Plugin Pulse
← Pulse

Welcart e-Commerce

by info@welcart · eCommerce

Also makes 1 other plugin · 10.0K+ installs across the portfolio →

Welcart is a free WordPress e-commerce plugin with the top market share in Japan.

⚠ Few reviews
How scoring works →
85 Health · A
Maintenance 100/100
Rating quality 78/100
Support 70/100

85 health vs 68 average across 5,563 eCommerce plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

90 / 100

Excellent listing optimization

Biggest win: Rating quality

Update recency 100/100
WP compatibility 100/100
Rating quality 58/100
Listing tuning 100/100

To rank higher: Too few reviews to rank on quality — nudge happy users to leave one.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,424 days · wp.org + Plugin Pulse archive

+63% vs prior 30d
150Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

30.5K

now · peak 32.4K

30.4K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Welcart e-Commerce · #1473 you Cargus · #7811 Shipping by Machool · #16018 Shopping Cart & eCom · #3700

Rating trend

Star average over time · dips mark rough releases

4.5Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

3Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

11

releases in the last 12 months

2mo ago

latest release · v2.11.31

283

tagged releases on record

Recent releases

2.11.31 · 2mo ago2.11.30 · 2mo ago2.11.29 · 3mo ago2.11.28 · 5mo ago2.11.27 · 7mo ago2.11.26 · 9mo ago2.11.25 · 10mo ago2.11.24 · 11mo ago2.11.23 · 11mo ago2.11.22 · 11mo ago2.11.21 · 12mo ago2.11.20 · 1.1y ago2.11.19 · 1.2y ago2.11.18 · 1.2y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v2.11 46%
v1.9 15%
v2.8 11%
v2.9 5.6%
Older / other versions 22%

Estimated active installs

The public count shows “10K+”. Our estimate pins where the real number sits.

tracked estimate
10K–20K ≈16K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-03-10 · 1,460 observations

10KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.

Details

Version
2.12.1
Last updated
11d ago
Added
2009-10-23 · 16 yrs old
Requires WP
5.6
Tested up to
7.0.4
Requires PHP
7.4

Recent reviews

All reviews on wp.org ↗
  1. matthew1309
    12mo ago

    コンビニ決済に対応した決済サービスを導入しやすい点で、WooCommerceより便利。ただし、WooCommerceのような分かりやすい説明はないため、慣れが必要。 以下の点で分かりづらく、仕組みを理解するのに時間がかかった。・最初に商品の新規追加をしようとしても、配送方法を登録しておかないとエラーとなり、配送方法の登録からやり直すことになる。・設定欄によって文字を入力するだけでよいものと、文字の入力後に追加ボタンを押す必要があるものがある(追加ボタンが入力欄を追加するボタンに見えるが、実際は確定ボタン相当となっている)ため、統一性がなく非常に分かりづらい。 また、プラグインを有効化した瞬間に固定ページと投稿カテゴリーを勝手に作り、無効化してもそれらが残ってしまうという、一度でも有効化すると環境を汚してしまうところも美しくない。そのため、既存の環境に安易に有効化せず、テスト用の環境で使ってみるのがお勧め。 (訂正)カスタム投稿タイプは追加しない様子のため訂正した。SKUも商品の新規追加時に設定可能だったため、配送方法だけ事前に登録しておけば、商品の新規追加が可能だった。 This topic was modified 10 months ago by matthew1309. This topic was modified 10 months ago by matthew1309.

    Read on wp.org ↗
  2. 阿部
    2.5y ago

    無料とは思えない高機能カートシステム。 設定が簡単です。 カスタマイズの幅も広いです。 他のプラグインと併用して機能拡張できるのも便利です。

    Read on wp.org ↗
  3. Hasan Islom
    4.0y ago

    オンラインショップを無料で制作するにすごくいいプラグインです。 カスタマーサポートも日本語で優しくしてくれて助かります。

    Read on wp.org ↗
  4. Mizuho Ogino
    11.6y ago

    It is a highly customizable plugin package. Their support also is very good and really helped for me.

