
WP Smart Wishlist Security & Risk Analysis
wordpress.org/plugins/wp-smart-wishlistThis is Wish List Plugin for WP eCommerce Site.
Is WP Smart Wishlist Safe to Use in 2026?
Generally Safe
Score 85/100WP Smart Wishlist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-smart-wishlist" v2.0 plugin presents a significant security risk due to a lack of proper authentication and output escaping mechanisms. The static analysis reveals a concerningly large attack surface with three AJAX handlers, all of which lack authentication checks. This means any unauthenticated user could potentially trigger these functions, leading to unintended actions. Furthermore, none of the identified output points are properly escaped, opening the door to cross-site scripting (XSS) vulnerabilities. The presence of dangerous functions like `unserialize` and `create_function` also raises red flags, as these can be exploited if user-supplied data is not rigorously validated and sanitized. While the plugin demonstrates good practices by using prepared statements for SQL queries and has no recorded vulnerability history, these strengths are overshadowed by the critical flaws in its attack surface and output handling. The absence of nonce checks further exacerbates the risk associated with the unprotected AJAX endpoints.
Key Concerns
- Unprotected AJAX handlers
- Unescaped output
- Missing nonce checks on AJAX
- Presence of dangerous functions
WP Smart Wishlist Security Vulnerabilities
WP Smart Wishlist Code Analysis
Dangerous Functions Found
Output Escaping
WP Smart Wishlist Attack Surface
AJAX Handlers 3
WordPress Hooks 4
Maintenance & Trust
WP Smart Wishlist Maintenance & Trust
Maintenance Signals
Community Trust
WP Smart Wishlist Alternatives
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
Wishlist for WooCommerce
wt-woocommerce-wishlist
This WooCommerce wishlist plugin adds a wishlist feature to your WooCommerce store. Let the users easily add and manage products from their wishlist p …
Easy Wishlist
easy-wishlist
The Easy Wishlist Plugin provides a wishlist solution for ecommerce websites. Users can wishlist products and view them anytime.
Wishlist and Compare for WooCommerce
wishlist-and-compare
Enhance your WooCommerce store with our Wishlist & Compare Plugin. Let customers save favorite products and compare features for informed decisions.
Advanced Product Wishlist for Woocommerce
advanced-product-wishlist-for-woo
Advanced Product Wishlist add all Wishlist features to your website. Needs WooCommerce to work..
WP Smart Wishlist Developer Profile
5 plugins · 130 total installs
How We Detect WP Smart Wishlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-smart-wishlist/css/custom.cssHTML / DOM Fingerprints
addWishlistwishlist-tableWishlistWidgetproidloadWishlistremoveWishlist/wp-json/<input type="button" value="Add to Wishlist " class="addWishlist"