
wunsch-index.de Wunschlisten Widget Security & Risk Analysis
wordpress.org/plugins/wunsch-indexde-wishlistsThis widget allows you to add your wunsch-index.de wishlist to your blog. Simply enter the URL to your wishlist and all your wishes will be displayed.
Is wunsch-index.de Wunschlisten Widget Safe to Use in 2026?
Generally Safe
Score 85/100wunsch-index.de Wunschlisten Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wunsch-indexde-wishlists" v0.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and has no known CVEs or recorded past vulnerabilities. However, significant concerns arise from the static analysis. The presence of the "unserialize" function is a critical risk, especially when combined with a lack of input sanitization and insufficient capability checks. The 100% of output not being properly escaped is a serious vulnerability that could lead to cross-site scripting (XSS) attacks if user-supplied data is outputted without sanitization. The taint analysis showing three flows with unsanitized paths further exacerbates these risks, indicating potential for malicious data to be processed without proper validation.
While the attack surface appears small with only one shortcode and no unprotected AJAX or REST API endpoints, the identified code signals and taint analysis point to a high potential for vulnerabilities. The absence of nonce checks and capability checks on its entry points, coupled with the dangerous use of `unserialize`, creates a dangerous environment. The vulnerability history of zero CVEs might suggest it hasn't been extensively targeted or audited, rather than indicating inherent security. Overall, despite a clean vulnerability history, the code itself contains serious security flaws that require immediate attention.
Key Concerns
- Dangerous function: unserialize used
- Output escaping: 100% not properly escaped
- Taint analysis: 3 unsanitized path flows
- Nonce checks: 0
- Capability checks: 0
wunsch-index.de Wunschlisten Widget Security Vulnerabilities
wunsch-index.de Wunschlisten Widget Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
wunsch-index.de Wunschlisten Widget Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
wunsch-index.de Wunschlisten Widget Maintenance & Trust
Maintenance Signals
Community Trust
wunsch-index.de Wunschlisten Widget Alternatives
Wunsch Koala – Joey der Wunschlisten Verwalter
wunsch-koala-joey-der-wunschlisten-verwalter
Biete deinen Besuchern die Möglichkeit, beliebige Artikel auf ihre Wunschliste beim Wunsch Koala zu setzen.
YITH WooCommerce Wishlist
yith-woocommerce-wishlist
YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 10.6.x compatible.
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
WPC Smart Wishlist for WooCommerce
woo-smart-wishlist
WPC Smart Wishlist is a simple but powerful tool that can help your customer save products for buying later.
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
wunsch-index.de Wunschlisten Widget Developer Profile
1 plugin · 10 total installs
How We Detect wunsch-index.de Wunschlisten Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wunsch-indexde-wishlists/css/style.cssHTML / DOM Fingerprints
wunschindex_item_freewunschindex_item_reservedwunschindex_item_imagewunschindex_item_textwunschindex_intro<!--
-->
id="wunschindex_list"id="wunschindex_intro"data-custom-attributewindow.document.getElementById('wunschindex_list').style.display='block'window.document.getElementById('wunschindex_intro').style.display='none'<div id="wunschindex_list"><div class="wunschindex_item_free"<div class="wunschindex_item_reserved"<div class="wunschindex_item_image"