Custom Add to Cart labels for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-custom-add-to-cart-labels

This plugin lets you change the “add to cart” labels on all single product pages (per product type) and also on archive/shop page (per product type)

5K active installs v1.5.3 PHP + WP 6.2+ Updated Nov 12, 2025
add-to-cartadd-to-cart-labeladd-to-cart-textwoocommercewoocommerce-add-to-cart
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Add to Cart labels for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Custom Add to Cart labels for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The static analysis of the "wc-custom-add-to-cart-labels" plugin version 1.5.3 reveals a generally good security posture with no direct code vulnerabilities identified. The plugin has no reported CVEs, a clean vulnerability history, and the code analysis shows no dangerous functions, no raw SQL queries, no external HTTP requests, and no file operations. This suggests a cautious approach to development and a lack of common attack vectors.

However, a significant concern arises from the "Output escaping" signal, which indicates that 0% of the 9 detected outputs are properly escaped. This is a critical weakness as it leaves the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the user's browser. The absence of nonce checks and capability checks on any potential entry points, though currently zero, also presents a latent risk if future updates introduce such points without proper security measures.

In conclusion, while the plugin's development history and lack of known exploits are positive indicators, the complete lack of output escaping is a serious flaw that significantly increases the risk profile. The absence of any identified attack surface is a strength, but it should not overshadow the critical need to address the unescaped output.

Key Concerns

  • 0% of outputs properly escaped
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Custom Add to Cart labels for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Custom Add to Cart labels for WooCommerce Release Timeline

v1.5.3Current
v1.5.2
v1.5.1
v1.4.1
v1.4.0
v1.3
Code Analysis
Analyzed Mar 16, 2026

Custom Add to Cart labels for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped9 total outputs
Attack Surface

Custom Add to Cart labels for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterwoocommerce_get_sections_productswc-custom-add-to-cart-labels.php:32
filterwoocommerce_settings_tabs_arraywc-custom-add-to-cart-labels.php:35
actionwoocommerce_settings_tabs_smtp_email_logswc-custom-add-to-cart-labels.php:36
actionadmin_enqueue_scriptswc-custom-add-to-cart-labels.php:37
filterwoocommerce_get_settings_productswc-custom-add-to-cart-labels.php:600
filterwoocommerce_product_single_add_to_cart_textwc-custom-add-to-cart-labels.php:650
filterwoocommerce_booking_single_add_to_cart_textwc-custom-add-to-cart-labels.php:651
filterwoocommerce_product_add_to_cart_textwc-custom-add-to-cart-labels.php:691
Maintenance & Trust

Custom Add to Cart labels for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 12, 2025
PHP min version
Downloads105K

Community Trust

Rating78/100
Number of ratings14
Active installs5K
Developer Profile

Custom Add to Cart labels for WooCommerce Developer Profile

Saad Iqbal

89 plugins · 1.4M total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
267 days
View full developer profile
Detection Fingerprints

How We Detect Custom Add to Cart labels for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-custom-add-to-cart-labels/css/catcl-admin-style.css/wp-content/plugins/wc-custom-add-to-cart-labels/js/catcl-admin-script.js
Script Paths
/wp-content/plugins/wc-custom-add-to-cart-labels/js/catcl-admin-script.js
Version Parameters
wc-custom-add-to-cart-labels/css/catcl-admin-style.css?ver=wc-custom-add-to-cart-labels/js/catcl-admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
smtp-providers-listsmtp-provider-rowsmtp-provider-logosmtp-provider-titlesmtp-provider-descsmtp-provider-statussmtp-provider-switchsmtp-toggle+7 more
JS Globals
catcl_admin_params
FAQ

Frequently Asked Questions about Custom Add to Cart labels for WooCommerce