
Abandoned Cart Reports For WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-abandoned-carts-by-small-fish-analyticsA simple plugin to see how many carts and which products your customers are abandoning
Is Abandoned Cart Reports For WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Abandoned Cart Reports For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wc-abandoned-carts-by-small-fish-analytics" v2.6.4 exhibits a mixed security posture. On the positive side, it has a very limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed to users, and notably, no documented historical vulnerabilities. This suggests a generally cautious approach to exposing functionality. However, the static analysis reveals some significant concerns. The presence of the `unserialize` function without clear context on its usage raises a red flag, as it is a known vector for unserialize vulnerabilities if user-supplied data is not properly sanitized before being passed to it. Furthermore, the taint analysis indicates two flows with unsanitized paths, with one being of high severity, directly pointing to a potential vulnerability where user-controlled input could be used in a sensitive operation without adequate validation or sanitization. The relatively low percentage of properly escaped output (39%) also suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if unsanitized data finds its way into user-facing output. While the plugin has a clean history, the static analysis findings highlight areas that require immediate attention to maintain a strong security posture.
Key Concerns
- High severity taint flow with unsanitized path
- Unsanitized path identified in taint analysis (2 flows)
- Dangerous function detected: unserialize
- Low percentage of properly escaped output (39%)
- SQL queries with low prepared statement usage (56%)
- No capability checks on entry points
Abandoned Cart Reports For WooCommerce Security Vulnerabilities
Abandoned Cart Reports For WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Abandoned Cart Reports For WooCommerce Attack Surface
WordPress Hooks 8
Maintenance & Trust
Abandoned Cart Reports For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Abandoned Cart Reports For WooCommerce Alternatives
CartBounty – Save and recover abandoned carts for WooCommerce
woo-save-abandoned-carts
Save abandoned carts and send automated abandoned cart recovery messages. Get more leads, reduce cart abandonment, and increase sales.
Recapture for WooCommerce
recapture-for-woocommerce
Recapture is the easiest and most effective way to recover abandoned carts and do SMS and email marketing for your WooCommerce store in WordPress.
Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails
woo-cart-abandonment-recovery
Every store loses sales to cart abandonment. But with Cart Abandonment Recovery for WooCommerce, you can win them back—automatically.
Abandoned Cart Lite for WooCommerce
woocommerce-abandoned-cart
Track abandoned carts and send automated, customizable abandoned cart recovery emails. Reduce cart abandonment, recover lost revenue & increase sales.
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
Abandoned Cart Reports For WooCommerce Developer Profile
2 plugins · 4K total installs
How We Detect Abandoned Cart Reports For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-abandoned-carts-by-small-fish-analytics/assets/sfa-styles.css/wp-content/plugins/wc-abandoned-carts-by-small-fish-analytics/assets/sfa-styles.css?ver=/wp-content/plugins/wc-abandoned-carts-by-small-fish-analytics/admin/js/sfa-abandoned-carts-dashboard.js?ver=/wp-content/plugins/wc-abandoned-carts-by-small-fish-analytics/admin/js/sfa-abandoned-carts-reports.js?ver=/wp-content/plugins/wc-abandoned-carts-by-small-fish-analytics/admin/js/sfa-abandoned-carts-products-table.js?ver=HTML / DOM Fingerprints
sfa_wrapsfa_announcementsfa_date_picker_formsfa_update_reportsfa_update_report_labelsfa_update_report_itemsfa_refresh_report_buttonsfa_counter_container+6 moreid="sfa_announcement"id="sfa_date_picker_form"id="sfa_report_start_date"id="sfa_report_end_date"id="sfa_refresh_report_button"id="sfa_counter_container"+18 moresfa_abandoned_carts_dashboard_datasfa_abandoned_carts_reports_datasfa_abandoned_carts_products_table_data