Welcart e-Commerce
by info@welcart · eCommerce
Also makes 1 other plugin · 10.0K+ installs across the portfolio →
Welcart is a free WordPress e-commerce plugin with the top market share in Japan.
85 health vs 68 average across 5,563 eCommerce plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Rating quality
To rank higher: Too few reviews to rank on quality — nudge happy users to leave one.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,424 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
30.5K
now · peak 32.4K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
11
releases in the last 12 months
2mo ago
latest release · v2.11.31
283
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “10K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-10 · 1,460 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ matthew130912mo ago
コンビニ決済に対応した決済サービスを導入しやすい点で、WooCommerceより便利。ただし、WooCommerceのような分かりやすい説明はないため、慣れが必要。 以下の点で分かりづらく、仕組みを理解するのに時間がかかった。・最初に商品の新規追加をしようとしても、配送方法を登録しておかないとエラーとなり、配送方法の登録からやり直すことになる。・設定欄によって文字を入力するだけでよいものと、文字の入力後に追加ボタンを押す必要があるものがある(追加ボタンが入力欄を追加するボタンに見えるが、実際は確定ボタン相当となっている)ため、統一性がなく非常に分かりづらい。 また、プラグインを有効化した瞬間に固定ページと投稿カテゴリーを勝手に作り、無効化してもそれらが残ってしまうという、一度でも有効化すると環境を汚してしまうところも美しくない。そのため、既存の環境に安易に有効化せず、テスト用の環境で使ってみるのがお勧め。 (訂正)カスタム投稿タイプは追加しない様子のため訂正した。SKUも商品の新規追加時に設定可能だったため、配送方法だけ事前に登録しておけば、商品の新規追加が可能だった。 This topic was modified 10 months ago by matthew1309. This topic was modified 10 months ago by matthew1309.
Read on wp.org ↗ - ★★★★★ 阿部2.5y ago
無料とは思えない高機能カートシステム。 設定が簡単です。 カスタマイズの幅も広いです。 他のプラグインと併用して機能拡張できるのも便利です。
Read on wp.org ↗ - ★★★★★ Hasan Islom4.0y ago
オンラインショップを無料で制作するにすごくいいプラグインです。 カスタマーサポートも日本語で優しくしてくれて助かります。
Read on wp.org ↗ - ★★★★★ Mizuho Ogino11.6y ago
It is a highly customizable plugin package. Their support also is very good and really helped for me.
Read on wp.org ↗ - ★★★★★ Carolrosent11.9y ago
Really good plugin , fairly simple to use
Read on wp.org ↗ - ★★★★★ Jandal13.8y ago
We are using this for a Japan e-commerce website, it is pretty good once you get into it. There are a number of things that really do need updating though, we have had to heavily modify the plugin core. Generally it is doing the job and has good integration into payment gateways for Japan. When it comes to translation, as we have a bi-lingual website, it is missing translation support in a number of areas, but we have been able to make it work. You will need PHP and WordPress experience to make the most of this plugin. =-)
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 11.31 [e-SCOTT / WelcartPay] Fixed a bug that caused an error with the product name in online payment collection transactions. Fixed a bug in the filtering of the “Order List CSV” and “Order Details List CSV” exported from the 11.31
- — Version 11.30 [Zeus] Updated the mobile phone number validation for Buy Now Pay Later payment. [Paidy] Fixed parameters. Updated the Japan Post tracking URL. Changed the order list and member list downloads in the admin screen to allo 11.30
- — Version 11.29 Security enhancement (Broken Access Control). [PayPal] Fixed subsequent processing after payment error in automatic recurring billing. Fixed a bug where radio buttons and checkboxes were not displayed in button_to_cart. 11.29
- — Version 11.28 [PayPal] Removed unnecessary IPN settings. [PayPal] Fixed a bug that an error status was not displayed on the order list when a capture error occurred. Fixed the style of the “Close” button on the mail sending dialog. Ad 11.28
- — Version 11.27 Made compatible with PHP 8.3. [WelcartPay] Fixed a bug that error messages for credit card updates were not displayed on the My Page when using 3DS. Fixed a bug that members using recurring payments could cancel their me 11.27
- — Version 11.26 Fixed a bug that the quantity could not be updated on the cart page when the SKU code contained specific symbols. Fixed a bug that an error occurred when attempting to use points for shipping payment when purchasing a 0 11.26
Known vulnerabilities
via Wordfence Intelligence52 disclosed vulnerabilities on record for this plugin, 1 still affects the current version.
