
Wishlist with hearts Security & Risk Analysis
wordpress.org/plugins/wishlist-with-heartsClick on heart(icon)/button to add/delete the product in wishlist in a Woocommerce store
Is Wishlist with hearts Safe to Use in 2026?
Generally Safe
Score 100/100Wishlist with hearts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wishlist-with-hearts" v2.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries, ensuring all are prepared statements, and all output is properly escaped. It also has a clean vulnerability history with no recorded CVEs. However, there are significant concerns stemming from the static analysis. The plugin exposes 3 REST API routes that lack permission callbacks, creating a substantial attack surface that could be exploited without proper authorization. Furthermore, the presence of 6 dangerous functions, specifically `unserialize`, is a critical red flag. The taint analysis reveals 10 flows with unsanitized paths, all of which are classified as high severity. This combination of insecure deserialization and high-severity unsanitized flows is particularly worrying and suggests a potential for remote code execution or data manipulation if these paths are triggered by malicious input.
Key Concerns
- REST API routes without permission callbacks
- Dangerous function 'unserialize' used
- High severity taint flows with unsanitized paths
Wishlist with hearts Security Vulnerabilities
Wishlist with hearts Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Wishlist with hearts Attack Surface
REST API Routes 3
Shortcodes 4
WordPress Hooks 17
Maintenance & Trust
Wishlist with hearts Maintenance & Trust
Maintenance Signals
Community Trust
Wishlist with hearts Alternatives
YITH WooCommerce Wishlist
yith-woocommerce-wishlist
YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 10.6.x compatible.
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
QODE Wishlist for WooCommerce
qode-wishlist-for-woocommerce
Qode Wishlist for WooCommerce plugin is the ideal toolkit for letting your visitors save & share comprehensive lists with their products of interest.
MoreConvert Wishlist for WooCommerce
smart-wishlist-for-more-convert
Free: WooCommerce Wishlist, Email automation, Elementor and Premium: Back-in-Stock Notifier, Save For Later, Multi-lists, reports, Email Marketing
Wishlist with hearts Developer Profile
1 plugin · 10 total installs
How We Detect Wishlist with hearts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wishlist-with-hearts/frontend/css/wlwhplugin-frontend-style.css/wp-content/plugins/wishlist-with-hearts/frontend/css/page-wishlist.css/wp-content/plugins/wishlist-with-hearts/assets/font-awesome-4.7.0/css/font-awesome.min.css/wp-content/plugins/wishlist-with-hearts/admin/css/metabox.css/wp-content/plugins/wishlist-with-hearts/admin/js/wlwhplugin-admin.js/wp-content/plugins/wishlist-with-hearts/admin/js/wlwhplugin-colpicker.js/wp-content/plugins/wishlist-with-hearts/frontend/js/wlwhplugin-wishlist.jsadmin/js/wlwhplugin-admin.jsadmin/js/wlwhplugin-colpicker.jsfrontend/js/wlwhplugin-wishlist.jswlwhplugin-adminmy-script-handlewlwhplugin-frontendload-fawlwhplugin-frontendwlwhplugin-frontend-wishlistwlwhplugin-adminHTML / DOM Fingerprints
wlwhplugin-admin-stylewlwhplugin-frontend-stylewlwhplugin-frontend-wishlist-styledata-plugin-urldata-site-urlwlwhData/wlwh/v1/sendemail/wlwh/v1/manageWish[wlwh_shortcode_view]