
YITH Request a Quote for WooCommerce Security & Risk Analysis
wordpress.org/plugins/yith-woocommerce-request-a-quoteThe YITH Request a Quote for WooCommerce plugin lets your customers ask for an estimate of a list of products they are interested into.
Is YITH Request a Quote for WooCommerce Safe to Use in 2026?
Generally Safe
Score 93/100YITH Request a Quote for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "yith-woocommerce-request-a-quote" version 2.48.0 exhibits a generally good security posture with strong adherence to best practices in output escaping and the use of prepared statements for SQL queries. The static analysis reveals a relatively low number of critical code signals, with no identified dangerous functions, unsanitized paths in taint analysis, or file operations, which are all positive indicators. However, there is a notable concern regarding the attack surface, with one out of seven AJAX handlers lacking authentication checks. This single unprotected entry point, while not immediately critical, represents a potential avenue for attackers to exploit if a vulnerability exists within that handler.
The plugin's vulnerability history, while currently showing no unpatched CVEs, does reveal a past pattern of high and medium severity vulnerabilities, specifically related to Missing Authorization and Cross-Site Request Forgery (CSRF). This historical trend, coupled with the identified unprotected AJAX handler, suggests a recurring susceptibility to authorization bypasses or injection-like attacks if not carefully managed. The last recorded vulnerability in 2026 is noted, but the presence of historical high-severity issues warrants continued vigilance.
In conclusion, the plugin demonstrates strengths in code sanitization and secure query practices. Nevertheless, the presence of an unprotected AJAX endpoint and a history of significant vulnerabilities, particularly those related to authorization, present a moderate risk. Addressing the unprotected AJAX handler and maintaining a strong awareness of potential authorization-related flaws would significantly improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handler
- Historical high severity CVEs (2)
- Historical medium severity CVEs (1)
- SQL queries not using prepared statements (30%)
YITH Request a Quote for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
YITH WooCommerce Request A Quote <= 2.46.0 - Missing Authorization
YITH plugins by YITHEMES <= (Various Versions) - Missing Authorization
YITH Request a Quote for WooCommerce <= 1.6.3 - Cross-Site Request Forgery
YITH Request a Quote for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
YITH Request a Quote for WooCommerce Attack Surface
AJAX Handlers 7
Shortcodes 2
WordPress Hooks 135
Scheduled Events 1
Maintenance & Trust
YITH Request a Quote for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
YITH Request a Quote for WooCommerce Alternatives
Appsila WooQuote
appsila-wooquote
Appsila WooQuote is a plugin that enables your customers send quote requests from your woocommerce shop which will then be tracked in a full functiona …
PSM Request a Quote for WooCommerce
psm-request-a-quote
Allow customers to request a quote for WooCommerce products with ease.
Request a Quote for WooCommerce – Get a Quote Button – Product Enquiry Form Popup – Product Quotation
get-a-quote-button-for-woocommerce
Request a Quote for WooCommerce and Elementor plugin shows a Contact Form 7 or WPForms popup on button click. Quote for WooCommerce, price on request.
ELEX WooCommerce Request a Quote
elex-request-a-quote
ELEX Request a Quote plugin allows your customers to add products to a quote list, fill out a form, and request a custom price.
B2B Request a Quote
woo-add-to-quote
Add B2B quote requests to WooCommerce. Let your customers request, manage, and negotiate quotes comfortably to boost B2B sales on your WordPress site.
YITH Request a Quote for WooCommerce Developer Profile
33 plugins · 1.1M total installs
How We Detect YITH Request a Quote for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yith-woocommerce-request-a-quote/assets/css/yith-ywraq-admin.css/wp-content/plugins/yith-woocommerce-request-a-quote/assets/css/yith-ywraq-frontend.css/wp-content/plugins/yith-woocommerce-request-a-quote/assets/js/yith-ywraq-admin.js/wp-content/plugins/yith-woocommerce-request-a-quote/assets/js/yith-ywraq-frontend.js/wp-content/plugins/yith-woocommerce-request-a-quote/assets/js/yith-ywraq-admin.js/wp-content/plugins/yith-woocommerce-request-a-quote/assets/js/yith-ywraq-frontend.jsyith-woocommerce-request-a-quote/assets/css/yith-ywraq-admin.css?ver=yith-woocommerce-request-a-quote/assets/css/yith-ywraq-frontend.css?ver=yith-woocommerce-request-a-quote/assets/js/yith-ywraq-admin.js?ver=yith-woocommerce-request-a-quote/assets/js/yith-ywraq-frontend.js?ver=HTML / DOM Fingerprints
yith-ywraq-add-to-quoteyith-ywraq-request-quote-button<!-- IMPORTANT: This file is part of YITH Request a Quote for WooCommerce. --><!-- This source file is subject to the GNU GENERAL PUBLIC LICENSE (GPL 3.0) --><!-- It is also available through the world-wide-web at this URL: --><!-- YITH Request a Quote for WooCommerce -->+2 moredata-yith-request-quote-iddata-yith-request-quote-product-iddata-yith-request-quote-product-idsYITH_YWRAQ_frontendyith_ywraq_admin_paramsywreaq_frontend_params[yith_ywraq_button][yith_ywraq_button product_id=...]