Sales UP for WooCommerce – Boost Your sales with Cross Sells Security & Risk Analysis

wordpress.org/plugins/wc-sales-up

This plugin helps you to display Frequently Bought together products with discount, display offers on cart page and checkout page to increase your sal …

10 active installs v1.0.3 PHP + WP 5.0+ Updated Jul 11, 2022
cross-sellcross-sellingup-sellsupselingwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Sales UP for WooCommerce – Boost Your sales with Cross Sells Safe to Use in 2026?

Generally Safe

Score 85/100

Sales UP for WooCommerce – Boost Your sales with Cross Sells has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The wc-sales-up plugin v1.0.3 exhibits a generally strong security posture, with a notable absence of critical vulnerabilities in its history and code analysis. The plugin utilizes prepared statements for all SQL queries, demonstrating a commitment to preventing SQL injection. Furthermore, the vast majority of output is properly escaped, and there are no recorded instances of file operations or external HTTP requests, which are common vectors for exploitation. The presence of 14 nonce checks and one capability check also indicates some level of security awareness in the development process.

However, two significant concerns emerge from the static analysis. Firstly, the presence of 13 AJAX handlers with two that lack authentication checks presents a clear attack surface. These unprotected entry points could potentially be exploited by unauthenticated users to trigger unintended actions or expose sensitive data. Secondly, while the plugin uses a bundled library (Select2), the analysis does not specify its version. If this library is outdated, it could introduce vulnerabilities not directly present in the plugin's own code.

Given the clean vulnerability history and the majority of secure coding practices, the plugin's overall risk is considered moderate. The primary risks stem from the unprotected AJAX endpoints, which require immediate attention. Addressing these specific issues would significantly enhance the plugin's security.

Key Concerns

  • Unprotected AJAX handlers
  • Potential outdated bundled library
Vulnerabilities
None known

Sales UP for WooCommerce – Boost Your sales with Cross Sells Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sales UP for WooCommerce – Boost Your sales with Cross Sells Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Sales UP for WooCommerce – Boost Your sales with Cross Sells Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
9
229 escaped
Nonce Checks
14
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared10 total queries

Output Escaping

96% escaped238 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
get_all_products (admin\class-wc-sales-up-admin.php:313)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Sales UP for WooCommerce – Boost Your sales with Cross Sells Attack Surface

Entry Points13
Unprotected2

AJAX Handlers 13

authwp_ajax_sort_cho_priorityadmin\class-wc-sales-up-admin.php:53
authwp_ajax_get_all_productsincludes\class-wc-sales-up.php:174
authwp_ajax_offer_dataincludes\class-wc-sales-up.php:175
authwp_ajax_add_offer_to_cartpublic\class-wc-sales-up-checkout.php:30
noprivwp_ajax_add_offer_to_cartpublic\class-wc-sales-up-checkout.php:31
authwp_ajax_change_cho_offer_pricepublic\class-wc-sales-up-checkout.php:37
noprivwp_ajax_change_cho_offer_pricepublic\class-wc-sales-up-checkout.php:38
authwp_ajax_submit_fbtpublic\class-wc-sales-up-product.php:32
noprivwp_ajax_submit_fbtpublic\class-wc-sales-up-product.php:33
authwp_ajax_change_offer_pricepublic\class-wc-sales-up-product.php:34
noprivwp_ajax_change_offer_pricepublic\class-wc-sales-up-product.php:35
authwp_ajax_change_single_product_pricepublic\class-wc-sales-up-product.php:36
noprivwp_ajax_change_single_product_pricepublic\class-wc-sales-up-product.php:37
WordPress Hooks 33
actionpre_get_postsadmin\class-wc-sales-up-admin.php:54
actionsave_post_checkout-offersadmin\class-wc-sales-up-admin.php:55
actionpost_row_actionsadmin\class-wc-sales-up-admin.php:56
actionadmin_action_wsp_duplicate_offeradmin\class-wc-sales-up-admin.php:57
actionplugins_loadedincludes\class-wc-sales-up.php:147
actionadmin_enqueue_scriptsincludes\class-wc-sales-up.php:161
actionadmin_enqueue_scriptsincludes\class-wc-sales-up.php:162
actionadmin_menuincludes\class-wc-sales-up.php:163
filtermanage_checkout-offers_posts_columnsincludes\class-wc-sales-up.php:164
actionmanage_checkout-offers_posts_custom_columnincludes\class-wc-sales-up.php:165
actioninitincludes\class-wc-sales-up.php:167
actioninitincludes\class-wc-sales-up.php:168
actionsave_post_checkout-offersincludes\class-wc-sales-up.php:170
actionedit_form_after_titleincludes\class-wc-sales-up.php:172
filterwoocommerce_product_data_tabsincludes\class-wc-sales-up.php:177
actionwoocommerce_product_data_panelsincludes\class-wc-sales-up.php:178
actionwoocommerce_process_product_metaincludes\class-wc-sales-up.php:179
actionwp_enqueue_scriptsincludes\class-wc-sales-up.php:194
actionwp_enqueue_scriptsincludes\class-wc-sales-up.php:195
actionwoocommerce_cart_calculate_feespublic\class-wc-sales-up-cart.php:31
actionwoocommerce_review_order_before_submitpublic\class-wc-sales-up-checkout.php:32
actionwoocommerce_review_order_after_submitpublic\class-wc-sales-up-checkout.php:33
actionwoocommerce_before_calculate_totalspublic\class-wc-sales-up-checkout.php:34
filterwoocommerce_cart_item_namepublic\class-wc-sales-up-checkout.php:35
actionwoocommerce_cart_collateralspublic\class-wc-sales-up-checkout.php:36
actionwoocommerce_before_single_productpublic\class-wc-sales-up-product.php:28
actiontemplate_redirectpublic\class-wc-sales-up-product.php:29
actionwp_headpublic\class-wc-sales-up-product.php:30
actionwoocommerce_after_single_product_summarypublic\class-wc-sales-up-product.php:31
actionadmin_noticeswc-sales-up.php:103
actionadmin_initwc-sales-up.php:117
actiondeactivated_pluginwc-sales-up.php:133
actioninitwc-sales-up.php:171
Maintenance & Trust

Sales UP for WooCommerce – Boost Your sales with Cross Sells Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 11, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Sales UP for WooCommerce – Boost Your sales with Cross Sells Developer Profile

Ritaben Vachhani

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sales UP for WooCommerce – Boost Your sales with Cross Sells

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-sales-up/css/wc-sales-up-admin.css/wp-content/plugins/wc-sales-up/js/wc-sales-up-admin.js
Script Paths
/wp-content/plugins/wc-sales-up/js/wc-sales-up-admin.js
Version Parameters
wc-sales-up/css/wc-sales-up-admin.css?ver=wc-sales-up/js/wc-sales-up-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wsp-save-offer-priority
Data Attributes
data-offeriddata-security
JS Globals
wsp_wc_product_adminwsp_wc_product_admin_params
FAQ

Frequently Asked Questions about Sales UP for WooCommerce – Boost Your sales with Cross Sells