LavBoost Lite – All in One Woocommerce Related Products Security & Risk Analysis

wordpress.org/plugins/up-sell-pro

Demo: LavBoost Demo

10 active installs v2.0.2 PHP 7.4+ WP 6.1+ Updated Oct 4, 2024
boost-salesdonationorder-bumpupsellwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LavBoost Lite – All in One Woocommerce Related Products Safe to Use in 2026?

Generally Safe

Score 92/100

LavBoost Lite – All in One Woocommerce Related Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "up-sell-pro" v2.0.2 plugin exhibits a generally strong security posture, with no recorded vulnerabilities or CVEs. Static analysis reveals good practices such as 100% of SQL queries using prepared statements and a high percentage (86%) of output being properly escaped. The plugin also has robust checks for AJAX handlers, with all 14 identified entry points possessing nonce checks and capability checks. There are no REST API routes, shortcodes, or cron events, which are common areas for plugin vulnerabilities.

However, the presence of two instances of the `unserialize` function is a significant concern. While the taint analysis did not reveal any unsanitized paths in the single flow analyzed, the `unserialize` function itself is inherently dangerous if the input is not strictly controlled and validated. An attacker could potentially craft malicious serialized data to trigger unintended code execution, leading to severe security breaches. This remains the primary risk associated with this plugin, despite the absence of historical vulnerabilities.

In conclusion, "up-sell-pro" v2.0.2 has a solid foundation with many good security practices in place. The lack of historical vulnerabilities is a positive indicator. Nevertheless, the use of `unserialize` introduces a potential critical vulnerability that requires careful mitigation. Developers should prioritize sanitizing or avoiding the use of user-supplied data with `unserialize`.

Key Concerns

  • Dangerous function: unserialize used
Vulnerabilities
None known

LavBoost Lite – All in One Woocommerce Related Products Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LavBoost Lite – All in One Woocommerce Related Products Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
48
307 escaped
Nonce Checks
7
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$tab = $this->getSearchQueriesTab( $value, unserialize( get_post_meta( $post->ID, '_search_lmodules\9-2-order-recommendation\LavBoostModuleOrderRecommendation.php:73
unserialize$row = $this->getSearchQueriesEmailRow( $value, unserialize( get_post_meta( $order_id, '_search_lmodules\9-3-order-email\LavBoostModuleOrderEmail.php:121

Output Escaping

86% escaped355 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<LavBoostModuleCheckoutPromo> (modules\9-8-1-checkout-promo\LavBoostModuleCheckoutPromo.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LavBoost Lite – All in One Woocommerce Related Products Attack Surface

