Modal Fly Cart & AJAX Add to Cart for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocomm-popup-cart-ajax

Popup Cart Lite for WooCommerce for WooCommerce plugin that displays popup cart for add to cart action.

2K active installs v1.5.7 PHP 7.4+ WP 5.0+ Updated Jul 25, 2025
ajax-add-to-cartfloating-cartmini-cartpopup-cartwoocommerce-add-to-cart
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Modal Fly Cart & AJAX Add to Cart for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Modal Fly Cart & AJAX Add to Cart for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

This plugin exhibits a mixed security posture with several strengths but also notable concerns. On the positive side, the plugin does not appear to have any recorded vulnerabilities or CVEs, suggesting a history of relatively secure development or diligent patching by users. Furthermore, all SQL queries are prepared, and a high percentage of output is properly escaped, indicating good practices in these common vulnerability areas. The use of jQuery as a bundled library is standard and not inherently risky in itself.

However, the static analysis reveals critical areas for improvement. The presence of 10 AJAX handlers, with two lacking authentication checks, represents a significant attack surface that could be exploited by unauthenticated users. This is compounded by a taint flow with an unsanitized path, which could potentially lead to path traversal or similar vulnerabilities if exploited in conjunction with the unprotected AJAX handlers. The limited number of nonce checks (4) relative to the number of AJAX handlers also suggests potential weaknesses in ensuring request integrity.

In conclusion, while the plugin benefits from a clean vulnerability history and good practices in SQL and output escaping, the unprotected AJAX endpoints and the identified unsanitized path flow introduce significant risks. Addressing these specific areas of concern is crucial to improving the overall security of the plugin.

Key Concerns

  • Unprotected AJAX handlers
  • Taint flow with unsanitized path
  • Limited nonce checks for AJAX handlers
Vulnerabilities
None known

Modal Fly Cart & AJAX Add to Cart for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Modal Fly Cart & AJAX Add to Cart for WooCommerce Release Timeline

v1.5.7Current
Code Analysis
Analyzed Mar 16, 2026

Modal Fly Cart & AJAX Add to Cart for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
77 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

jQuery

Output Escaping

87% escaped89 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
so_27270880_add_variation_to_cart (inc\class-frontend.php:137)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Modal Fly Cart & AJAX Add to Cart for WooCommerce Attack Surface

Entry Points10
Unprotected2

AJAX Handlers 10

authwp_ajax_ata_cart_noticesinc\class-admin.php:54
noprivwp_ajax_ata_cart_noticesinc\class-admin.php:55
authwp_ajax_wcspc_get_cartinc\class-frontend.php:48
noprivwp_ajax_wcspc_get_cartinc\class-frontend.php:49
authwp_ajax_wcspc_remove_iteminc\class-frontend.php:52
noprivwp_ajax_wcspc_remove_iteminc\class-frontend.php:53
authwp_ajax_wcspc_update_qtyinc\class-frontend.php:57
noprivwp_ajax_wcspc_update_qtyinc\class-frontend.php:58
authwp_ajax_wcspc_add_variation_to_cartinc\class-frontend.php:63
noprivwp_ajax_wcspc_add_variation_to_cartinc\class-frontend.php:64
WordPress Hooks 15
actionadmin_menuinc\class-admin.php:46
actionadmin_enqueue_scriptsinc\class-admin.php:47
actionadmin_initinc\class-admin.php:49
actionwp_dashboard_setupinc\class-admin.php:51
actionwp_footerinc\class-frontend.php:43
actionwp_enqueue_scriptsinc\class-frontend.php:45
actionwp_headinc\class-frontend.php:67
actioninitwoocommerce-modal-fly-cart.php:70
actioninitwoocommerce-modal-fly-cart.php:75
actioninitwoocommerce-modal-fly-cart.php:77
actionadmin_noticeswoocommerce-modal-fly-cart.php:124
actionplugins_loadedwoocommerce-modal-fly-cart.php:130
actionadmin_noticeswoocommerce-modal-fly-cart.php:137
filterplugin_action_linkswoocommerce-modal-fly-cart.php:138
actionbefore_woocommerce_initwoocommerce-modal-fly-cart.php:169
Maintenance & Trust

Modal Fly Cart & AJAX Add to Cart for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 25, 2025
PHP min version7.4
Downloads210K

Community Trust

Rating70/100
Number of ratings11
Active installs2K
Developer Profile

Modal Fly Cart & AJAX Add to Cart for WooCommerce Developer Profile

aThemeArt

46 plugins · 21K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Modal Fly Cart & AJAX Add to Cart for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocomm-popup-cart-ajax/assets/css/fonts.css/wp-content/plugins/woocomm-popup-cart-ajax/assets/js/backend.js/wp-content/plugins/woocomm-popup-cart-ajax/assets/js/frontend.js
Script Paths
/wp-content/plugins/woocomm-popup-cart-ajax/assets/js/backend.js/wp-content/plugins/woocomm-popup-cart-ajax/assets/js/frontend.js

HTML / DOM Fingerprints

CSS Classes
ata-cart-noticeata-rss-widgets
HTML Comments
<!-- To support this WooCommerce Popup Cart + Ajax and get all features, upgrade to WooCommerce Popup Cart + Ajax Pro -->
Data Attributes
data-cart-iddata-product-iddata-quantitydata-product-variation-id
JS Globals
wcspcata_hide_notice_params
FAQ

Frequently Asked Questions about Modal Fly Cart & AJAX Add to Cart for WooCommerce