
WPMozo Wishlist Lite for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wpmozo-wishlist-lite-for-woocommerceWPMozo Wishlist Lite for WooCommerce adds a wishlist feature to your WooCommerce store, allowing customers to save their favorite products for future …
Is WPMozo Wishlist Lite for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100WPMozo Wishlist Lite for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wpmozo-wishlist-lite-for-woocommerce" v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and performing proper output escaping on almost all outputs. The absence of file operations and external HTTP requests also reduces the potential attack vectors. Furthermore, its vulnerability history is clean, with no recorded CVEs, suggesting a generally stable codebase in the past.
However, significant concerns arise from its attack surface and taint analysis. The plugin exposes a considerable number of AJAX handlers (13) without any authentication or capability checks, presenting a high risk of unauthorized actions if these handlers are exploitable. The taint analysis revealing three high-severity flows with unsanitized paths further exacerbates this risk, indicating that user-supplied input might be used in a dangerous way within these unprotected AJAX endpoints, potentially leading to serious vulnerabilities.
While the lack of known CVEs is encouraging, the high number of unprotected AJAX endpoints combined with critical taint flows points to a significant potential for newly discovered vulnerabilities. The plugin's strengths lie in its SQL and output handling, but its weaknesses in authentication and input sanitization for its extensive AJAX interface are serious security flaws.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Missing capability checks on AJAX
WPMozo Wishlist Lite for WooCommerce Security Vulnerabilities
WPMozo Wishlist Lite for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPMozo Wishlist Lite for WooCommerce Attack Surface
AJAX Handlers 13
Shortcodes 2
WordPress Hooks 57
Maintenance & Trust
WPMozo Wishlist Lite for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WPMozo Wishlist Lite for WooCommerce Alternatives
Addonify – WooCommerce Wishlist
addonify-wishlist
Addonify WooCommerce Wishlist is a light-weight yet powerful tool that adds a wishlist functionality to your e-commerce shop.
Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later
flexible-wishlist
Lightweight and simple WooCommerce wishlist. Increases sales. Fits any theme. Customizes texts and icons. Add to ecommerce wishlist with just 1 click.
Premmerce Wishlist for WooCommerce
premmerce-woocommerce-wishlist
This plugin provides the possibility for your customers to create wishlists with the further possibility to share them with friends.
Bizzwishlist
bizzwishlist
A lightweight and powerful WooCommerce Wishlist addon. Allow customers to save their favorite products and purchase them later.
Velocity Wishlist – WooCommerce Wishlist Plugin
velocity-wishlist
Powerful, lightweight wishlist functionality for WooCommerce. Supports guest users, product variations, social sharing, and fully customizable buttons …
WPMozo Wishlist Lite for WooCommerce Developer Profile
5 plugins · 410 total installs
How We Detect WPMozo Wishlist Lite for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpmozo-wishlist-lite-for-woocommerce/admin/js/settings.js/wp-content/plugins/wpmozo-wishlist-lite-for-woocommerce/admin/css/settings.css/wp-content/plugins/wpmozo-wishlist-lite-for-woocommerce/public/css/frontend.css/wp-content/plugins/wpmozo-wishlist-lite-for-woocommerce/public/js/frontend.js/wp-content/plugins/wpmozo-wishlist-lite-for-woocommerce/admin/js/settings.js/wp-content/plugins/wpmozo-wishlist-lite-for-woocommerce/public/js/frontend.jswpmozo-wishlist-lite-for-woocommerce/admin/js/settings.js?ver=wpmozo-wishlist-lite-for-woocommerce/admin/css/settings.css?ver=wpmozo-wishlist-lite-for-woocommerce/public/css/frontend.css?ver=wpmozo-wishlist-lite-for-woocommerce/public/js/frontend.js?ver=HTML / DOM Fingerprints
wpmozo-wishlist-lite-settings-wrapwpmozo-wishlist-lite-settings-fieldswpmozo-wishlist-lite-form-groupwpmozo-wishlist-lite-button<!-- WPMozo Wishlist Lite Settings --><!-- Start: Settings Section --><!-- End: Settings Section -->data-plugin-name="wpmozo-wishlist-lite-for-woocommerce"wpmozo_wishlist_lite_params