
One Click Upsell Funnel for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-one-click-upsell-funnelCreate WooCommerce Upsells in One Click, Increase Sales with Related Products, Post Purchase Upsell, Cross Sell, Order Bump and Frequently Bought.
Is One Click Upsell Funnel for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100One Click Upsell Funnel for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "woo-one-click-upsell-funnel" v3.6.1 exhibits a mixed security posture. On the positive side, the code demonstrates good practices regarding SQL queries, exclusively using prepared statements, and a very high percentage of properly escaped output, mitigating common injection and XSS risks. The presence of numerous nonce and capability checks also indicates an effort to secure functionalities. However, a significant concern arises from the substantial attack surface, particularly the 11 unprotected AJAX handlers. While taint analysis didn't reveal critical or high severity flows, the presence of 4 flows with unsanitized paths warrants attention as it could be exploited in conjunction with other vulnerabilities.
The vulnerability history shows a single medium severity CVE related to Cross-site Scripting (XSS), which is positive that it's patched. However, the fact that a medium severity XSS vulnerability was present at some point, combined with the unprotected AJAX handlers, suggests a potential for attackers to leverage these unprotected entry points to execute malicious scripts if input validation is insufficient in those areas. The plugin's strengths lie in its database interaction and output handling, but its weaknesses are concentrated in the handling of user-submitted data through its numerous AJAX endpoints.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Medium severity CVE history
One Click Upsell Funnel for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
One Click Upsell Funnel for WooCommerce <= 3.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via wps_wocuf_pro_yes Shortcode
One Click Upsell Funnel for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
One Click Upsell Funnel for WooCommerce Attack Surface
AJAX Handlers 13
Shortcodes 18
WordPress Hooks 72
Scheduled Events 2
Maintenance & Trust
One Click Upsell Funnel for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
One Click Upsell Funnel for WooCommerce Alternatives
FunnelKit – Funnel Builder for WooCommerce Checkout
funnel-builder
Create high-converting WooCommerce checkout pages, WooCommerce thank you pages & sales funnels with the highest-rated WordPress funnel builder.
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
wpfunnels
WPFunnels is a powerful funnel builder for WooCommerce that helps store owners create high-converting WooCommerce checkout pages, sales funnels, one-c …
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce
cartflows
1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups.
upsell-order-bump-offer-for-woocommerce
Upsell Funnel Builder lets you create WooCommerce Upsells, Order Bumps, One Click upsell, Cross-Sells, Frequently Bought, and Popups.
Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator
stylish-cost-calculator
Cost calculator for WordPress: 🌟 Engage visitors and boost conversions with interactive calculations, lead capture, and payment integrations.
One Click Upsell Funnel for WooCommerce Developer Profile
13 plugins · 43K total installs
How We Detect One Click Upsell Funnel for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-one-click-upsell-funnel/assets/css/admin-style.css/wp-content/plugins/woo-one-click-upsell-funnel/assets/css/style.css/wp-content/plugins/woo-one-click-upsell-funnel/assets/js/admin-script.js/wp-content/plugins/woo-one-click-upsell-funnel/assets/js/script.js/wp-content/plugins/woo-one-click-upsell-funnel/assets/js/script.js/wp-content/plugins/woo-one-click-upsell-funnel/assets/js/admin-script.jswoo-one-click-upsell-funnel/assets/css/style.css?ver=woo-one-click-upsell-funnel/assets/css/admin-style.css?ver=woo-one-click-upsell-funnel/assets/js/script.js?ver=woo-one-click-upsell-funnel/assets/js/admin-script.js?ver=HTML / DOM Fingerprints
wocuf-admin-wrapwps-upsell-settingswocuf-offer-detailswocuf-offer-list-tablewocuf-upsell-preview<!-- Start of WooCommerce One Click Upsell Funnel -->data-wocuf-offer-iddata-wocuf-product-idWPS_WOCUF_OBJ/wp-json/wocuf/v1/get-upsell-data/wp-json/wocuf/v1/save-upsell-settings[wocuf_upsell_offer]