
WPC Smart Upsell Funnel for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wpc-smart-upsell-funnelSuggest additional products and offer discounts to customers on the checkout page with flexible and smart conditions.
Is WPC Smart Upsell Funnel for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100WPC Smart Upsell Funnel for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "wpc-smart-upsell-funnel" plugin v3.0.9 presents a mixed security posture. While it demonstrates good practices in several areas, such as 100% use of prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns remain. The presence of a single AJAX handler without authentication checks creates a potential entry point for unauthorized actions. Furthermore, the use of the `unserialize` function, even without immediate evidence of exploitable taint flows in the static analysis, is a known risk and warrants careful attention due to potential deserialization vulnerabilities. The plugin's vulnerability history, showing a past high-severity vulnerability related to missing authorization, reinforces the concern around authorization checks. This pattern suggests a recurring area of weakness that attackers might target. Overall, the plugin has strengths in data handling and output sanitization, but the identified attack vector and the continued potential for deserialization issues necessitate caution.
Key Concerns
- AJAX handler without authentication checks
- Use of unserialize function
- Past high severity vulnerability (Missing Authorization)
WPC Smart Upsell Funnel for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPC Smart Upsell Funnel for WooCommerce <= 3.0.4 - Authenticated (Subscriber+) Arbitrary Options Update
WPC Smart Upsell Funnel for WooCommerce Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WPC Smart Upsell Funnel for WooCommerce Attack Surface
AJAX Handlers 11
Shortcodes 2
WordPress Hooks 42
Maintenance & Trust
WPC Smart Upsell Funnel for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WPC Smart Upsell Funnel for WooCommerce Alternatives
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce
cartflows
1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.
FunnelKit – Funnel Builder for WooCommerce Checkout
funnel-builder
Create high-converting WooCommerce checkout pages, WooCommerce thank you pages & sales funnels with the highest-rated WordPress funnel builder.
WPC Frequently Bought Together for WooCommerce
woo-bought-together
WPC Frequently Bought Together helps you increase your sales with personalized product recommendations.
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
wpfunnels
WPFunnels is a powerful funnel builder for WooCommerce that helps store owners create high-converting WooCommerce checkout pages, sales funnels, one-c …
Upsell Funnel Builder for WooCommerce – Create Upsells, Cross-Sells, Order Bumps, Frequently Bought, and Popups.
upsell-order-bump-offer-for-woocommerce
Upsell Funnel Builder lets you create WooCommerce Upsells, Order Bumps, One Click upsell, Cross-Sells, Frequently Bought, and Popups.
WPC Smart Upsell Funnel for WooCommerce Developer Profile
71 plugins · 441K total installs
How We Detect WPC Smart Upsell Funnel for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpc-smart-upsell-funnel/assets/css/wpcuf-frontend.css/wp-content/plugins/wpc-smart-upsell-funnel/assets/js/wpcuf-frontend.js/wp-content/plugins/wpc-smart-upsell-funnel/assets/css/wpcuf-backend.css/wp-content/plugins/wpc-smart-upsell-funnel/assets/js/wpcuf-backend.js/wp-content/plugins/wpc-smart-upsell-funnel/assets/js/wpcuf-frontend.js/wp-content/plugins/wpc-smart-upsell-funnel/assets/js/wpcuf-backend.jswpc-smart-upsell-funnel/assets/css/wpcuf-frontend.css?ver=wpc-smart-upsell-funnel/assets/js/wpcuf-frontend.js?ver=wpc-smart-upsell-funnel/assets/css/wpcuf-backend.css?ver=wpc-smart-upsell-funnel/assets/js/wpcuf-backend.js?ver=HTML / DOM Fingerprints
wpcuf-popupwpcuf-popup-contentwpcuf-popup-closewpcuf-uf-wrapperwpcuf-ob-wrapperwpcuf-uf-productwpcuf-ob-productWPC Smart Upsell Funnel for WooCommerceWPCUF AJAXdata-wpcuf-popupdata-wpcuf-product-iddata-wpcuf-variation-idWPCUF_AJAX_URLwpcuf_frontend_params/wp-json/wpcuf/v1/add-to-cart/wp-json/wpcuf/v1/remove-from-cart