Add to Cart Text Changer and Customize Button, Add Custom Icon Security & Risk Analysis

wordpress.org/plugins/woo-add-to-cart-text-change

Easy handle: Add to Cart Text Changer and Customize Button, Add Custom Icon. With icon of shop or cart.

2K active installs v2.3.0 PHP 6.4+ WP 4.0.0+ Updated Oct 26, 2025
add-to-cartadd-to-cart-text-changesingle-product-cart-buttonwoocommerce-add-to-cartwoocommerce-plugin
100
A · Safe
CVEs total1
Unpatched0
Last CVENov 28, 2023
Safety Verdict

Is Add to Cart Text Changer and Customize Button, Add Custom Icon Safe to Use in 2026?

Generally Safe

Score 100/100

Add to Cart Text Changer and Customize Button, Add Custom Icon has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 28, 2023Updated 5mo ago
Risk Assessment

The plugin "woo-add-to-cart-text-change" v2.3.0 exhibits a mixed security posture. On one hand, the static analysis shows no identified dangerous functions, no direct SQL queries outside of prepared statements, and a reasonable number of nonce checks present. The absence of external HTTP requests and file operations is also a positive indicator. However, a significant concern is the low percentage of properly escaped output (59%), which suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, particularly for stored or reflected XSS if user-supplied data is not consistently sanitized before being displayed. The presence of 2 known vulnerabilities in its history, though currently patched, indicates a pattern that warrants attention. The fact that one of these was a medium severity vulnerability (CSRF) is notable, as CSRF can be exploited to perform unauthorized actions on behalf of logged-in users.

Key Concerns

  • Low percentage of properly escaped output
  • Past medium severity vulnerability (CSRF)
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
1

Add to Cart Text Changer and Customize Button, Add Custom Icon Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-49153medium · 4.3Cross-Site Request Forgery (CSRF)

Add to Cart Text Changer and Customize Button, Add Custom Icon <= 2.0 - Cross-Site Request Forgery via wactc_text_form

Nov 28, 2023 Patched in 2.1 (104d)
Code Analysis
Analyzed Mar 16, 2026

Add to Cart Text Changer and Customize Button, Add Custom Icon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
56
81 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

59% escaped137 total outputs
Attack Surface

Add to Cart Text Changer and Customize Button, Add Custom Icon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuadmin\menu.php:12
actionadmin_menuadmin\page-loader.php:24
actionadmin_enqueue_scriptsadmin\page-loader.php:27
actionwactc_after_form_renderadmin\placeholder-premium.php:15
filterwoocommerce_product_add_to_cart_textincludes\add_to_cart_front.php:31
filterwoocommerce_product_single_add_to_cart_textincludes\add_to_cart_front.php:58
actionwp_enqueue_scriptsincludes\add_to_cart_front.php:70
actionwp_headincludes\add_to_cart_front.php:126
actionplugins_loadedindex.php:99
actionadmin_noticesindex.php:103
actionbefore_woocommerce_initindex.php:107
actioninitindex.php:170
Maintenance & Trust

Add to Cart Text Changer and Customize Button, Add Custom Icon Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedOct 26, 2025
PHP min version6.4
Downloads35K

Community Trust

Rating90/100
Number of ratings8
Active installs2K
Developer Profile

Add to Cart Text Changer and Customize Button, Add Custom Icon Developer Profile

Saiful Islam

12 plugins · 20K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
116 days
View full developer profile
Detection Fingerprints

How We Detect Add to Cart Text Changer and Customize Button, Add Custom Icon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-add-to-cart-text-change/assets/css/main.css/wp-content/plugins/woo-add-to-cart-text-change/assets/js/main.js/wp-content/plugins/woo-add-to-cart-text-change/admin/assets/css/menu.css/wp-content/plugins/woo-add-to-cart-text-change/admin/assets/js/menu.js/wp-content/plugins/woo-add-to-cart-text-change/admin/assets/css/wactc-admin.css/wp-content/plugins/woo-add-to-cart-text-change/admin/assets/js/wactc-admin.js
Script Paths
/wp-content/plugins/woo-add-to-cart-text-change/assets/js/main.js/wp-content/plugins/woo-add-to-cart-text-change/admin/assets/js/menu.js/wp-content/plugins/woo-add-to-cart-text-change/admin/assets/js/wactc-admin.js
Version Parameters
woo-add-to-cart-text-change/assets/css/main.css?ver=woo-add-to-cart-text-change/assets/js/main.js?ver=woo-add-to-cart-text-change/admin/assets/css/menu.css?ver=woo-add-to-cart-text-change/admin/assets/js/menu.js?ver=woo-add-to-cart-text-change/admin/assets/css/wactc-admin.css?ver=woo-add-to-cart-text-change/admin/assets/js/wactc-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wactc-add-to-cart-button
HTML Comments
<!--Add to Cart Button text Customizing form.--><!-- New updated and added --><!-- Freemius integration --><!-- DO NOT REMOVE THIS IF, IT IS ESSENTIAL FOR THE * `function_exists` CALL ABOVE TO PROPERLY WORK. -->+5 more
Data Attributes
data-wactc-id
JS Globals
WACTC_VERSIONWACTC_NAMEWACTC_PLUGIN_BASE_FOLDERWACTC_PLUGIN_BASE_FILEWACTC_BASE_URLwactc_dir_base+4 more
FAQ

Frequently Asked Questions about Add to Cart Text Changer and Customize Button, Add Custom Icon