
Sales UP for WooCommerce – Boost Your sales with Cross Sells Security & Risk Analysis
wordpress.org/plugins/wc-sales-upThis plugin helps you to display Frequently Bought together products with discount, display offers on cart page and checkout page to increase your sal …
Is Sales UP for WooCommerce – Boost Your sales with Cross Sells Safe to Use in 2026?
Generally Safe
Score 85/100Sales UP for WooCommerce – Boost Your sales with Cross Sells has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wc-sales-up plugin v1.0.3 exhibits a generally strong security posture, with a notable absence of critical vulnerabilities in its history and code analysis. The plugin utilizes prepared statements for all SQL queries, demonstrating a commitment to preventing SQL injection. Furthermore, the vast majority of output is properly escaped, and there are no recorded instances of file operations or external HTTP requests, which are common vectors for exploitation. The presence of 14 nonce checks and one capability check also indicates some level of security awareness in the development process.
However, two significant concerns emerge from the static analysis. Firstly, the presence of 13 AJAX handlers with two that lack authentication checks presents a clear attack surface. These unprotected entry points could potentially be exploited by unauthenticated users to trigger unintended actions or expose sensitive data. Secondly, while the plugin uses a bundled library (Select2), the analysis does not specify its version. If this library is outdated, it could introduce vulnerabilities not directly present in the plugin's own code.
Given the clean vulnerability history and the majority of secure coding practices, the plugin's overall risk is considered moderate. The primary risks stem from the unprotected AJAX endpoints, which require immediate attention. Addressing these specific issues would significantly enhance the plugin's security.
Key Concerns
- Unprotected AJAX handlers
- Potential outdated bundled library
Sales UP for WooCommerce – Boost Your sales with Cross Sells Security Vulnerabilities
Sales UP for WooCommerce – Boost Your sales with Cross Sells Release Timeline
Sales UP for WooCommerce – Boost Your sales with Cross Sells Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Sales UP for WooCommerce – Boost Your sales with Cross Sells Attack Surface
AJAX Handlers 13
WordPress Hooks 33
Maintenance & Trust
Sales UP for WooCommerce – Boost Your sales with Cross Sells Maintenance & Trust
Maintenance Signals
Community Trust
Sales UP for WooCommerce – Boost Your sales with Cross Sells Alternatives
Product Recommendations – Custom Locations
product-recommendations-custom-locations
Feature plugin for the official Product Recommendations extension that allows you to use shortcodes to recommend products in custom WooCommerce store …
QODE Product Bundles for WooCommerce
qode-product-bundles-for-woocommerce
Boost conversion rates, create extra value deals and run cross-selling campaigns by combining two or more products in practical product bundles.
C4D Woo Boost Sales – Set up Up-Sells & Cross-Sells
c4d-woo-boost-sales
Help WooCommerce stores convert traffic into sales, upsell & cross-sell. Boost Sales Plugin for WooCommerce.
CrossSell Mailer – Post-Purchase Coupon Rules (Lite)
crosssell-mailer-post-purchase-coupon-rules-lite
Automatically send personalized coupon emails after purchase to boost repeat sales and cross-selling performance.
NextBestOffer-OLS
nextbestoffer-ols
Revolutionize your customers' shopping journey with recommendations tailored to their individual preferences. Increase your sales with minimal ef …
Sales UP for WooCommerce – Boost Your sales with Cross Sells Developer Profile
1 plugin · 10 total installs
How We Detect Sales UP for WooCommerce – Boost Your sales with Cross Sells
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-sales-up/css/wc-sales-up-admin.css/wp-content/plugins/wc-sales-up/js/wc-sales-up-admin.js/wp-content/plugins/wc-sales-up/js/wc-sales-up-admin.jswc-sales-up/css/wc-sales-up-admin.css?ver=wc-sales-up/js/wc-sales-up-admin.js?ver=HTML / DOM Fingerprints
wsp-save-offer-prioritydata-offeriddata-securitywsp_wc_product_adminwsp_wc_product_admin_params