Willing2Buy Price Suggestion Security & Risk Analysis

wordpress.org/plugins/willing2buy

The plugin helps Admin to collect price suggestions from customers for products listed on Wordpress (Woocommerce) store.

0 active installs v1.0 PHP + WP 4.4+ Updated Apr 28, 2017
price-suggestionproduct-price-suggestionsuggest-product-pricesuggest-your-price-for-productwoocommerce-price-suggestion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Willing2Buy Price Suggestion Safe to Use in 2026?

Generally Safe

Score 85/100

Willing2Buy Price Suggestion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "willing2buy" v1.0 plugin exhibits a concerning security posture due to a significant number of unprotected entry points. While the absence of dangerous functions, external HTTP requests, and file operations is positive, the presence of four AJAX handlers without authentication checks is a major security flaw. The taint analysis revealing two flows with unsanitized paths, classified as high severity, further exacerbates this risk, suggesting potential for unauthorized data manipulation or execution.

Furthermore, the low percentage of properly escaped output (15%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities. Despite having no recorded CVEs, the inherent weaknesses in input validation and output sanitization create a fertile ground for exploitation. The plugin's lack of a strong security history, while seemingly good, could simply mean it hasn't been thoroughly analyzed or targeted yet. The presence of a single nonce check and two capability checks are insufficient to secure the identified unprotected AJAX handlers.

In conclusion, "willing2buy" v1.0 has critical security weaknesses. The unprotected AJAX endpoints combined with unsanitized taint flows and poor output escaping pose a substantial risk to WordPress sites. Immediate attention is required to implement proper authentication, authorization, and sanitization measures for all AJAX handlers, and to address the output escaping issues.

Key Concerns

  • 4 AJAX handlers without auth checks
  • 2 flows with unsanitized paths (high severity)
  • Low output escaping (15%)
  • 1 nonce check is insufficient for 4 AJAX handlers
Vulnerabilities
None known

Willing2Buy Price Suggestion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Willing2Buy Price Suggestion Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Willing2Buy Price Suggestion Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
6 prepared
Unescaped Output
11
2 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

55% prepared11 total queries

Output Escaping

15% escaped13 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
suggest_email_format (class-email-format.php:57)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Willing2Buy Price Suggestion Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_submit_priceindex.php:277
noprivwp_ajax_submit_priceindex.php:278
authwp_ajax_update_user_name_emailindex.php:282
authwp_ajax_update_user_name_emailindex.php:283
WordPress Hooks 17
actionadmin_menuclass-email-format.php:38
actionadmin_menuclass-medma-willing-home.php:24
actionwoocommerce_product_options_general_product_dataclass-suggest-price.php:26
actionwoocommerce_process_product_metaclass-suggest-price.php:29
actionadmin_menuindex.php:18
actionwpindex.php:44
filterwp_mail_content_typeindex.php:70
actionmycronjobindex.php:83
filtercron_schedulesindex.php:94
filtercron_schedulesindex.php:106
filtercron_schedulesindex.php:120
actionwoocommerce_single_product_summaryindex.php:156
actionwp_footerindex.php:272
actionwp_headindex.php:273
actionplugins_loadedindex.php:341
actionplugins_loadedindex.php:350
actionplugins_loadedindex.php:360

Scheduled Events 1

mycronjob
Maintenance & Trust

Willing2Buy Price Suggestion Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedApr 28, 2017
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Alternatives

Willing2Buy Price Suggestion Alternatives

No alternatives data available yet.

Developer Profile

Willing2Buy Price Suggestion Developer Profile

medmatech

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Willing2Buy Price Suggestion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/willing2buy/css/suggest_mycss.css/wp-content/plugins/willing2buy/css/suggest_custom.css/wp-content/plugins/willing2buy/css/font-awesome_4.1.0/css/font-awesome.min.css/wp-content/plugins/willing2buy/js/suggest_custom.js
Script Paths
/wp-content/plugins/willing2buy/js/suggest_custom.js

HTML / DOM Fingerprints

CSS Classes
suggestPriceLinksuggest-product-idfa-commentsuggestPriceFormsuggest-input-typeerr-txtnameEmailFormnotification
Data Attributes
data-suggest-iddata-valuearia-hidden="true"
JS Globals
ajax_url
REST Endpoints
/wp-admin/admin-ajax.php
FAQ

Frequently Asked Questions about Willing2Buy Price Suggestion