
UpSellSmart – Product Recommendations Security & Risk Analysis
wordpress.org/plugins/upsellsmart-product-recommendationsLocal, data-driven UpSellSmart – Product Recommendations with multiple engines and comprehensive admin controls.
Is UpSellSmart – Product Recommendations Safe to Use in 2026?
Generally Safe
Score 100/100UpSellSmart – Product Recommendations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'upsellsmart-product-recommendations' plugin version 1.0.3 exhibits a generally good security posture, with a low risk profile. The code analysis reveals strong adherence to secure coding practices, including a high percentage of SQL queries using prepared statements and properly escaped output. The absence of dangerous functions, file operations, and external HTTP requests further mitigates potential attack vectors. The plugin also demonstrates a proactive approach to security with a significant number of nonce and capability checks, indicating an awareness of common WordPress vulnerabilities.
Despite these strengths, a critical concern arises from the presence of one AJAX handler that lacks authentication checks. This creates a direct entry point for unauthenticated users to interact with the plugin's functionality, potentially leading to unintended actions or information disclosure depending on the handler's purpose. The taint analysis shows no unsanitized paths, which is a positive sign, and the plugin has no known past vulnerabilities, suggesting a stable and well-maintained codebase.
In conclusion, while the plugin is well-built with many secure coding practices in place, the single unprotected AJAX handler represents a significant weakness that needs immediate attention. Addressing this specific vulnerability would elevate the plugin's security posture considerably, making it a highly secure option for WordPress users.
Key Concerns
- AJAX handler without auth check
UpSellSmart – Product Recommendations Security Vulnerabilities
UpSellSmart – Product Recommendations Release Timeline
UpSellSmart – Product Recommendations Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
UpSellSmart – Product Recommendations Attack Surface
AJAX Handlers 15
WordPress Hooks 14
Maintenance & Trust
UpSellSmart – Product Recommendations Maintenance & Trust
Maintenance Signals
Community Trust
UpSellSmart – Product Recommendations Alternatives
Frequently Bought Together Product For Woocommerce
frequently-bought-together-product-for-woocommerce
Boost WooCommerce sales with a Frequently Bought Together widget — display product bundles with per-product discounts on any product page.
Appsell for WooCommerce: Upsell, Cross Sell, Frequently Bought Together, Discounts, Coupons & Bundles
appsell
Increase your store's average order value, conversion rate, sales, and revenues significantly with the easiest-to-use Upsell & Cross-sell builder app.
DynamicBlocks – Product Recommendations & Bundles for WooCommerce
dynamic-blocks-builder
Create product recommendations, bundles and upsell blocks for WooCommerce with flexible dynamic options and customizable display rules.
DL Frequently Bought Together
dl-frequently-bought-together
Adds a “Frequently Bought Together” bundle section to WooCommerce product pages, with dynamic pricing and one-click add-to-cart.
Easy Frequently Bought Together for WooCommerce
easy-frequently-bought-together-for-woocommerce
Sell more by bundling related products — Easy Frequently Bought Together for WooCommerce lets customers buy together with smart discounts.
UpSellSmart – Product Recommendations Developer Profile
1 plugin · 0 total installs
How We Detect UpSellSmart – Product Recommendations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/upsellsmart-product-recommendations/assets/dist/js/admin.js/wp-content/plugins/upsellsmart-product-recommendations/assets/dist/css/admin.css/wp-content/plugins/upsellsmart-product-recommendations/assets/dist/js/admin.jsupsellsmart-product-recommendations/assets/dist/js/admin.js?ver=upsellsmart-product-recommendations/assets/dist/css/admin.css?ver=HTML / DOM Fingerprints
upspr_plugin_urlupspr_plugin_versionupspr_ajax_object/wp-json/upspr/v1/recommendations[upsellsmart_recommendations]