
Conditional Cart Messages for WooCommerce – YourPlugins.com Security & Risk Analysis
wordpress.org/plugins/yourplugins-wc-conditional-cart-noticesShow cart messages or notices in your WooCommerce cart by using conditional rules! Made with love by yourplugins.com
Is Conditional Cart Messages for WooCommerce – YourPlugins.com Safe to Use in 2026?
Use With Caution
Score 63/100Conditional Cart Messages for WooCommerce – YourPlugins.com has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin "yourplugins-wc-conditional-cart-notices" v1.2.10 exhibits a mixed security posture. On one hand, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication. There are also no critical or high severity taint flows detected, and dangerous functions are absent. This suggests a deliberate effort to limit direct entry points for attackers.
However, significant concerns arise from the output escaping and the vulnerability history. The complete lack of proper output escaping (0%) for 22 identified outputs is a critical flaw, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. Furthermore, the presence of one unpatched medium severity vulnerability (likely CSRF, given the historical pattern) from 2025-09-26 indicates a failure in timely patching and a potential recurring weakness. The plugin also only implements one capability check, which is insufficient given the lack of robust output sanitization.
In conclusion, while the plugin has a limited attack surface, the critical deficiency in output escaping and the unpatched medium severity vulnerability present substantial risks. The lack of proper sanitization for all output makes it an easy target for XSS, and the historical vulnerability pattern suggests a need for more rigorous security testing and maintenance. It is strongly recommended that users update to a version where the output escaping is corrected and the known vulnerability is patched.
Key Concerns
- Complete lack of output escaping
- Unpatched CVE
- Low number of capability checks
- SQL queries not fully prepared
Conditional Cart Messages for WooCommerce – YourPlugins.com Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Conditional Cart Messages for WooCommerce – YourPlugins.com <= 1.2.10 - Cross-Site Request Forgery
Conditional Cart Messages for WooCommerce – YourPlugins.com Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Conditional Cart Messages for WooCommerce – YourPlugins.com Attack Surface
WordPress Hooks 7
Maintenance & Trust
Conditional Cart Messages for WooCommerce – YourPlugins.com Maintenance & Trust
Maintenance Signals
Community Trust
Conditional Cart Messages for WooCommerce – YourPlugins.com Alternatives
Cart & Checkout Notices/Messages for WooCommerce
cart-messages-for-woocommerce
Add and customize WooCommerce cart and checkout notices.
Direct Checkout for WooCommerce
woocommerce-direct-checkout
Formerly "WooCommerce Direct Checkout". This plugin simplifies the entire WooCommerce checkout process to improve your sales rate.
Sliding Cart for WooCommerce by FunnelKit – Skip Cart & Reach WooCommerce Checkout Faster
cart-for-woocommerce
FunnelKit Cart adds a beautiful sliding cart to your WooCommerce store. Let the buyers add items, edit quantity and add upsells on the side cart.
Force Authentification Before Checkout for WooCommerce
woo-force-authentification-before-checkout
Force customer to log in or register before checkout
Disable cart page for WooCommerce
disable-cart-page-for-woocommerce
Disable WooCommerce cart page and force customers to buy single products.
Conditional Cart Messages for WooCommerce – YourPlugins.com Developer Profile
1 plugin · 60 total installs
How We Detect Conditional Cart Messages for WooCommerce – YourPlugins.com
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
yourplugins-wc-conditional-cart-notices/style.css?ver=1.2.10yourplugins-wc-conditional-cart-notices/script.js?ver=1.2.10HTML / DOM Fingerprints
window.YPS_WC_Conditional_Cart_Notices