WPC Fly Cart for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-fly-cart

WPC Fly Cart is an interactive mini cart for WooCommerce. It allows users to update product quantities or remove products without reloading the page.

10K active installs v6.0.1 PHP + WP 4.0+ Updated Mar 14, 2026
floating-cartfly-cartmini-cartwoocommercewpc
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPC Fly Cart for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

WPC Fly Cart for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 20d ago
Risk Assessment

The "woo-fly-cart" v6.0.1 plugin exhibits a generally strong security posture with no recorded historical vulnerabilities. Static analysis reveals good practices like 100% use of prepared statements for SQL queries and a high percentage (79%) of properly escaped outputs. The absence of known CVEs and the plugin's last vulnerability being "none recorded" further bolster its security reputation. However, a few areas warrant attention. The presence of the "unserialize" function, while not inherently a vulnerability, is a known source of potential issues if used with untrusted data. Additionally, while the attack surface is small and all identified entry points have authentication checks, the inclusion of 3 external HTTP requests introduces a dependency on external services, which could be a vector for supply chain attacks or denial-of-service if those services are compromised or unavailable. The plugin also bundles jQuery, which, if outdated, could present a risk, although this is not explicitly stated in the provided data.

Overall, the plugin appears well-maintained and secure from known exploits. The primary concerns stem from the potential misuse of `unserialize` and the reliance on external HTTP requests. The lack of critical or high severity taint flows and the absence of historical vulnerabilities are significant strengths. Continued vigilance regarding updates and secure implementation of `unserialize` would further enhance its security.

Key Concerns

  • Presence of 'unserialize' function
  • External HTTP requests present
Vulnerabilities
None known

WPC Fly Cart for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPC Fly Cart for WooCommerce Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
0 prepared
Unescaped Output
62
236 escaped
Nonce Checks
11
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
1

Dangerous Functions Found

unserialize$plugins = unserialize( $response['body'] );includes\dashboard\wpc-dashboard.php:101
unserialize$plugins = unserialize( $response['body'] );includes\dashboard\wpc-dashboard.php:179
unserialize$plugins = unserialize( $response['body'] );includes\kit\wpc-kit.php:98

Bundled Libraries

jQuery

Output Escaping

79% escaped298 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
ajax_export (includes\dashboard\wpc-dashboard.php:215)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WPC Fly Cart for WooCommerce Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 5

authwp_ajax_wpc_get_pluginsincludes\dashboard\wpc-dashboard.php:9
authwp_ajax_wpc_get_suggestionincludes\dashboard\wpc-dashboard.php:10
authwp_ajax_wpc_exportincludes\dashboard\wpc-dashboard.php:11
authwp_ajax_wpc_importincludes\dashboard\wpc-dashboard.php:12
authwp_ajax_wpc_get_essential_kitincludes\kit\wpc-kit.php:22

Shortcodes 2

[woofc_link] wpc-fly-cart.php:105
[woofc_cart_link] wpc-fly-cart.php:106
WordPress Hooks 26
actionadmin_enqueue_scriptsincludes\dashboard\wpc-dashboard.php:7
actionadmin_menuincludes\dashboard\wpc-dashboard.php:8
actionbefore_woocommerce_initincludes\hpos.php:7
actionadmin_enqueue_scriptsincludes\kit\wpc-kit.php:20
actionadmin_menuincludes\kit\wpc-kit.php:21
actionadmin_initincludes\log\wpc-log.php:6
actionplugins_loadedwpc-fly-cart.php:58
actionadmin_noticeswpc-fly-cart.php:62
actioninitwpc-fly-cart.php:90
actionwp_footerwpc-fly-cart.php:91
actionwp_enqueue_scriptswpc-fly-cart.php:92
actionadmin_enqueue_scriptswpc-fly-cart.php:93
actionadmin_initwpc-fly-cart.php:94
filterpre_update_optionwpc-fly-cart.php:95
actionadmin_menuwpc-fly-cart.php:96
filterplugin_action_linkswpc-fly-cart.php:97
filterplugin_row_metawpc-fly-cart.php:98
filterwp_nav_menu_itemswpc-fly-cart.php:99
filterwoocommerce_add_to_cart_fragmentswpc-fly-cart.php:100
filterwoocommerce_update_order_review_fragmentswpc-fly-cart.php:101
filterwpcsm_locationswpc-fly-cart.php:102
actionwc_ajax_woofc_update_qtywpc-fly-cart.php:109
actionwc_ajax_woofc_remove_itemwpc-fly-cart.php:110
actionwc_ajax_woofc_undo_removewpc-fly-cart.php:111
actionwc_ajax_woofc_empty_cartwpc-fly-cart.php:112
filterwoofc_disable_nonce_checkwpc-fly-cart.php:115
Maintenance & Trust

WPC Fly Cart for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version
Downloads847K

Community Trust

Rating94/100
Number of ratings61
Active installs10K
Developer Profile

WPC Fly Cart for WooCommerce Developer Profile

WPClever

71 plugins · 441K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
68 days
View full developer profile
Detection Fingerprints

How We Detect WPC Fly Cart for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-fly-cart/assets/hint/hint.min.css/wp-content/plugins/woo-fly-cart/assets/perfect-scrollbar/css/perfect-scrollbar.min.css/wp-content/plugins/woo-fly-cart/assets/perfect-scrollbar/css/custom-theme.css/wp-content/plugins/woo-fly-cart/assets/perfect-scrollbar/js/perfect-scrollbar.jquery.min.js/wp-content/plugins/woo-fly-cart/assets/js/frontend.min.js/wp-content/plugins/woo-fly-cart/assets/css/frontend.min.css
Script Paths
/wp-content/plugins/woo-fly-cart/assets/hint/hint.min.css/wp-content/plugins/woo-fly-cart/assets/perfect-scrollbar/css/perfect-scrollbar.min.css/wp-content/plugins/woo-fly-cart/assets/perfect-scrollbar/css/custom-theme.css/wp-content/plugins/woo-fly-cart/assets/perfect-scrollbar/js/perfect-scrollbar.jquery.min.js/wp-content/plugins/woo-fly-cart/assets/js/frontend.min.js/wp-content/plugins/woo-fly-cart/assets/css/frontend.min.css
Version Parameters
woo-fly-cart/assets/hint/hint.min.css?ver=woo-fly-cart/assets/perfect-scrollbar/css/perfect-scrollbar.min.css?ver=woo-fly-cart/assets/perfect-scrollbar/css/custom-theme.css?ver=woo-fly-cart/assets/perfect-scrollbar/js/perfect-scrollbar.jquery.min.js?ver=woo-fly-cart/assets/js/frontend.min.js?ver=woo-fly-cart/assets/css/frontend.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
woofc-main-cartwoofc-showwoofc-emptywoofc-countwoofc-mini-cart-itemwoofc-mini-cart-titlewoofc-mini-cart-pricewoofc-mini-cart-qty+14 more
HTML Comments
WPC Fly Cart for WooCommercePowered by WPClever
Data Attributes
data-woofc-cart-hash=data-woofc-cart-item-key=
JS Globals
woofc_params
REST Endpoints
/wp-json/woofc/v1/update_qty/wp-json/woofc/v1/remove_item/wp-json/woofc/v1/undo_remove/wp-json/woofc/v1/empty_cart
Shortcode Output
[woofc_link][woofc_cart_link]
FAQ

Frequently Asked Questions about WPC Fly Cart for WooCommerce