
sleekStore lite Security & Risk Analysis
wordpress.org/plugins/sleekstoresleekStore - instant way to start sales and launch online store powered by WordPress. Functional, convenient, hyper-flexlible.
Is sleekStore lite Safe to Use in 2026?
Generally Safe
Score 85/100sleekStore lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sleekstore v2.3 plugin exhibits a mixed security posture. On the positive side, it has a relatively small attack surface with all identified entry points (shortcodes) appearing to have some form of authentication or capability checks, and there are no known historical vulnerabilities. This suggests a degree of attention to common security pitfalls.
However, significant concerns arise from the static analysis. The presence of dangerous functions like `create_function` and `unserialize` is a major red flag, as these can be exploited for remote code execution or deserialization vulnerabilities if user-supplied data is not rigorously sanitized. Furthermore, the extremely low percentage of properly escaped output (1%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, where untrusted data displayed to users could be manipulated to execute malicious scripts. While taint analysis shows no critical or high-severity unsanitized flows, the overall lack of output escaping creates a strong potential for such issues.
In conclusion, while the plugin benefits from a clean vulnerability history and protected entry points, the use of dangerous functions and the severe lack of output escaping present substantial security risks that require immediate attention. These code-level weaknesses outweigh the strengths, suggesting a plugin that requires careful review and remediation before deployment in a production environment.
Key Concerns
- Dangerous function: unserialize detected
- Dangerous function: create_function detected
- Output escaping: 1% properly escaped (very low)
- SQL queries: 19% not using prepared statements
- Taint analysis: 3 flows with unsanitized paths
sleekStore lite Security Vulnerabilities
sleekStore lite Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
sleekStore lite Attack Surface
Shortcodes 3
WordPress Hooks 13
Maintenance & Trust
sleekStore lite Maintenance & Trust
Maintenance Signals
Community Trust
sleekStore lite Alternatives
Shopping Cart & eCommerce Store
wp-easycart
A FREE WordPress eCommerce & WordPress Shopping Cart plugin that can sell products, subscriptions, downloads, services, donations, and much more o …
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Shopify Importer
shopify
Import products from a Shopify.com online store into your blog.
Shift4Shop Online Store
3dcart-wp-online-store
Shift4Shop Online Store provides a streamlined way to sell any number of products from your Shift4Shop store directly on your WordPress blog.
CommerceBird
commercebird
Elevate WooCommerce to the next level by turning it into a complete ERP system.
sleekStore lite Developer Profile
1 plugin · 20 total installs
How We Detect sleekStore lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sleekstore/w9ss.cssHTML / DOM Fingerprints
w9ss_productsw9ss_productw9ss_imgw9ss_titlew9ss_pricew9ss_buttonw9ss_cartw9ss_cart_item+9 more główna funkcja zmieniająca contentautmatyczne dodanie koszykana końcu lub na początkudata-product-iddata-quantitydata-pricew9ss_ajax_url/wp-json/w9ss/v1/add-to-cart/wp-json/w9ss/v1/update-cart/wp-json/w9ss/v1/checkout[ss_addtocart][ss_addproduct][ss_productlist]