
Wishlist for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wt-woocommerce-wishlistThis WooCommerce wishlist plugin adds a wishlist feature to your WooCommerce store. Let the users easily add and manage products from their wishlist p …
Is Wishlist for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Wishlist for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The wt-woocommerce-wishlist plugin version 2.1.6 presents a mixed security posture. While it demonstrates some good practices, such as a low number of dangerous functions and file operations, and a majority of SQL queries using prepared statements and outputs being properly escaped, there are significant concerns regarding its attack surface and authentication mechanisms.
The static analysis reveals a substantial attack surface, with 7 out of 8 entry points being AJAX handlers that lack authentication checks. This is a critical oversight, as it allows any user to interact with these endpoints, potentially leading to unintended actions or information disclosure. The presence of one flow with an unsanitized path in taint analysis, although not critical or high severity, also indicates a potential avenue for vulnerabilities if not handled carefully.
The vulnerability history shows a single medium-severity CVE related to Cross-Site Scripting. While there are currently no unpatched vulnerabilities, the past existence of an XSS issue, especially when combined with the unprotected AJAX handlers, suggests a recurring pattern of input sanitization weaknesses. The plugin has a history of vulnerabilities, which, despite being patched, warrants caution. Overall, the plugin has strengths in its core coding practices but weaknesses in its exposed endpoints that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Flow with unsanitized path
- Medium severity vulnerability in history
Wishlist for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Wishlist for WooCommerce <= 2.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Wishlist for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wishlist for WooCommerce Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 33
Maintenance & Trust
Wishlist for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Wishlist for WooCommerce Alternatives
Wishlist and Save for later for Woocommerce
aco-wishlist-for-woocommerce
Wishlist for WooCommerce helps to manage Wishlist and save for later feature in a WooCommerce store
YITH WooCommerce Wishlist
yith-woocommerce-wishlist
YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 10.6.x compatible.
Addonify – WooCommerce Wishlist
addonify-wishlist
Addonify WooCommerce Wishlist is a light-weight yet powerful tool that adds a wishlist functionality to your e-commerce shop.
Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later
flexible-wishlist
Lightweight and simple WooCommerce wishlist. Increases sales. Fits any theme. Customizes texts and icons. Add to ecommerce wishlist with just 1 click.
Wishlist for WooCommerce
jvm-woocommerce-wishlist
Supercharge your sales with WooCommerce Wishlist - a powerful tool that empowers customers to create wishlists and enhances their shopping experience.
Wishlist for WooCommerce Developer Profile
17 plugins · 377K total installs
How We Detect Wishlist for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wt-woocommerce-wishlist/assets/css/wishlist-frontend.css/wp-content/plugins/wt-woocommerce-wishlist/assets/css/wishlist-account-view.css/wp-content/plugins/wt-woocommerce-wishlist/assets/js/wishlist-frontend.js/wp-content/plugins/wt-woocommerce-wishlist/assets/js/wishlist-account-view.js/wp-content/plugins/wt-woocommerce-wishlist/admin/css/wishlist-webtoffee-admin.css/wp-content/plugins/wt-woocommerce-wishlist/assets/js/wishlist-frontend.js/wp-content/plugins/wt-woocommerce-wishlist/assets/js/wishlist-account-view.jswt-woocommerce-wishlist/assets/css/wishlist-frontend.css?ver=wt-woocommerce-wishlist/assets/css/wishlist-account-view.css?ver=wt-woocommerce-wishlist/assets/js/wishlist-frontend.js?ver=wt-woocommerce-wishlist/assets/js/wishlist-account-view.js?ver=wt-woocommerce-wishlist/admin/css/wishlist-webtoffee-admin.css?ver=HTML / DOM Fingerprints
webtoffee_bannerwishlist_version<!-- TODO Move to inner page -->data-product_iddata-product_typedata-variation_iddata-user_iddata-wishlist-countdata-wishlist-urlwt_wishlist_frontend_params[wt_mywishlist]