Zypento Wishlist for WooCommerce Security & Risk Analysis

wordpress.org/plugins/zypento-wishlist-for-woocommerce

Add a heart button so customers can save products to a wishlist and manage it anytime from their My Account page.

0 active installs v1.0.6 PHP 7.0+ WP 6.0+ Updated Mar 1, 2026
ecommercefavoriteswishlistwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Zypento Wishlist for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Zypento Wishlist for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "zypento-wishlist-for-woocommerce" plugin, version 1.0.6, exhibits a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, unsanitized taint flows, or raw SQL queries is commendable. Furthermore, all identified SQL queries utilize prepared statements, and 100% of output is properly escaped, significantly mitigating common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS).

The plugin also demonstrates good practice by implementing nonce checks (9 instances) and capability checks (3 instances), indicating an effort to secure its functionalities. The attack surface appears minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. The lack of external HTTP requests further limits potential attack vectors.

Given the complete absence of known CVEs, historical vulnerabilities, or any recorded common vulnerability types, the plugin's historical security track record appears clean. This suggests a commitment to secure coding over time or a very limited exposure to security researchers. The overall assessment is positive, with no immediate critical or high-risk security concerns directly identifiable from the provided data. The plugin's strengths lie in its careful handling of data and its limited exposure points.

Vulnerabilities
None known

Zypento Wishlist for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Zypento Wishlist for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
35 prepared
Unescaped Output
0
76 escaped
Nonce Checks
9
Capability Checks
3
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared35 total queries

Output Escaping

100% escaped76 total outputs
Attack Surface

Zypento Wishlist for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actioninitincludes\core\class-admin.php:37
actionset_logged_in_cookieincludes\core\class-admin.php:38
actionadmin_enqueue_scriptsincludes\core\class-admin.php:39
actionenqueue_block_editor_assetsincludes\core\class-admin.php:40
actionadmin_menuincludes\core\class-admin.php:41
filterzypento_admin_settingsincludes\core\class-admin.php:42
actionzypento_admin_page_contentincludes\core\class-admin.php:43
filterzypento_wishlist_admin_variablesincludes\core\class-admin.php:44
actionrest_api_initincludes\core\class-admin.php:45
actioninitincludes\core\class-admin.php:46
actionwp_enqueue_scriptsincludes\core\class-frontend.php:32
actioninitincludes\core\class-wishlist.php:59
actionrest_api_initincludes\core\class-wishlist.php:60
actionwoocommerce_after_add_to_cart_buttonincludes\core\class-wishlist.php:61
actioninitincludes\core\class-wishlist.php:62
filterwoocommerce_account_menu_itemsincludes\core\class-wishlist.php:63
actionwoocommerce_account_wishlist_endpointincludes\core\class-wishlist.php:64
actionwp_footerincludes\core\class-wishlist.php:65
filterzypento_woo_wishlist_variablesincludes\core\class-wishlist.php:66
Maintenance & Trust

Zypento Wishlist for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 1, 2026
PHP min version7.0
Downloads380

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Zypento Wishlist for WooCommerce Developer Profile

sproutient

9 plugins · 90 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zypento Wishlist for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zypento-wishlist-for-woocommerce/assets/css/admin-main.css/wp-content/plugins/zypento-wishlist-for-woocommerce/assets/js/admin-main.js/wp-content/plugins/zypento-wishlist-for-woocommerce/assets/css/admin.css/wp-content/plugins/zypento-wishlist-for-woocommerce/assets/js/admin.js/wp-content/plugins/zypento-wishlist-for-woocommerce/assets/css/blockeditor.css/wp-content/plugins/zypento-wishlist-for-woocommerce/assets/js/blockeditor.js
Script Paths
/wp-content/plugins/zypento-wishlist-for-woocommerce/assets/js/admin-main.js/wp-content/plugins/zypento-wishlist-for-woocommerce/assets/js/admin.js/wp-content/plugins/zypento-wishlist-for-woocommerce/assets/js/blockeditor.js
Version Parameters
zypento-wishlist-for-woocommerce/assets/css/admin-main.css?ver=zypento-wishlist-for-woocommerce/assets/js/admin-main.js?ver=zypento-wishlist-for-woocommerce/assets/css/admin.css?ver=zypento-wishlist-for-woocommerce/assets/js/admin.js?ver=zypento-wishlist-for-woocommerce/assets/css/blockeditor.css?ver=zypento-wishlist-for-woocommerce/assets/js/blockeditor.js?ver=

HTML / DOM Fingerprints

CSS Classes
zypento-settingszypento-wishlist-setting-action-item
HTML Comments
<!-- Start Zypento Wishlist Admin Page -->
Data Attributes
data-zypento-id
JS Globals
zypentoWishlistAdminVariableszypentoWishlistBlocksEditorVariables
REST Endpoints
/wp-json/zypento-wishlist-for-woocommerce/v1/
FAQ

Frequently Asked Questions about Zypento Wishlist for WooCommerce