
B2B Request a Quote Security & Risk Analysis
wordpress.org/plugins/woo-add-to-quoteAdd B2B quote requests to WooCommerce. Let your customers request, manage, and negotiate quotes comfortably to boost B2B sales on your WordPress site.
Is B2B Request a Quote Safe to Use in 2026?
Generally Safe
Score 100/100B2B Request a Quote has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-add-to-quote" plugin version 1.5.6 presents a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, critical taint flows, dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly positive. Furthermore, the presence of nonce checks on 14 entry points and the fact that all AJAX handlers and REST API routes are protected by authentication checks are excellent security practices. The high percentage of properly escaped output also mitigates risks related to cross-site scripting (XSS).
However, there are a few areas that warrant attention. The lack of capability checks on any of the entry points is a notable weakness. While authentication is present, the absence of authorization checks means that any authenticated user, regardless of their role or permissions, could potentially interact with these handlers. This could lead to privilege escalation or unauthorized actions if the functionality exposed by these handlers is sensitive. Additionally, the bundled Freemius library, while not explicitly flagged as vulnerable in this report, could become a risk if it is outdated or has known vulnerabilities in other versions.
Overall, the plugin demonstrates good security awareness with robust input validation and protection against common attack vectors. The absence of historical vulnerabilities further reinforces this. The primary concern lies in the missing capability checks, which, if exploited, could allow authenticated users to perform actions they shouldn't. The plugin's strengths lie in its secure handling of data and protection of its attack surface from unauthenticated access.
Key Concerns
- Missing capability checks on entry points
- Bundled library (Freemius v1.0) may be outdated
- Output escaping not fully implemented (78%)
B2B Request a Quote Security Vulnerabilities
B2B Request a Quote Release Timeline
B2B Request a Quote Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
B2B Request a Quote Attack Surface
AJAX Handlers 18
Shortcodes 1
WordPress Hooks 58
Maintenance & Trust
B2B Request a Quote Maintenance & Trust
Maintenance Signals
Community Trust
B2B Request a Quote Alternatives
Request a Quote Form Plugin – Price Quote Request Management Made Easy
request-a-quote
Easily collect quote requests with a customizable form and manage them in one place. Perfect for pricing inquiries, RFQs, and RFIs.
Product Enquiry for WooCommerce
product-enquiry-for-woocommerce
Product Enquiry allows prospective customers to "Make an Enquiry" about a product, or "Request a Quote" right from within the product page.
YITH Request a Quote for WooCommerce
yith-woocommerce-request-a-quote
The YITH Request a Quote for WooCommerce plugin lets your customers ask for an estimate of a list of products they are interested into.
Request a Quote for WooCommerce – Get a Quote Button
get-a-quote-button-for-woocommerce
Request a Quote for WooCommerce and Elementor plugin shows a Contact Form 7 or WPForms popup on button click. Quote for WooCommerce, price on request.
ELEX WooCommerce Request a Quote
elex-request-a-quote
ELEX Request a Quote plugin allows your customers to add products to a quote list, fill out a form, and request a custom price.
B2B Request a Quote Developer Profile
89 plugins · 1.4M total installs
How We Detect B2B Request a Quote
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-add-to-quote/assets/css/admin/admin-style.css/wp-content/plugins/woo-add-to-quote/assets/css/frontend/frontend-style.css/wp-content/plugins/woo-add-to-quote/assets/js/frontend/frontend-script.js/wp-content/plugins/woo-add-to-quote/assets/js/frontend/frontend-script.jswoo-add-to-quote/assets/css/admin/admin-style.css?ver=woo-add-to-quote/assets/css/frontend/frontend-style.css?ver=woo-add-to-quote/assets/js/frontend/frontend-script.js?ver=HTML / DOM Fingerprints
woo-quote-add-to-cartwoo-quote-button-wrapperwoo-quote-request-formwoo-quote-product-idwoo-quote-product-quantitywoo-quote-add-to-quote-buttondata-product_iddata-quantitydata-add-to-quote-noncewoo_add_to_quote_params/wp-json/woo-add-to-quote/v1/add-to-quote/wp-json/woo-add-to-quote/v1/request-quote