    Read on wp.org ↗
  5. Carolrosent
    11.9y ago

    Really good plugin , fairly simple to use

    Read on wp.org ↗
  6. Jandal
    13.8y ago

    We are using this for a Japan e-commerce website, it is pretty good once you get into it. There are a number of things that really do need updating though, we have had to heavily modify the plugin core. Generally it is doing the job and has good integration into payment gateways for Japan. When it comes to translation, as we have a bi-lingual website, it is missing translation support in a number of areas, but we have been able to make it work. You will need PHP and WordPress experience to make the most of this plugin. =-)

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 11.31 [e-SCOTT / WelcartPay] Fixed a bug that caused an error with the product name in online payment collection transactions. Fixed a bug in the filtering of the “Order List CSV” and “Order Details List CSV” exported from the 11.31
  2. Version 11.30 [Zeus] Updated the mobile phone number validation for Buy Now Pay Later payment. [Paidy] Fixed parameters. Updated the Japan Post tracking URL. Changed the order list and member list downloads in the admin screen to allo 11.30
  3. Version 11.29 Security enhancement (Broken Access Control). [PayPal] Fixed subsequent processing after payment error in automatic recurring billing. Fixed a bug where radio buttons and checkboxes were not displayed in button_to_cart. 11.29
  4. Version 11.28 [PayPal] Removed unnecessary IPN settings. [PayPal] Fixed a bug that an error status was not displayed on the order list when a capture error occurred. Fixed the style of the “Close” button on the mail sending dialog. Ad 11.28
  5. Version 11.27 Made compatible with PHP 8.3. [WelcartPay] Fixed a bug that error messages for credit card updates were not displayed on the My Page when using 3DS. Fixed a bug that members using recurring payments could cancel their me 11.27
  6. Version 11.26 Fixed a bug that the quantity could not be updated on the cart page when the SKU code contained specific symbols. Fixed a bug that an error occurred when attempting to use points for shipping payment when purchasing a 0 11.26

Known vulnerabilities

via Wordfence Intelligence

52 disclosed vulnerabilities on record for this plugin, 1 still affects the current version.

