WinCarts Security & Risk Analysis

wordpress.org/plugins/wincarts

AI-powered abandoned cart recovery via SMS for WooCommerce stores. Recover lost sales on autopilot.

0 active installs v1.1.1 PHP 7.4+ WP 5.8+ Updated Jan 3, 2026
abandoned-cartcart-recoverymarketing-automationsms-marketingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WinCarts Safe to Use in 2026?

Generally Safe

Score 100/100

WinCarts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The Wincarts plugin v1.1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output, indicating a strong defense against common SQL injection and cross-site scripting (XSS) vulnerabilities originating from these areas. The absence of known vulnerabilities (CVEs) is also a significant strength, suggesting a generally stable and secure codebase historically. However, a notable concern lies in the significant attack surface exposed through AJAX handlers. With 7 AJAX handlers, 5 of which lack authentication checks, there's a substantial risk of unauthorized actions being performed if these endpoints are accessible to unauthenticated users. The single identified taint flow with unsanitized paths, while not classified as critical or high, warrants further investigation to understand its potential impact and ensure it's adequately mitigated. The limited use of capability checks and nonce checks on these unprotected AJAX endpoints exacerbates this risk.

Key Concerns

  • Unprotected AJAX handlers
  • Taint flow with unsanitized paths
  • Low number of capability checks
Vulnerabilities
None known

WinCarts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WinCarts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
39 escaped
Nonce Checks
6
Capability Checks
2
File Operations
0
External Requests
8
Bundled Libraries
0

Output Escaping

100% escaped39 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<wincarts> (wincarts.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

WinCarts Attack Surface

Entry Points7
Unprotected5

AJAX Handlers 7

authwp_ajax_wincarts_save_consentwincarts.php:540
authwp_ajax_wincarts_save_timezonewincarts.php:628
noprivwp_ajax_wincarts_save_timezonewincarts.php:660
authwp_ajax_wincarts_connectwincarts.php:1017
authwp_ajax_wincarts_disconnectwincarts.php:1105
authwp_ajax_wincarts_exit_intent_submitwincarts.php:1496
noprivwp_ajax_wincarts_exit_intent_submitwincarts.php:1497
WordPress Hooks 10
actiontemplate_redirectwincarts.php:125
actionwoocommerce_cart_updatedwincarts.php:205
actionwoocommerce_review_order_before_submitwincarts.php:305
actionwoocommerce_initwincarts.php:368
actionwp_enqueue_scriptswincarts.php:388
actionwoocommerce_set_additional_field_valuewincarts.php:453
actionwoocommerce_checkout_order_processedwincarts.php:684
actionadmin_menuwincarts.php:704
actionadmin_enqueue_scriptswincarts.php:798
actionwp_footerwincarts.php:1184
Maintenance & Trust

WinCarts Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 3, 2026
PHP min version7.4
Downloads191

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WinCarts Developer Profile

suryatejatammana

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WinCarts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wincarts/css/styles.css/wp-content/plugins/wincarts/js/scripts.js/wp-content/plugins/wincarts/js/abandoned-cart-tracker.js
Script Paths
/wp-content/plugins/wincarts/js/scripts.js/wp-content/plugins/wincarts/js/abandoned-cart-tracker.js
Version Parameters
wincarts/css/styles.css?ver=wincarts/js/scripts.js?ver=wincarts/js/abandoned-cart-tracker.js?ver=

HTML / DOM Fingerprints

CSS Classes
wincarts-consent-checkboxwincarts-popup-container
HTML Comments
<!-- WinCarts - AI-powered abandoned cart recovery via SMS --><!-- WinCarts Main Cart Tracker Script --><!-- WinCarts Consent Form -->
Data Attributes
data-wincarts-tracking-iddata-wincarts-api-keydata-wincarts-consent-text
JS Globals
window.wincarts = {var wincartsConfig = {
REST Endpoints
/wp-json/wincarts/v1/track/wp-json/wincarts/v1/consent
Shortcode Output
[wincarts_consent_form][wincarts_tracking_script]
FAQ

Frequently Asked Questions about WinCarts