remediation before deployment in a production environment.
Key Concerns
- Dangerous function: unserialize detected
- Dangerous function: create_function detected
- Output escaping: 1% properly escaped (very low)
- SQL queries: 19% not using prepared statements
- Taint analysis: 3 flows with unsanitized paths
sleekStore lite Security Vulnerabilities
sleekStore lite Release Timeline
sleekStore lite Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
sleekStore lite Attack Surface
Shortcodes 3
WordPress Hooks 13
Maintenance & Trust
sleekStore lite Maintenance & Trust
Maintenance Signals
Community Trust
sleekStore lite Alternatives
Shopping Cart & eCommerce Store
wp-easycart
A FREE WordPress eCommerce & WordPress Shopping Cart plugin that can sell products, subscriptions, downloads, services, donations, and much more o …
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Shopify Importer
shopify
Import products from a Shopify.com online store into your blog.
Shift4Shop Online Store
3dcart-wp-online-store
Shift4Shop Online Store provides a streamlined way to sell any number of products from your Shift4Shop store directly on your WordPress blog.
HDCommerce
hdcommerce
HDCommerce, the ultimate eCommerce experience. *In beta.
sleekStore lite Developer Profile
1 plugin · 20 total installs
How We Detect sleekStore lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sleekstore/w9ss.cssHTML / DOM Fingerprints
w9ss_productsw9ss_productw9ss_imgw9ss_titlew9ss_pricew9ss_buttonw9ss_cartw9ss_cart_item+9 more główna funkcja zmieniająca contentautmatyczne dodanie koszykana końcu lub na początkudata-product-iddata-quantitydata-pricew9ss_ajax_url/wp-json/w9ss/v1/add-to-cart/wp-json/w9ss/v1/update-cart/wp-json/w9ss/v1/checkout[ss_addtocart][ss_addproduct][ss_productlist]