Entry Points14
Unprotected0

AJAX Handlers 14

authwp_ajax_popUpResponsemodules\9-1-pop-up-related\LavBoostModulePopUpRelated.php:20
noprivwp_ajax_popUpResponsemodules\9-1-pop-up-related\LavBoostModulePopUpRelated.php:21
authwp_ajax_donate_add_to_cartmodules\9-6-donation\LavBoostModuleDonation.php:22
noprivwp_ajax_donate_add_to_cartmodules\9-6-donation\LavBoostModuleDonation.php:23
authwp_ajax_donate_remove_cart_itemmodules\9-6-donation\LavBoostModuleDonation.php:26
noprivwp_ajax_donate_remove_cart_itemmodules\9-6-donation\LavBoostModuleDonation.php:27
authwp_ajax_promo_add_to_cartmodules\9-8-1-checkout-promo\LavBoostModuleCheckoutPromo.php:24
noprivwp_ajax_promo_add_to_cartmodules\9-8-1-checkout-promo\LavBoostModuleCheckoutPromo.php:25
authwp_ajax_promo_remove_cart_itemmodules\9-8-1-checkout-promo\LavBoostModuleCheckoutPromo.php:28
noprivwp_ajax_promo_remove_cart_itemmodules\9-8-1-checkout-promo\LavBoostModuleCheckoutPromo.php:29
authwp_ajax_service_add_to_cartmodules\9-8-2-services\LavBoostModuleServices.php:25
noprivwp_ajax_service_add_to_cartmodules\9-8-2-services\LavBoostModuleServices.php:26
authwp_ajax_service_remove_cart_itemmodules\9-8-2-services\LavBoostModuleServices.php:29
noprivwp_ajax_service_remove_cart_itemmodules\9-8-2-services\LavBoostModuleServices.php:30
WordPress Hooks 39
actionwp_loadedapp\modules\LavBoostModuleMultipleAddToCart.php:18
actionadmin_enqueue_scriptsincludes\class-lav-boost.php:97
actionadmin_enqueue_scriptsincludes\class-lav-boost.php:98
actionwp_enqueue_scriptsincludes\class-lav-boost.php:113
actionwp_enqueue_scriptsincludes\class-lav-boost.php:114
actiontemplate_redirectmodules\1-general\LavBoostModuleGeneral.php:20
actioninitmodules\1-general\LavBoostModuleGeneral.php:24
actioninitmodules\1-general\LavBoostModuleGeneral.php:26
actionwoocommerce_after_single_productmodules\4-gift-product\LavBoostModuleGiftProduct.php:17
actionwoocommerce_add_to_cartmodules\4-gift-product\LavBoostModuleGiftProduct.php:18
actionwoocommerce_update_cart_action_cart_updatedmodules\4-gift-product\LavBoostModuleGiftProduct.php:19
actionwoocommerce_cart_item_removedmodules\4-gift-product\LavBoostModuleGiftProduct.php:20
actionwp_enqueue_scriptsmodules\5-social-proof\LavBoostModuleSocialProof.php:18
actionwoocommerce_product_get_stock_quantitymodules\6-viewing\LavBoostModuleViewing.php:26
actionwp_loadedmodules\7-bundle\LavBoostModuleBundle.php:23
actionwoocommerce_cart_calculate_feesmodules\7-bundle\LavBoostModuleBundle.php:25
actionwp_enqueue_scriptsmodules\9-1-pop-up-related\LavBoostModulePopUpRelated.php:18
filterbody_classmodules\9-1-pop-up-related\LavBoostModulePopUpRelated.php:19
actionwoocommerce_checkout_update_order_metamodules\9-2-order-recommendation\LavBoostModuleOrderRecommendation.php:20
actionadd_meta_boxesmodules\9-2-order-recommendation\LavBoostModuleOrderRecommendation.php:23
actionwoocommerce_email_customer_detailsmodules\9-3-order-email\LavBoostModuleOrderEmail.php:151
actionwoocommerce_thankyoumodules\9-4-thank-you-page\LavBoostModuleThankYouPage.php:19
actionwoocommerce_email_customer_detailsmodules\9-5-new-order-messages\LavBoostModuleNewOrderMessages.php:115
actionwp_enqueue_scriptsmodules\9-6-donation\LavBoostModuleDonation.php:18
actionwoocommerce_review_order_before_submitmodules\9-6-donation\LavBoostModuleDonation.php:19
actionwp_enqueue_scriptsmodules\9-8-1-checkout-promo\LavBoostModuleCheckoutPromo.php:18
actionwoocommerce_review_order_before_submitmodules\9-8-1-checkout-promo\LavBoostModuleCheckoutPromo.php:20
actionwoocommerce_before_calculate_totalsmodules\9-8-1-checkout-promo\LavBoostModuleCheckoutPromo.php:21
actionwp_enqueue_scriptsmodules\9-8-2-services\LavBoostModuleServices.php:18
actionwoocommerce_after_add_to_cart_quantitymodules\9-8-2-services\LavBoostModuleServices.php:19
actionwoocommerce_before_calculate_totalsmodules\9-8-2-services\LavBoostModuleServices.php:22
actionwoocommerce_remove_cart_itemmodules\9-8-2-services\LavBoostModuleServices.php:33
actionwoocommerce_cart_item_removedmodules\9-8-2-services\LavBoostModuleServices.php:34
actionelementor/frontend/after_register_scriptsmodules\9-8-9-elementor\LavBoostModuleElementor.php:19
actionelementor/elements/categories_registeredmodules\9-8-9-elementor\LavBoostModuleElementor.php:21
actionelementor/widgets/registermodules\9-8-9-elementor\LavBoostModuleElementor.php:23
actionwoocommerce_cart_calculate_feesmodules\9-8-quantity-discount\LavBoostModuleQuantityDiscount.php:23
actionadmin_noticesup-sell-pro.php:60
actionadmin_noticesup-sell-pro.php:136
Maintenance & Trust

LavBoost Lite – All in One Woocommerce Related Products Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 4, 2024
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

LavBoost Lite – All in One Woocommerce Related Products Developer Profile

alicetheme

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LavBoost Lite – All in One Woocommerce Related Products

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/up-sell-pro/admin/css/lav-boost-admin.css/wp-content/plugins/up-sell-pro/admin/js/lav-boost-admin.js
Script Paths
/wp-content/plugins/up-sell-pro/admin/js/lav-boost-admin.js
Version Parameters
lav-boost-admin.css?ver=lav-boost-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
notice-warningis-dismissible
FAQ

Frequently Asked Questions about LavBoost Lite – All in One Woocommerce Related Products