WooCom Add Multiple Products Security & Risk Analysis

wordpress.org/plugins/woocom-add-multiple-products

A plugin for adding bulk product by SKU or product name to cart when you're in cart.

10 active installs v3.0.0 PHP + WP 3.5.1+ Updated Oct 7, 2017
add-to-cartajaxcartshopping-cartwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WooCom Add Multiple Products Safe to Use in 2026?

Generally Safe

Score 85/100

WooCom Add Multiple Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "woocom-add-multiple-products" v3.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, using prepared statements exclusively, and a majority of its output escaping is properly handled. The absence of known vulnerabilities in its history is also a strong indicator of diligent development and maintenance. The plugin also avoids dangerous functions, file operations, external HTTP requests, and does not bundle external libraries, all of which are positive security attributes.

However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers that lack authentication checks, presenting a direct pathway for unauthenticated users to interact with sensitive plugin functionalities. Furthermore, the absence of nonce checks on these AJAX actions exacerbates this risk, as it opens the door to Cross-Site Request Forgery (CSRF) attacks. The limited taint analysis, while showing no critical or high severity flows, is based on zero flows analyzed, which means its effectiveness in detecting potential issues is unproven. Therefore, while the plugin has a clean vulnerability history and good internal coding practices for SQL and output, the unprotected AJAX endpoints represent a substantial security weakness.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • Limited taint analysis coverage
Vulnerabilities
None known

WooCom Add Multiple Products Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WooCom Add Multiple Products Release Timeline

v2.0.0
v1.0.9
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

WooCom Add Multiple Products Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped39 total outputs
Attack Surface
2 unprotected

WooCom Add Multiple Products Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_woocom_amp_add_to_cartsrc/Frontend/Frontend.php:40
noprivwp_ajax_woocom_amp_add_to_cartsrc/Frontend/Frontend.php:41

Shortcodes 1

[wamp_product_input] src/Frontend/Frontend.php:43
WordPress Hooks 12
actionwp_enqueue_scriptssrc/Assets/AssetsEnqueue.php:35
actionwp_enqueue_scriptssrc/Assets/AssetsEnqueue.php:36
actionadmin_enqueue_scriptssrc/Assets/AssetsEnqueue.php:38
actionadmin_enqueue_scriptssrc/Assets/AssetsEnqueue.php:39
actionwoocommerce_after_cartsrc/Frontend/Frontend.php:37
actionwoocommerce_cart_is_emptysrc/Frontend/Frontend.php:38
actionadmin_menusrc/Settings/Settings.php:35
actionadmin_initsrc/Settings/Settings.php:36
actionadmin_initsrc/Settings/Settings.php:57
actionwidgets_initsrc/Widget/Widget.php:46
actionadmin_noticeswoocom-add-multiple-products.php:52
actionplugins_loadedwoocom-add-multiple-products.php:99
Maintenance & Trust

WooCom Add Multiple Products Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedOct 7, 2017
PHP min version
Downloads9K

Community Trust

Rating68/100
Number of ratings5
Active installs10
Developer Profile

WooCom Add Multiple Products Developer Profile

Rnaby

4 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WooCom Add Multiple Products

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocom-add-multiple-products/assets/css/public.css/wp-content/plugins/woocom-add-multiple-products/assets/js/public.js/wp-content/plugins/woocom-add-multiple-products/assets/css/admin.css/wp-content/plugins/woocom-add-multiple-products/assets/js/admin.js
Version Parameters
/wp-content/plugins/woocom-add-multiple-products/assets/css/public.css?ver=1.0.0/wp-content/plugins/woocom-add-multiple-products/assets/js/public.js?ver=1.0.0/wp-content/plugins/woocom-add-multiple-products/assets/css/admin.css?ver=1.0.0/wp-content/plugins/woocom-add-multiple-products/assets/js/admin.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
woocom-add-multiple-products-input-area
Data Attributes
data-action="woocom_amp_add_to_cart"
JS Globals
WPAjaxObj
Shortcode Output
[wamp_product_input]
FAQ

Frequently Asked Questions about WooCom Add Multiple Products