Conditional Cart Messages for WooCommerce – YourPlugins.com Security & Risk Analysis

wordpress.org/plugins/yourplugins-wc-conditional-cart-notices

Show cart messages or notices in your WooCommerce cart by using conditional rules! Made with love by yourplugins.com

60 active installs v1.2.10 PHP + WP 4.3.1+ Updated Jun 26, 2023
cartcheckoutmessagesnoticeswoocommerce
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 26, 2025
Safety Verdict

Is Conditional Cart Messages for WooCommerce – YourPlugins.com Safe to Use in 2026?

Use With Caution

Score 63/100

Conditional Cart Messages for WooCommerce – YourPlugins.com has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 26, 2025Updated 2yr ago
Risk Assessment

The plugin "yourplugins-wc-conditional-cart-notices" v1.2.10 exhibits a mixed security posture. On one hand, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication. There are also no critical or high severity taint flows detected, and dangerous functions are absent. This suggests a deliberate effort to limit direct entry points for attackers.

However, significant concerns arise from the output escaping and the vulnerability history. The complete lack of proper output escaping (0%) for 22 identified outputs is a critical flaw, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. Furthermore, the presence of one unpatched medium severity vulnerability (likely CSRF, given the historical pattern) from 2025-09-26 indicates a failure in timely patching and a potential recurring weakness. The plugin also only implements one capability check, which is insufficient given the lack of robust output sanitization.

In conclusion, while the plugin has a limited attack surface, the critical deficiency in output escaping and the unpatched medium severity vulnerability present substantial risks. The lack of proper sanitization for all output makes it an easy target for XSS, and the historical vulnerability pattern suggests a need for more rigorous security testing and maintenance. It is strongly recommended that users update to a version where the output escaping is corrected and the known vulnerability is patched.

Key Concerns

  • Complete lack of output escaping
  • Unpatched CVE
  • Low number of capability checks
  • SQL queries not fully prepared
Vulnerabilities
1

Conditional Cart Messages for WooCommerce – YourPlugins.com Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-60171medium · 4.3Cross-Site Request Forgery (CSRF)

Conditional Cart Messages for WooCommerce &#8211; YourPlugins.com <= 1.2.10 - Cross-Site Request Forgery

Sep 26, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Conditional Cart Messages for WooCommerce – YourPlugins.com Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
22
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

jQueryDataTables

SQL Query Safety

50% prepared2 total queries

Output Escaping

0% escaped22 total outputs
Attack Surface

Conditional Cart Messages for WooCommerce – YourPlugins.com Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuapp\application\wc-conditional-cart-notices-application.php:27
actionwoocommerce_before_cartapp\notice\notice-helper.php:16
actionwoocommerce_before_cart_tableapp\notice\notice-helper.php:17
actionwoocommerce_before_cart_contentsapp\notice\notice-helper.php:18
actionwoocommerce_cart_contentsapp\notice\notice-helper.php:20
actionwoocommerce_after_cart_contentsapp\notice\notice-helper.php:21
actionwoocommerce_after_cart_tableapp\notice\notice-helper.php:22
Maintenance & Trust

Conditional Cart Messages for WooCommerce – YourPlugins.com Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 26, 2023
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings4
Active installs60
Developer Profile

Conditional Cart Messages for WooCommerce – YourPlugins.com Developer Profile

yourplugins

1 plugin · 60 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Conditional Cart Messages for WooCommerce – YourPlugins.com

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
yourplugins-wc-conditional-cart-notices/style.css?ver=1.2.10yourplugins-wc-conditional-cart-notices/script.js?ver=1.2.10

HTML / DOM Fingerprints

JS Globals
window.YPS_WC_Conditional_Cart_Notices
FAQ

Frequently Asked Questions about Conditional Cart Messages for WooCommerce – YourPlugins.com