
WP e-Commerce Cross Sales (Also Bought) Security & Risk Analysis
wordpress.org/plugins/wp-e-commerce-cross-salesThis plugin displays cross sales in WP e-Commerce. It provides the same functionality as in earlier versions of WP e-Commerce plus a little bit more.
Is WP e-Commerce Cross Sales (Also Bought) Safe to Use in 2026?
Generally Safe
Score 85/100WP e-Commerce Cross Sales (Also Bought) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the "wp-e-commerce-cross-sales" v0.3 plugin exhibits a generally strong security posture. The absence of any registered CVEs and the plugin's robust use of prepared statements for SQL queries are significant strengths. Furthermore, the analysis reveals no critical or high-severity taint flows, and a good percentage of output is properly escaped, indicating a commitment to secure coding practices.
However, a few areas warrant attention. The presence of only one nonce check and one capability check across the entire plugin, coupled with zero AJAX handlers, REST API routes, or shortcodes being analyzed, raises questions about the overall coverage and implementation of security controls for potential entry points. While the attack surface appears small or non-existent in the analyzed components, the limited security checks could be a concern if undocumented or future entry points are introduced without adequate protection. The plugin's history of no recorded vulnerabilities is positive, suggesting a stable and secure codebase to date, but it's crucial to maintain this standard by ensuring comprehensive security measures are in place.
In conclusion, the plugin is likely secure in its current form, demonstrating good coding practices. The primary recommendation is to review and potentially enhance the implementation of nonce and capability checks, especially if the plugin's functionality evolves to include more interactive elements. The lack of reported vulnerabilities is a strong positive indicator, but vigilance in security is always paramount.
Key Concerns
- Limited Nonce Checks
- Limited Capability Checks
WP e-Commerce Cross Sales (Also Bought) Security Vulnerabilities
WP e-Commerce Cross Sales (Also Bought) Release Timeline
WP e-Commerce Cross Sales (Also Bought) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP e-Commerce Cross Sales (Also Bought) Attack Surface
WordPress Hooks 9
Maintenance & Trust
WP e-Commerce Cross Sales (Also Bought) Maintenance & Trust
Maintenance Signals
Community Trust
WP e-Commerce Cross Sales (Also Bought) Alternatives
Content Shelf Shopping Cart
content-shelf-shopping-cart
Content Shelf is shopping cart software for selling digital content, tangible products, services, subscriptions and gift cards.
E-Commerce by SalesCart
e-commerce-by-salescart
SalesCart is a fully featured, complete Shopping Cart solution that can be added in under 15 mins to any WP theme. Use SalesCart for FREE today.
WP e-Commerce – Store Toolkit
store-toolkit-for-wp-e-commerce
This is a legacy Plugin, please see WP e-Commerce - Store Toolkit for the latest release.
X-Cart Integration
x-cart-integration
X-Cart Integration plugin allows you integrate X-Cart shopping cart to any Wordpress site in a few minutes.
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
WP e-Commerce Cross Sales (Also Bought) Developer Profile
18 plugins · 21K total installs
How We Detect WP e-Commerce Cross Sales (Also Bought)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-e-commerce-cross-sales/css/style.csswp-e-commerce-cross-sales/css/style.css?ver=HTML / DOM Fingerprints
wpsc_also_boughtwpsc_also_bought_itemwpsc_product_namewpec_cross_sales