WPC Smart Quick View for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-smart-quick-view

WPC Smart Quick View allows users to get a quick look at products without opening the product page.

100K active installs v4.3.0 PHP + WP 4.0+ Updated Mar 14, 2026
quick-viewquickviewwoocommercewpc
96
A · Safe
CVEs total3
Unpatched0
Last CVEOct 17, 2025
Safety Verdict

Is WPC Smart Quick View for WooCommerce Safe to Use in 2026?

Generally Safe

Score 96/100

WPC Smart Quick View for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Oct 17, 2025Updated 20d ago
Risk Assessment

The "woo-smart-quick-view" v4.3.0 plugin demonstrates a generally good security posture, with several positive indicators. The static analysis shows a robust approach to SQL queries, with all queries using prepared statements, and a high percentage of output escaping. Furthermore, the absence of unsanitized paths in taint analysis and a significant number of nonce and capability checks are strong security practices. The plugin also has no critical or high-severity known vulnerabilities currently unpatched.

However, there are some areas for concern. The presence of the `unserialize` function is a significant risk, as it can be vulnerable to deserialization attacks if user-controlled input is passed to it without proper sanitization. While the taint analysis did not reveal any unsanitized paths in this specific scan, the potential for exploitation exists. The plugin's vulnerability history reveals three past medium-severity vulnerabilities, specifically related to Authorization Bypass and Cross-Site Scripting. While none are currently unpatched, this pattern suggests a history of introducing exploitable flaws.

In conclusion, the plugin has strengths in its handling of SQL and output escaping, along with diligent use of security checks. Nevertheless, the presence of `unserialize` and the historical pattern of medium-severity vulnerabilities, particularly in sensitive areas like authorization and XSS, warrant careful consideration and ongoing monitoring. Developers should prioritize mitigating the risks associated with `unserialize` and continue to focus on comprehensive security testing.

Key Concerns

  • Dangerous function: unserialize detected
  • 3 medium severity vulnerabilities historically
  • Potential for Cross-Site Scripting history
  • Potential for Authorization Bypass history
Vulnerabilities
3

WPC Smart Quick View for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-11741medium · 5.3Authorization Bypass Through User-Controlled Key

WPC Smart Quick View for WooCommerce <= 4.2.5 - Insecure Direct Object Reference to Unauthenticated Private Product Exposure

Oct 17, 2025 Patched in 4.2.6 (1d)
CVE-2025-8618medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WPC Smart Quick View for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via woosq_btn Shortcode

Aug 19, 2025 Patched in 4.2.2 (1d)
CVE-2023-6494medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WPC Smart Quick View for WooCommerce <= 4.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 12, 2024 Patched in 4.0.3 (109d)
Code Analysis
Analyzed Mar 16, 2026

WPC Smart Quick View for WooCommerce Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
2 prepared
Unescaped Output
18
197 escaped
Nonce Checks
9
Capability Checks
3
File Operations
0
External Requests
3
Bundled Libraries
1

Dangerous Functions Found

unserialize$plugins = unserialize( $response['body'] );includes\dashboard\wpc-dashboard.php:101
unserialize$plugins = unserialize( $response['body'] );includes\dashboard\wpc-dashboard.php:179
unserialize$plugins = unserialize( $response['body'] );includes\kit\wpc-kit.php:98

Bundled Libraries

jQuery

SQL Query Safety

100% prepared2 total queries

Output Escaping

92% escaped215 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
ajax_export (includes\dashboard\wpc-dashboard.php:215)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WPC Smart Quick View for WooCommerce Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 6

authwp_ajax_wpc_get_pluginsincludes\dashboard\wpc-dashboard.php:9
authwp_ajax_wpc_get_suggestionincludes\dashboard\wpc-dashboard.php:10
authwp_ajax_wpc_exportincludes\dashboard\wpc-dashboard.php:11
authwp_ajax_wpc_importincludes\dashboard\wpc-dashboard.php:12
authwp_ajax_wpc_get_essential_kitincludes\kit\wpc-kit.php:22
authwp_ajax_woosq_add_fieldwpc-smart-quick-view.php:85