  1. 2026-08-14 CVE-2026-15213 Client-Side Enforcement of Server-Side Security Affects < 2.11.33 Patched in 2.11.33
  2. 2026-08-11 CVE-2026-27539 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.31 Patched in 2.11.32
  3. 2026-08-10 CVE-2026-16066 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.33 Patched in 2.11.34
  4. 2026-07-31 CVE-2026-16065 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.11.31 Patched in 2.11.32
  5. 2026-06-04 CVE-2026-49775 Missing Authorization Affects <= 2.11.28 Patched in 2.11.29
  6. 2025-11-12 CVE-2025-12979 Missing Authorization Affects <= 2.11.24 Patched in 2.11.25
  7. 2025-10-21 CVE-2025-10651 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.22 Patched in 2.11.23
  8. 2025-10-14 CVE-2025-62953 Missing Authorization Affects <= 2.11.24 Patched in 2.11.25
  9. 2025-10-07 CVE-2025-10649 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.11.21 Patched in 2.11.22
  10. 2025-09-09 CVE-2025-9367 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.20 Patched in 2.11.21
  11. 2025-09-09 CVE-2025-58984 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.20 Patched in 2.11.21
  12. 2025-08-12 CVE-2025-54012 Deserialization of Untrusted Data Affects <= 2.11.16 Patched in 2.11.17
  13. 2025-07-16 CVE-2025-54013 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.16 Patched in 2.11.17
  14. 2025-06-03 CVE-2025-47511 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.11.13 Patched in 2.11.14
  15. 2025-02-11 CVE-2025-0511 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.9 Patched in 2.11.10
  16. 2024-09-18 CVE-2024-42404 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.11.1 Patched in 2.11.2
  17. 2024-04-12 CVE-2024-32144 Missing Authorization Affects <= 2.9.14 Patched in 2.10.0
  18. 2023-12-21 CVE-2023-50847 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.9.4 Patched in 2.9.4
  19. 2023-12-08 CVE-2023-6120 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.9.6 Patched in 2.9.7
  20. 2023-11-15 Deserialization of Untrusted Data Affects < 2.9.6 Patched in 2.9.6
  21. 2023-11-14 Cross-Site Request Forgery (CSRF) Affects <= 2.9.4 Patched in 2.9.5
  22. 2023-11-14 CVE-2023-5953 Unrestricted Upload of File with Dangerous Type Affects <= 2.9.4 Patched in 2.9.5
  23. 2023-11-10 CVE-2023-5951 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.4 Patched in 2.9.5
  24. 2023-11-10 CVE-2023-5952 Deserialization of Untrusted Data Affects <= 2.9.4 Patched in 2.9.5
  25. 2023-09-26 CVE-2023-40219 Unrestricted Upload of File with Dangerous Type Affects <= 2.8.21 Patched in 2.8.22
  26. 2023-09-14 CVE-2023-43493 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.8.22 Patched in 2.8.22
  27. 2023-09-14 CVE-2023-43610 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.8.22 Patched in 2.8.22
  28. 2023-01-27 CVE-2023-22705 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.10 Patched in 2.8.11
  29. 2022-12-23 CVE-2022-4655 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.8 Patched in 2.8.9
  30. 2022-12-05 CVE-2022-4237 Deserialization of Untrusted Data Affects <= 2.8.5 Patched in 2.8.6
  31. 2022-12-05 CVE-2022-4236 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.8.4 Patched in 2.8.5
  32. 2022-11-30 CVE-2022-4140 Exposure of Sensitive Information to an Unauthorized Actor Affects 2.6.10 - 2.8.4 Patched in 2.8.5
  33. 2022-11-28 Cross-Site Request Forgery (CSRF) Affects <= 2.8.3 Patched in 2.8.4
  34. 2022-11-21 CVE-2022-3935 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.3 Patched in 2.8.4
  35. 2022-11-21 CVE-2022-3946 Missing Authorization Affects <= 2.8.3 Patched in 2.8.4
  36. 2022-11-16 Cross-Site Request Forgery (CSRF) Affects <= 2.8.3 Patched in 2.8.4
  37. 2022-09-02 CVE-2022-41840 Exposure of Sensitive Information to an Unauthorized Actor Affects 2.6.0 - 2.7.7 Patched in 2.7.8
  38. 2021-08-06 CVE-2021-4355 Missing Authorization Affects < 2.2.8 Patched in 2.2.8
  39. 2021-08-06 CVE-2021-4375 Missing Authorization Affects < 2.2.8 Patched in 2.2.8
  40. 2021-06-11 CVE-2021-20734 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.3 Patched in 2.2.4
  41. 2021-02-08 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.1.0 Patched in 2.1.1
  42. 2020-11-05 CVE-2020-28339 Deserialization of Untrusted Data Affects < 1.9.36 Patched in 1.9.36
  43. 2016-06-24 CVE-2016-4827 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.2 Patched in 1.8.3
  44. 2016-06-24 CVE-2016-4828 Authentication Bypass Using an Alternate Path or Channel Affects <= 1.8.2 Patched in 1.8.3
  45. 2016-06-24 CVE-2016-4825 Deserialization of Untrusted Data Affects < 1.8.3 Patched in 1.8.3
  46. 2016-06-24 CVE-2016-4826 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.8.3 Patched in 1.8.3
  47. 2015-12-17 CVE-2015-7791 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.5.3 Patched in 1.5.3
  48. 2015-07-15 CVE-2015-2973 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.4.18 Patched in 1.4.18
  49. 2014-03-04 CVE-2014-10017 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.9.1 Patched in 2.9.2
  50. 2014-03-03 CVE-2014-10016 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.3.12 No patch available
  51. 2012-12-14 CVE-2012-5177 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.2.2 Patched in 1.2.2
  52. 2012-12-14 CVE-2012-5178 Cross-Site Request Forgery (CSRF) Affects < 1.2.2 Patched in 1.2.2

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 53 languages, 1 at 90% or more

Japanese 100%
Vietnamese 67%
Thai 31%
English (Australia) 29%
Swedish 28%
Russian 17%
Ukrainian 17%
German 9%
Danish 7%
English (Canada) 7%
Romanian 7%
Cebuano 6%
Dutch (Formal) 6%
English (South Africa) 6%
English (UK) 6%
French (France) 6%
Azerbaijani 5%
Dutch 5%
English (New Zealand) 5%
Czech 4%
Italian 4%
Moroccan Arabic 4%
Polish 4%
Finnish 3%

Plus 29 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-03-22 20K+ → 10K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Welcart e-Commerce into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/usc-e-shop" width="480" height="300" style="border:0" loading="lazy" title="Welcart e-Commerce — Plugin Pulse"></iframe>
Preview card ↗

Welcart e-Commerce: 10K+ active installs, 4.5★ (6 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/usc-e-shop