
WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wpc-smart-linked-productsWPC Smart Linked Products plugin simplifies managing related, upsells, and cross-sells products in bulk with custom rules and mixed combinations.
Is WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The wpc-smart-linked-products plugin version 1.4.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices in its SQL query handling, exclusively using prepared statements, and a high percentage of properly escaped output. The absence of file operations and critical/high severity taint flows is also encouraging. However, there are notable areas of concern. The presence of one AJAX handler without authentication checks creates a significant attack vector, potentially allowing unauthorized actions. Additionally, the use of the `unserialize` function, while not directly flagged with high severity taint issues in this analysis, is inherently risky and can lead to vulnerabilities if not handled with extreme care and strict input validation.
The plugin's vulnerability history, although currently showing no unpatched CVEs, indicates a past high-severity issue related to Incorrect Privilege Assignment. The fact that a vulnerability existed in the past, even if patched, suggests that the plugin may have had exploitable flaws, and this specific type of vulnerability (Incorrect Privilege Assignment) can be particularly damaging. The plugin has a total of one known CVE, which is currently patched. This indicates that while past vulnerabilities have been addressed, vigilance is still required. The plugin has 7 entry points with 1 unprotected entry point.
In conclusion, while the plugin employs some solid security practices, particularly around database interactions and output encoding, the unprotected AJAX handler and the inherent risk of `unserialize` are significant weaknesses. The past high-severity vulnerability also warrants cautious consideration. The plugin is moderately secure, but the identified unprotected entry point and the use of `unserialize` require immediate attention and mitigation.
Key Concerns
- Unprotected AJAX handler
- Use of unserialize function
- Past high severity vulnerability
WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce <= 1.3.5 - Authenticated (Contributor+) Privilege Escalation
WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce Attack Surface
AJAX Handlers 7
WordPress Hooks 21
Maintenance & Trust
WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce Alternatives
WPC Frequently Bought Together for WooCommerce
woo-bought-together
WPC Frequently Bought Together helps you increase your sales with personalized product recommendations.
WPC Linked Variation for WooCommerce
wpc-linked-variation
WPC Linked Variation is built to link separate products together by attributes.
WPC Smart Quick View for WooCommerce
woo-smart-quick-view
WPC Smart Quick View allows users to get a quick look at products without opening the product page.
WPC Smart Wishlist for WooCommerce
woo-smart-wishlist
WPC Smart Wishlist is a simple but powerful tool that can help your customer save products for buying later.
WPC Smart Compare for WooCommerce
woo-smart-compare
It helps customers compare products with mighty AJAX, doesn't require opening a new page or iframe, and allows drag-and-drop functionality.
WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce Developer Profile
71 plugins · 441K total installs
How We Detect WPC Smart Linked Products – Upsells & Cross-sells for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpc-smart-linked-products/assets/css/wpcsl-backend.css/wp-content/plugins/wpc-smart-linked-products/assets/js/wpcsl-backend.js/wp-content/plugins/wpc-smart-linked-products/assets/js/wpcsl-frontend.js/wp-content/plugins/wpc-smart-linked-products/assets/js/wpcsl-frontend-init.js/wp-content/plugins/wpc-smart-linked-products/assets/js/wpcsl-backend.js/wp-content/plugins/wpc-smart-linked-products/assets/js/wpcsl-frontend.js/wp-content/plugins/wpc-smart-linked-products/assets/js/wpcsl-frontend-init.jswpc-smart-linked-products/assets/css/wpcsl-backend.css?ver=wpc-smart-linked-products/assets/js/wpcsl-backend.js?ver=wpc-smart-linked-products/assets/js/wpcsl-frontend.js?ver=wpc-smart-linked-products/assets/js/wpcsl-frontend-init.js?ver=HTML / DOM Fingerprints
wpcsl-tabswpcsl-field-wrapperwpcsl-rule-fieldswpcsl-add-rule-wrapwpcsl-product-selectdata-wpcsl-product-iddata-wpcsl-rule-idWPCleverWpcslwpcsl_ajax_object/wp-json/wpcsl/v1/search_term