
Wishlist for WooCommerce Security & Risk Analysis
wordpress.org/plugins/th-wishlistA modern wishlist plugin for WooCommerce. Allows users to add products to a wishlist, view, and manage them.
Is Wishlist for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Wishlist for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "th-wishlist" plugin v1.1.5 demonstrates a generally good security posture with several strengths. Notably, all identified entry points (AJAX handlers, REST API routes, and shortcodes) appear to have proper authorization checks, and all output is properly escaped, mitigating common web vulnerabilities like Cross-Site Scripting (XSS). The high percentage of SQL queries using prepared statements is also a positive indicator of secure database interaction, and the absence of file operations and external HTTP requests reduces potential attack vectors. However, the static analysis did reveal two flows with unsanitized paths in the taint analysis, categorized as high severity. While the plugin has no currently unpatched vulnerabilities, its history includes one medium severity CVE related to Authorization Bypass Through User-Controlled Key. This suggests that while the developers are responsive to security issues, there have been past vulnerabilities that warrant ongoing vigilance.
Key Concerns
- High severity unsanitized taint flow
- High severity unsanitized taint flow
- History of medium severity CVE
Wishlist for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Wishlist for WooCommerce <= 1.1.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation
Wishlist for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wishlist for WooCommerce Attack Surface
AJAX Handlers 10
Shortcodes 4
WordPress Hooks 26
Maintenance & Trust
Wishlist for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Wishlist for WooCommerce Alternatives
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later
flexible-wishlist
Lightweight and simple WooCommerce wishlist. Increases sales. Fits any theme. Customizes texts and icons. Add to ecommerce wishlist with just 1 click.
Premmerce Wishlist for WooCommerce
premmerce-woocommerce-wishlist
This plugin provides the possibility for your customers to create wishlists with the further possibility to share them with friends.
Better Wishlist
better-wishlist
Better Wishlist lets you display Wishlist anywhere on your WooCommerce shop so that your customers can easily bookmark their favourite products and fi …
Wishlist with hearts
wishlist-with-hearts
Click on heart(icon)/button to add/delete the product in wishlist in a Woocommerce store
Wishlist for WooCommerce Developer Profile
48 plugins · 66K total installs
How We Detect Wishlist for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/th-wishlist/assets/css/th-wishlist-frontend.css/wp-content/plugins/th-wishlist/assets/js/th-wishlist-frontend.js/wp-content/plugins/th-wishlist/assets/css/th-wishlist-backend.css/wp-content/plugins/th-wishlist/assets/js/th-wishlist-backend.js/wp-content/plugins/th-wishlist/assets/css/pickr.min.css/wp-content/plugins/th-wishlist/assets/js/th-wishlist-frontend.js/wp-content/plugins/th-wishlist/assets/js/th-wishlist-backend.jsth-wishlist/assets/css/th-wishlist-frontend.css?ver=th-wishlist/assets/js/th-wishlist-frontend.js?ver=th-wishlist/assets/css/th-wishlist-backend.css?ver=th-wishlist/assets/js/th-wishlist-backend.js?ver=pickr-style?ver=HTML / DOM Fingerprints
thwl-add-to-wishlistdata-thwl-wishlist-iddata-product-idthwl_frontend_params