
Willing2Buy Price Suggestion Security & Risk Analysis
wordpress.org/plugins/willing2buyThe plugin helps Admin to collect price suggestions from customers for products listed on Wordpress (Woocommerce) store.
Is Willing2Buy Price Suggestion Safe to Use in 2026?
Generally Safe
Score 85/100Willing2Buy Price Suggestion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "willing2buy" v1.0 plugin exhibits a concerning security posture due to a significant number of unprotected entry points. While the absence of dangerous functions, external HTTP requests, and file operations is positive, the presence of four AJAX handlers without authentication checks is a major security flaw. The taint analysis revealing two flows with unsanitized paths, classified as high severity, further exacerbates this risk, suggesting potential for unauthorized data manipulation or execution.
Furthermore, the low percentage of properly escaped output (15%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities. Despite having no recorded CVEs, the inherent weaknesses in input validation and output sanitization create a fertile ground for exploitation. The plugin's lack of a strong security history, while seemingly good, could simply mean it hasn't been thoroughly analyzed or targeted yet. The presence of a single nonce check and two capability checks are insufficient to secure the identified unprotected AJAX handlers.
In conclusion, "willing2buy" v1.0 has critical security weaknesses. The unprotected AJAX endpoints combined with unsanitized taint flows and poor output escaping pose a substantial risk to WordPress sites. Immediate attention is required to implement proper authentication, authorization, and sanitization measures for all AJAX handlers, and to address the output escaping issues.
Key Concerns
- 4 AJAX handlers without auth checks
- 2 flows with unsanitized paths (high severity)
- Low output escaping (15%)
- 1 nonce check is insufficient for 4 AJAX handlers
Willing2Buy Price Suggestion Security Vulnerabilities
Willing2Buy Price Suggestion Release Timeline
Willing2Buy Price Suggestion Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Willing2Buy Price Suggestion Attack Surface
AJAX Handlers 4
WordPress Hooks 17
Scheduled Events 1
Maintenance & Trust
Willing2Buy Price Suggestion Maintenance & Trust
Maintenance Signals
Community Trust
Willing2Buy Price Suggestion Alternatives
No alternatives data available yet.
Willing2Buy Price Suggestion Developer Profile
1 plugin · 0 total installs
How We Detect Willing2Buy Price Suggestion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/willing2buy/css/suggest_mycss.css/wp-content/plugins/willing2buy/css/suggest_custom.css/wp-content/plugins/willing2buy/css/font-awesome_4.1.0/css/font-awesome.min.css/wp-content/plugins/willing2buy/js/suggest_custom.js/wp-content/plugins/willing2buy/js/suggest_custom.jsHTML / DOM Fingerprints
suggestPriceLinksuggest-product-idfa-commentsuggestPriceFormsuggest-input-typeerr-txtnameEmailFormnotificationdata-suggest-iddata-valuearia-hidden="true"ajax_url/wp-admin/admin-ajax.php