Text Changer for Welcart Security & Risk Analysis

wordpress.org/plugins/text-changer-for-welcart

This plugin allows you to change the text in Welcart cart pages and member pages.

500 active installs v1.2.1 PHP 7.2+ WP 5.0+ Updated Jan 23, 2026
productwelcart
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Text Changer for Welcart Safe to Use in 2026?

Generally Safe

Score 100/100

Text Changer for Welcart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "text-changer-for-welcart" plugin v1.2.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate a responsible development approach with 100% of SQL queries using prepared statements, a high percentage of properly escaped output, and a nonce check in place. The lack of dangerous functions, file operations, and external HTTP requests further bolsters its security. Taint analysis reveals no concerning flows, suggesting that user-supplied data is handled safely.

The plugin's vulnerability history is also exceptionally clean, with no recorded CVEs. This, combined with the positive static analysis, suggests a well-maintained and secure codebase. The plugin demonstrates good practices by minimizing its attack surface and diligently employing security measures like prepared statements and output escaping. While the lack of capability checks on its limited entry points might be a minor oversight, the overall minimal exposure makes this less of a significant concern.

In conclusion, this plugin appears to be very secure. Its strengths lie in its extremely limited attack surface and robust implementation of core security best practices. The absence of any historical vulnerabilities or concerning code signals further solidifies its positive security standing. There are no significant weaknesses identified in the provided data.

Vulnerabilities
None known

Text Changer for Welcart Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Text Changer for Welcart Release Timeline

v1.2.1Current
v1.2.0
v1.1.9
v1.1.8
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Text Changer for Welcart Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
288 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped302 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<tcw_function_settings> (tcw_function_settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Text Changer for Welcart Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 26
filterusces_filter_incart_button_labelfunctions\tcw_functions.php:25
filterusces_filters_addressform_name_labelfunctions\tcw_functions.php:34
filterusces_filter_postal_code_address_search_labelfunctions\tcw_functions.php:44
filterusces_filter_after_zipcodefunctions\tcw_functions.php:54
filterusces_filter_after_address1functions\tcw_functions.php:65
filterusces_filter_after_address2functions\tcw_functions.php:74
filterusces_filter_after_address3functions\tcw_functions.php:83
filterusces_filter_after_telfunctions\tcw_functions.php:93
filterusces_filter_after_faxfunctions\tcw_functions.php:103
filterusces_filter_itemGpExp_titlefunctions\tcw_functions.php:112
filterusces_confirm_discount_labelfunctions\tcw_functions.php:121
filterusces_filter_disnount_labelfunctions\tcw_functions.php:126
filterusces_filter_loginlink_labelfunctions\tcw_functions.php:135
filterusces_filter_logoutlink_labelfunctions\tcw_functions.php:144
filterusces_filter_newmember_buttonfunctions\tcw_functions.php:153
actionafter_setup_themefunctions\tcw_functions.php:611
actionshutdownfunctions\tcw_functions.php:618
filterusces_send_ordermail_para_to_customerfunctions\tcw_functions.php:701
filterusces_send_ordermail_para_to_managerfunctions\tcw_functions.php:782
filterusces_filter_send_regmembermail_messagefunctions\tcw_functions.php:805
filterusces_filter_send_updmembermail_messagefunctions\tcw_functions.php:806
filterusces_filter_send_delmembermail_messagefunctions\tcw_functions.php:807
actionadmin_enqueue_scriptsfunctions\tcw_other.php:11
actionadmin_menufunctions\tcw_other.php:20
actionplugins_loadedtext-changer-for-welcart.php:26
filterplugin_action_linkstext-changer-for-welcart.php:45
Maintenance & Trust

Text Changer for Welcart Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedJan 23, 2026
PHP min version7.2
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Text Changer for Welcart Developer Profile

mainichiweb

3 plugins · 2K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect Text Changer for Welcart

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/text-changer-for-welcart/style_admin.css
Version Parameters
text-changer-for-welcart/style_admin.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Text Changer for Welcart