Unyson WooComerce Shortcodes Security & Risk Analysis

wordpress.org/plugins/uws-unyson-woocommerce-shortcodes

A simple and easy way to use WooCommerce Shortcodes in Unyson Visual Builder

1K active installs v1.0.3 PHP 5.2.6+ WP 4.4+ Updated Aug 15, 2020
add-to-cart-shortcodeproducts-shortcodeshortcodesunysonwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Unyson WooComerce Shortcodes Safe to Use in 2026?

Generally Safe

Score 85/100

Unyson WooComerce Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "uws-unyson-woocommerce-shortcodes" v1.0.3 exhibits a concerning security posture due to a significant unprotected entry point. While the static analysis shows no dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, external HTTP requests, and no obvious taint flows, the presence of one AJAX handler without authentication checks is a critical weakness. This unprotected endpoint could potentially be exploited by an unauthenticated attacker to perform unintended actions within the WordPress site.

The plugin demonstrates good practices by using prepared statements for all SQL queries and generally escaping output, although the 68% proper escaping rate suggests there might be some less critical unescaped outputs. The absence of known vulnerabilities in its history is a positive sign, indicating a history of relative security. However, this is overshadowed by the immediate risk posed by the unprotected AJAX handler. The lack of nonce and capability checks on this entry point further exacerbates the risk, as it directly bypasses WordPress's built-in security mechanisms.

In conclusion, while the plugin has some strengths in its handling of database queries and lack of historical vulnerabilities, the single unprotected AJAX handler represents a significant and immediate security risk that needs to be addressed. The absence of proper authorization checks on this entry point makes it a prime target for exploitation. Addressing this unprotected entry point should be the highest priority for improving the plugin's security.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks
  • Missing capability checks
  • Partially unescaped output
Vulnerabilities
None known

Unyson WooComerce Shortcodes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Unyson WooComerce Shortcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

68% escaped25 total outputs
Attack Surface
1 unprotected

Unyson WooComerce Shortcodes Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_uws_dismissed_noticeincludes\helpers.php:86
WordPress Hooks 2
actionadmin_noticesincludes\helpers.php:76
filterfw_extensions_locationsuws.php:28
Maintenance & Trust

Unyson WooComerce Shortcodes Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 15, 2020
PHP min version5.2.6
Downloads21K

Community Trust

Rating74/100
Number of ratings3
Active installs1K
Developer Profile

Unyson WooComerce Shortcodes Developer Profile

flytemplates

1 plugin · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Unyson WooComerce Shortcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/uws-unyson-woocommerce-shortcodes/extensions/uws/shortcodes/uws_add_to_cart/static/css/uws-add-to-cart.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Unyson WooComerce Shortcodes