
Unyson WooComerce Shortcodes Security & Risk Analysis
wordpress.org/plugins/uws-unyson-woocommerce-shortcodesA simple and easy way to use WooCommerce Shortcodes in Unyson Visual Builder
Is Unyson WooComerce Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100Unyson WooComerce Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "uws-unyson-woocommerce-shortcodes" v1.0.3 exhibits a concerning security posture due to a significant unprotected entry point. While the static analysis shows no dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, external HTTP requests, and no obvious taint flows, the presence of one AJAX handler without authentication checks is a critical weakness. This unprotected endpoint could potentially be exploited by an unauthenticated attacker to perform unintended actions within the WordPress site.
The plugin demonstrates good practices by using prepared statements for all SQL queries and generally escaping output, although the 68% proper escaping rate suggests there might be some less critical unescaped outputs. The absence of known vulnerabilities in its history is a positive sign, indicating a history of relative security. However, this is overshadowed by the immediate risk posed by the unprotected AJAX handler. The lack of nonce and capability checks on this entry point further exacerbates the risk, as it directly bypasses WordPress's built-in security mechanisms.
In conclusion, while the plugin has some strengths in its handling of database queries and lack of historical vulnerabilities, the single unprotected AJAX handler represents a significant and immediate security risk that needs to be addressed. The absence of proper authorization checks on this entry point makes it a prime target for exploitation. Addressing this unprotected entry point should be the highest priority for improving the plugin's security.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks
- Missing capability checks
- Partially unescaped output
Unyson WooComerce Shortcodes Security Vulnerabilities
Unyson WooComerce Shortcodes Code Analysis
Output Escaping
Unyson WooComerce Shortcodes Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
Unyson WooComerce Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Unyson WooComerce Shortcodes Alternatives
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
WooCommerce Colors
woocommerce-colors
Allows you to change the buttons color and other elements of WooCommerce. Beautifully.
WooCommerce Shortcodes
woocommerce-shortcodes
Adds a button in TinyMCE editor allowing use of WooCommerce shortcodes. Beautifully.
Admire Extra
admire-extra
Admire extra is a elementor as well as Gutenberg template library where you can choose from available designs and use them with any WordPress theme fr …
WP Responsive Tabs
wp-responsive-tabs
An easy way to create tabs for unique posts/pages and feel freedom to use them anywhere in your content or files.
Unyson WooComerce Shortcodes Developer Profile
1 plugin · 1K total installs
How We Detect Unyson WooComerce Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/uws-unyson-woocommerce-shortcodes/extensions/uws/shortcodes/uws_add_to_cart/static/css/uws-add-to-cart.css