Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce Security & Risk Analysis

wordpress.org/plugins/th-all-in-one-woo-cart

Enhance your Cart for WooCommerce with a modern side cart and floating cart. Improve shopping experience with a fast, Ajax-powered shopping cart.

7K active installs v2.3.0 PHP + WP 5.5+ Updated Feb 28, 2026
ajax-cartcart-for-woocommercefloating-cartshopping-cartside-cart
100
A · Safe
CVEs total1
Unpatched0
Last CVEMar 24, 2023
Safety Verdict

Is Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 24, 2023Updated 1mo ago
Risk Assessment

The "th-all-in-one-woo-cart" plugin v2.3.0 exhibits a generally good security posture based on the static analysis results. The plugin demonstrates strong adherence to secure coding practices with a high percentage of properly escaped outputs, no identified dangerous functions, no file operations, and no external HTTP requests. Furthermore, the presence of nonce and capability checks on its entry points is encouraging, with all AJAX handlers and REST API routes (though none exist) reportedly secured. SQL queries are exclusively handled using prepared statements, which mitigates the risk of SQL injection vulnerabilities.

However, there is a history of known vulnerabilities, specifically one medium-severity Cross-Site Request Forgery (CSRF) vulnerability, last documented in March 2023. While this vulnerability is reported as currently unpatched, its medium severity and the lack of recent critical or high-severity issues suggest a pattern of addressable, but not catastrophic, security flaws. The absence of any critical or high-severity findings in the static analysis, including no unsanitized taint flows, is a positive indicator. The relatively small attack surface with protected entry points further strengthens its security profile. Overall, the plugin shows diligent development practices but a history of past vulnerabilities warrants continued vigilance and prompt patching of any newly discovered issues.

Key Concerns

  • One known medium severity vulnerability
  • Vulnerability history present
Vulnerabilities
1

Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-18f04566-3a63-41f3-aa9b-766304d56499-th-all-in-one-woo-cartmedium · 4.3Cross-Site Request Forgery (CSRF)

TH Side Cart and Menu Cart for Woocommerce <= 1.1.1 - Cross-Site Request Forgery

Mar 24, 2023 Patched in 1.1.2 (305d)
Code Analysis
Analyzed Mar 16, 2026

Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
468 escaped
Nonce Checks
4
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped478 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
taiowc_form_setting (inc\taiowc-setting.php:133)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_taiowc_form_settinginc\taiowc-setting.php:29
authwp_ajax_themehunk_activeplugininc\themehunk-menu\admin-menu.php:7

Shortcodes 1

[taiowc] inc\taiowc.php:56
WordPress Hooks 27
actioninitinc\taiowc-block.php:75
filterblock_categories_allinc\taiowc-block.php:91
actionenqueue_block_assetsinc\taiowc-block.php:114
actionwc_ajax_get_refreshed_fragmentsinc\taiowc-cart-fragment.php:37
filterwoocommerce_add_to_cart_fragmentsinc\taiowc-cart-fragment.php:38
filterwoocommerce_add_to_cart_fragmentsinc\taiowc-cart-fragment.php:39
actionwp_footerinc\taiowc-markup.php:33
actioninitinc\taiowc-option.php:29
actionadmin_menuinc\taiowc-setting.php:24
actioninitinc\taiowc-setting.php:25
actionadmin_initinc\taiowc-setting.php:26
actionadmin_enqueue_scriptsinc\taiowc-setting.php:27
actioninitinc\taiowc.php:52
filterbody_classinc\taiowc.php:54
actionwp_enqueue_scriptsinc\taiowc.php:58
actiontaiowc_cart_show_iconinc\taiowc.php:60
actionwp_footerinc\taiowc.php:62
actiontaiowc_mini_cartinc\taiowc.php:64
actiontaiowc_mini_cart_emptyinc\taiowc.php:66
actionwc_ajax_taiowc_update_item_quantityinc\taiowc.php:68
actioninitinc\taiowc.php:72
filtertaiowc_settingsinc\taiowc.php:179
actionplugins_loadedinc\taiowc.php:673
actionadmin_menuinc\themehunk-menu\admin-menu.php:8
actionadmin_enqueue_scriptsinc\themehunk-menu\admin-menu.php:9
actionbefore_woocommerce_initth-all-in-one-woo-cart.php:60
filterplugin_row_metath-all-in-one-woo-cart.php:122
Maintenance & Trust

Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 28, 2026
PHP min version
Downloads224K

Community Trust

Rating0/100
Number of ratings0
Active installs7K
Developer Profile

Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce Developer Profile

ThemeHunk

48 plugins · 66K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
189 days
View full developer profile
Detection Fingerprints

How We Detect Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/th-all-in-one-woo-cart/build/taiowc.js/wp-content/plugins/th-all-in-one-woo-cart/build/taiowc.css/wp-content/plugins/th-all-in-one-woo-cart/build/style-taiowc.css
Script Paths
/wp-content/plugins/th-all-in-one-woo-cart/build/taiowc.js
Version Parameters
th-all-in-one-woo-cart/build/taiowc.js?ver=th-all-in-one-woo-cart/build/taiowc.css?ver=th-all-in-one-woo-cart/build/style-taiowc.css?ver=

HTML / DOM Fingerprints

CSS Classes
taiowc-block-preview
Data Attributes
data-block="taiowc/taiowc"
JS Globals
window.ThBlockDatataiowc
FAQ

Frequently Asked Questions about Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce