
CartBounty – Save and recover abandoned carts for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-save-abandoned-cartsSave abandoned carts and send automated abandoned cart recovery messages. Get more leads, reduce cart abandonment, and increase sales.
Is CartBounty – Save and recover abandoned carts for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100CartBounty – Save and recover abandoned carts for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "woo-save-abandoned-carts" plugin version 8.10 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for the vast majority of its SQL queries and has no known unpatched vulnerabilities. It also lacks file operations and external HTTP requests, which reduces certain attack vectors. However, significant concerns arise from the attack surface. All 11 AJAX handlers are exposed without any authentication checks, creating a large potential entry point for attackers. Furthermore, the taint analysis reveals 6 high-severity flows with unsanitized paths, indicating potential for malicious data to be processed in unintended ways, even though no critical severity issues were found. The plugin's vulnerability history shows a single medium-severity CSRF vulnerability, which, while patched, suggests a history of security weaknesses that require ongoing vigilance. While the plugin has strengths in database query security and a lack of critical unpatched issues, the unprotected AJAX endpoints and high-severity taint flows represent immediate and serious risks that need to be addressed.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows
- Medium severity CVE history
- Output escaping not fully implemented
CartBounty – Save and recover abandoned carts for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CartBounty – Save and recover abandoned carts for WooCommerce <= 8.2 - Cross-Site Request Forgery
CartBounty – Save and recover abandoned carts for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
CartBounty – Save and recover abandoned carts for WooCommerce Attack Surface
AJAX Handlers 11
WordPress Hooks 40
Maintenance & Trust
CartBounty – Save and recover abandoned carts for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
CartBounty – Save and recover abandoned carts for WooCommerce Alternatives
Abandoned Cart Reports For WooCommerce
wc-abandoned-carts-by-small-fish-analytics
A simple plugin to see how many carts and which products your customers are abandoning
Recapture for WooCommerce
recapture-for-woocommerce
Recapture is the easiest and most effective way to recover abandoned carts and do SMS and email marketing for your WooCommerce store in WordPress.
Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails
woo-cart-abandonment-recovery
Every store loses sales to cart abandonment. But with Cart Abandonment Recovery for WooCommerce, you can win them back—automatically.
Abandoned Cart Lite for WooCommerce
woocommerce-abandoned-cart
Track abandoned carts and send automated, customizable abandoned cart recovery emails. Reduce cart abandonment, recover lost revenue & increase sales.
PushEngage – Web Push notification, WA Automation & Multi-Channel Chat Widget ( WA, Messenger, X, Telegram, TikTok & More)
pushengage
Send order updates, recover abandoned carts, and boost retention with push notifications, WhatsApp automation + multichannel Chat widget.
CartBounty – Save and recover abandoned carts for WooCommerce Developer Profile
2 plugins · 10K total installs
How We Detect CartBounty – Save and recover abandoned carts for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-save-abandoned-carts/assets/css/cartbounty-admin.css/wp-content/plugins/woo-save-abandoned-carts/assets/css/cartbounty-public.css/wp-content/plugins/woo-save-abandoned-carts/assets/js/cartbounty-admin.js/wp-content/plugins/woo-save-abandoned-carts/assets/js/cartbounty-public.js/wp-content/plugins/woo-save-abandoned-carts/assets/js/cartbounty-reports.js/wp-content/plugins/woo-save-abandoned-carts/admin/js/cartbounty-admin.js/wp-content/plugins/woo-save-abandoned-carts/public/js/cartbounty-public.js/wp-content/plugins/woo-save-abandoned-carts/admin/js/cartbounty-reports.jswoo-save-abandoned-carts/assets/css/cartbounty-admin.css?ver=woo-save-abandoned-carts/assets/css/cartbounty-public.css?ver=woo-save-abandoned-carts/assets/js/cartbounty-admin.js?ver=woo-save-abandoned-carts/assets/js/cartbounty-public.js?ver=woo-save-abandoned-carts/assets/js/cartbounty-reports.js?ver=HTML / DOM Fingerprints
cartbounty-admin-wrapcartbounty-settings-wrapcartbounty-abandoned-cart-listcartbounty-recovered-cart-listcartbounty-email-template-editor<!-- CartBounty Settings Start --><!-- CartBounty Settings End --><!-- CartBounty Abandoned Cart List Start --><!-- CartBounty Recovered Cart List Start -->+1 moredata-cartbounty-iddata-cartbounty-actiondata-cartbounty-noncecartbounty_admin_paramscartbounty_public_paramscartbounty_reports_params/wp-json/cartbounty/v1/carts/wp-json/cartbounty/v1/settings