- 2026-08-14 CVE-2026-15213 Client-Side Enforcement of Server-Side Security Affects < 2.11.33 Patched in 2.11.33
- 2026-08-11 CVE-2026-27539 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.31 Patched in 2.11.32
- 2026-08-10 CVE-2026-16066 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.33 Patched in 2.11.34
- 2026-07-31 CVE-2026-16065 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.11.31 Patched in 2.11.32
- Medium · 5.5 Welcart e-Commerce <= 2.11.22 - Authenticated (Editor+) Stored Cross-Site Scripting via order_mail ↗2025-10-21 CVE-2025-10651 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.22 Patched in 2.11.23
- 2025-10-07 CVE-2025-10649 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.11.21 Patched in 2.11.22
- 2025-09-09 CVE-2025-9367 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.20 Patched in 2.11.21
- 2025-09-09 CVE-2025-58984 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.20 Patched in 2.11.21
- 2025-07-16 CVE-2025-54013 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.16 Patched in 2.11.17
- 2025-06-03 CVE-2025-47511 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.11.13 Patched in 2.11.14
- High · 7.2 Welcart e-Commerce <= 2.11.9 - Unauthenticated Stored Cross-Site Scripting via name Parameter ↗2025-02-11 CVE-2025-0511 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.11.9 Patched in 2.11.10
- 2024-09-18 CVE-2024-42404 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.11.1 Patched in 2.11.2
- 2023-12-21 CVE-2023-50847 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.9.4 Patched in 2.9.4
- 2023-12-08 CVE-2023-6120 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 2.9.6 Patched in 2.9.7
- 2023-11-15 Deserialization of Untrusted Data Affects < 2.9.6 Patched in 2.9.6
- 2023-11-14 Cross-Site Request Forgery (CSRF) Affects <= 2.9.4 Patched in 2.9.5
- 2023-11-14 CVE-2023-5953 Unrestricted Upload of File with Dangerous Type Affects <= 2.9.4 Patched in 2.9.5
- 2023-11-10 CVE-2023-5951 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.4 Patched in 2.9.5
- 2023-09-26 CVE-2023-40219 Unrestricted Upload of File with Dangerous Type Affects <= 2.8.21 Patched in 2.8.22
- 2023-09-14 CVE-2023-43493 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.8.22 Patched in 2.8.22
- 2023-09-14 CVE-2023-43610 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.8.22 Patched in 2.8.22
- 2023-01-27 CVE-2023-22705 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.10 Patched in 2.8.11
- Medium · 6.4 Welcart e-Commerce <= 2.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2022-12-23 CVE-2022-4655 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.8 Patched in 2.8.9
- 2022-12-05 CVE-2022-4236 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.8.4 Patched in 2.8.5
- 2022-11-30 CVE-2022-4140 Exposure of Sensitive Information to an Unauthorized Actor Affects 2.6.10 - 2.8.4 Patched in 2.8.5
- 2022-11-28 Cross-Site Request Forgery (CSRF) Affects <= 2.8.3 Patched in 2.8.4
- Medium · 6.4 Welcart e-Commerce <= 2.8.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ↗2022-11-21 CVE-2022-3935 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.3 Patched in 2.8.4
- 2022-11-16 Cross-Site Request Forgery (CSRF) Affects <= 2.8.3 Patched in 2.8.4
- 2022-09-02 CVE-2022-41840 Exposure of Sensitive Information to an Unauthorized Actor Affects 2.6.0 - 2.7.7 Patched in 2.7.8
- 2021-06-11 CVE-2021-20734 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.3 Patched in 2.2.4
- 2021-02-08 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.1.0 Patched in 2.1.1
- Medium · 6.1 Welcart e-Commerce <= 1.8.2 - Cross-Site Scripting ↗2016-06-24 CVE-2016-4827 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.8.2 Patched in 1.8.3
- Critical · 9.8 Welcart e-Commerce <= 1.8.2 - Authentication Bypass ↗2016-06-24 CVE-2016-4828 Authentication Bypass Using an Alternate Path or Channel Affects <= 1.8.2 Patched in 1.8.3
- 2016-06-24 CVE-2016-4826 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.8.3 Patched in 1.8.3
- High · 8.8 Welcart e-Commerce < 1.5.3 - SQL Injection ↗2015-12-17 CVE-2015-7791 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.5.3 Patched in 1.5.3
- 2015-07-15 CVE-2015-2973 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.4.18 Patched in 1.4.18
- Critical · 9.8 Welcart e-Commerce <= 2.9.1 - SQL Injection ↗2014-03-04 CVE-2014-10017 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.9.1 Patched in 2.9.2
- 2014-03-03 CVE-2014-10016 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.3.12 No patch available
- Medium · 6.1 Welcart e-Commerce < 1.2.2 - Cross-Site Scripting ↗2012-12-14 CVE-2012-5177 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.2.2 Patched in 1.2.2
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 53 languages, 1 at 90% or more
Plus 29 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-03-22 20K+ → 10K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Cargus 700+ installs · 3.4★ · 3 shared tags B
-
Shipping by Machool 100+ installs · 3.6★ · 3 shared tags B
-
Shopping Cart & eCommerce Store 3K+ installs · 4.4★ · 2 shared tags A -
External Product New Tab for WooCommerce 3K+ installs · 4.6★ · 2 shared tags A -
Invoice Payment Gateway for WooCommerce 2K+ installs · 4.4★ · 2 shared tags A -
WC Pickup Store 2K+ installs · 4.4★ · 2 shared tags B
Embed this report card
Drop a live Pulse card for Welcart e-Commerce into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/usc-e-shop" width="480" height="300" style="border:0" loading="lazy" title="Welcart e-Commerce — Plugin Pulse"></iframe> Welcart e-Commerce: 10K+ active installs, 4.5★ (6 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/usc-e-shop