WP Quick Shop Security & Risk Analysis

wordpress.org/plugins/wp-quick-shop

WP Quick Shop is a great plugin to order multiple products together without searching and spending time on pagination.

10 active installs v1.3.3 PHP 7.0+ WP 3.0+ Updated Unknown
cartquickshopshoppingwoocommercewp-e-commerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 11, 2024
Safety Verdict

Is WP Quick Shop Safe to Use in 2026?

Generally Safe

Score 99/100

WP Quick Shop has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 11, 2024
Risk Assessment

The wp-quick-shop v1.3.3 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, performing nonce checks on all identified entry points, and having no critical or high-severity vulnerabilities in its history that remain unpatched. This suggests a level of diligence in handling sensitive database operations and input validation.

However, there are significant concerns. The static analysis reveals one AJAX handler without proper authentication checks, which represents a direct entry point for potential unauthorized actions or information disclosure. Furthermore, a concerning 11% of outputs are not properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities, especially given its past CVE history which includes a medium-severity XSS vulnerability. The taint analysis, while not showing critical or high severity issues, did identify one flow with unsanitized paths, which could lead to path traversal or file manipulation under certain circumstances.

In conclusion, while the plugin has strengths in its database interaction and input validation for certain areas, the unprotected AJAX handler and the high percentage of unescaped output present immediate security risks. The past XSS vulnerability, coupled with unescaped outputs, suggests a recurring pattern of input sanitization weaknesses that require immediate attention. Users should be aware of these potential vulnerabilities, especially the XSS risk.

Key Concerns

  • Unprotected AJAX handler found
  • 11% of outputs are not properly escaped
  • Taint flow with unsanitized paths
  • Medium severity XSS vulnerability in history
Vulnerabilities
1

WP Quick Shop Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-54344medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Quick Shop <= 1.3.1 - Reflected Cross-Site Scripting

Dec 11, 2024 Patched in 1.3.2 (9d)
Code Analysis
Analyzed Mar 16, 2026

WP Quick Shop Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
172
22 escaped
Nonce Checks
5
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

11% escaped194 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

6 flows1 with unsanitized paths
wpqs_unsanitized_settings_data (inc\functions-inner.php:134)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

WP Quick Shop Attack Surface

Entry Points5
Unprotected1

AJAX Handlers 4

authwp_ajax_wpqs_update_optionsinc\functions-inner.php:170
noprivwp_ajax_wpqs_add_variation_to_cartinc\functions.php:453
authwp_ajax_wpqs_add_variation_to_cartinc\functions.php:454
authwp_ajax_wpqs_tax_typesindex.php:51

Shortcodes 1

[WP-QUICKSHOP] inc\functions.php:51
WordPress Hooks 10
actioninitinc\functions-inner.php:132
actionwp_loadedinc\functions.php:50
actionwp_loadedinc\functions.php:153
actioninitinc\functions.php:445
actionadmin_enqueue_scriptsindex.php:42
actionwp_enqueue_scriptsindex.php:43
actionadmin_enqueue_scriptsindex.php:45
actionwp_enqueue_scriptsindex.php:46
actionadmin_menuindex.php:50
actionadmin_enqueue_scriptsindex.php:55
Maintenance & Trust

WP Quick Shop Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.0
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

WP Quick Shop Developer Profile

Fahad Mahmood

40 plugins · 33K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
237 days
View full developer profile
Detection Fingerprints

How We Detect WP Quick Shop

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-quick-shop/css/common.css/wp-content/plugins/wp-quick-shop/css/front-style.css/wp-content/plugins/wp-quick-shop/css/mobile.css/wp-content/plugins/wp-quick-shop/css/bootstrap.min.css/wp-content/plugins/wp-quick-shop/js/popper.min.js/wp-content/plugins/wp-quick-shop/js/bootstrap.min.js
Script Paths
/wp-content/plugins/wp-quick-shop/js/popper.min.js/wp-content/plugins/wp-quick-shop/js/bootstrap.min.js
Version Parameters
wp-quick-shop/css/common.css?ver=wp-quick-shop/js/popper.min.js?ver=wp-quick-shop/js/bootstrap.min.js?ver=wp-quick-shop/css/bootstrap.min.css?ver=wp-quick-shop/css/front-style.css?ver=wp-quick-shop/css/mobile.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpqs-bootstrap-stylewpqs-common-stylewpqs-front-stylewpqs-mobile-style
JS Globals
wpqs_style_obj
Shortcode Output
[WP-QUICKSHOP]
FAQ

Frequently Asked Questions about WP Quick Shop