Shortcodes 2

[woosq] wpc-smart-quick-view.php:166
[woosq_btn] wpc-smart-quick-view.php:167
WordPress Hooks 35
actionadmin_enqueue_scriptsincludes\dashboard\wpc-dashboard.php:7
actionadmin_menuincludes\dashboard\wpc-dashboard.php:8
actionbefore_woocommerce_initincludes\hpos.php:7
actionadmin_enqueue_scriptsincludes\kit\wpc-kit.php:20
actionadmin_menuincludes\kit\wpc-kit.php:21
actionplugins_loadedwpc-smart-quick-view.php:38
actionadmin_noticeswpc-smart-quick-view.php:42
actioninitwpc-smart-quick-view.php:65
actionadmin_initwpc-smart-quick-view.php:68
filterpre_update_optionwpc-smart-quick-view.php:69
actionadmin_menuwpc-smart-quick-view.php:70
actionadmin_enqueue_scriptswpc-smart-quick-view.php:73
actionwp_enqueue_scriptswpc-smart-quick-view.php:76
actionwp_footerwpc-smart-quick-view.php:79
actionwc_ajax_woosq_quickviewwpc-smart-quick-view.php:82
actionsave_postwpc-smart-quick-view.php:88
filterplugin_action_linkswpc-smart-quick-view.php:91
filterplugin_row_metawpc-smart-quick-view.php:92
filterwoocommerce_available_variationwpc-smart-quick-view.php:95
actionwoocommerce_before_mini_cartwpc-smart-quick-view.php:98
actionwoocommerce_after_mini_cartwpc-smart-quick-view.php:101
filterwoocommerce_cart_item_permalinkwpc-smart-quick-view.php:106
filterwoocommerce_add_to_cart_redirectwpc-smart-quick-view.php:108
filterwoocommerce_loop_product_linkwpc-smart-quick-view.php:112
filterwp_dropdown_catswpc-smart-quick-view.php:116
filterwcml_multi_currency_ajax_actionswpc-smart-quick-view.php:119
filterwoosq_thumbnailswpc-smart-quick-view.php:122
filterwpcsm_locationswpc-smart-quick-view.php:126
filterwoosq_disable_nonce_checkwpc-smart-quick-view.php:129
actionwoocommerce_shop_loop_item_titlewpc-smart-quick-view.php:175
actionwoocommerce_shop_loop_item_titlewpc-smart-quick-view.php:178
actionwoocommerce_after_shop_loop_item_titlewpc-smart-quick-view.php:181
actionwoocommerce_after_shop_loop_item_titlewpc-smart-quick-view.php:184
actionwoocommerce_after_shop_loop_itemwpc-smart-quick-view.php:187
actionwoocommerce_after_shop_loop_itemwpc-smart-quick-view.php:190
Maintenance & Trust

WPC Smart Quick View for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version
Downloads2.1M

Community Trust

Rating98/100
Number of ratings30
Active installs100K
Developer Profile

WPC Smart Quick View for WooCommerce Developer Profile

WPClever

71 plugins · 441K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
68 days
View full developer profile
Detection Fingerprints

How We Detect WPC Smart Quick View for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-smart-quick-view/assets/css/frontend.css/wp-content/plugins/woo-smart-quick-view/assets/js/frontend.js/wp-content/plugins/woo-smart-quick-view/assets/css/backend.css/wp-content/plugins/woo-smart-quick-view/assets/js/backend.js
Script Paths
/wp-content/plugins/woo-smart-quick-view/assets/js/frontend.js/wp-content/plugins/woo-smart-quick-view/assets/js/backend.js
Version Parameters
woo-smart-quick-view/assets/css/frontend.css?ver=woo-smart-quick-view/assets/js/frontend.js?ver=woo-smart-quick-view/assets/css/backend.css?ver=woo-smart-quick-view/assets/js/backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
woosq-quickviewwoosq-buttonwoosq-btnwoosq-popup-contentwoosq-popup-titlewoosq-popup-imageswoosq-popup-images-wrapperwoosq-popup-image+22 more
HTML Comments
<!-- WPC Smart Quick View -->
Data Attributes
data-woosq-iddata-woosq-noncedata-woosq-parent-id
JS Globals
woosq_ajax_urlwoosq_params
Shortcode Output
[woosq]
FAQ

Frequently Asked Questions about WPC Smart Quick View for WooCommerce