Buy one click

Buy one click for Shop-Script

Increases sales conversion online store

4.5 94 ratings

7 days free

To try out this plugin, open it in the Installer app in your Webasyst. Free trial is available on Webasyst Cloud only.

Your review
Installs
3400+
Developer
Version
1.7.0
Updated
July 9, 2026
Additional licenses
50% discount
Minimal requirements
1.7.0 July 9, 2026

Security

  • PHP object injection on the quick-order form. The buy_data POST field was passed to unserialize() without restrictions, allowing a serialized object to be supplied and a gadget chain to be triggered. The call now uses ['allowed_classes' => false]: arrays and scalars keep working, objects are not restored.
  • Reflected XSS in the order dialog. The reflected buy_data value and the user comment were printed into the template without escaping (Smarty auto-escaping is off in this project). Escaping was added; the round-trip of the serialized data is preserved.

Bug fixes

  • The order window's vertical offset ignored its setting. The option was ignored — the script hard-coded 200 in both branches. The offset is now read from the setting, with 200 kept as the default.
  • Use of eval() when accessing the Yandex.Metrica counter. Looking up the yaCounter<id> object went through eval(); replaced with a safe window['yaCounter'+id] access — same behavior, without executing a string.
  • PHP 8 warning in the order fields list: the $types variable was used in array_merge() before initialization; array initialization was added before the loop.

Improvements

  • The settings screen was migrated to the Webasyst UI 2.0 interface. Settings were rebuilt on native 2.0 components: tabs, waSwitch toggles, a built-in color picker instead of colpick.js, and plain text fields instead of redactor/CodeMirror. The contact-fields repeater and the dependent fields (Metrica, Google Analytics, alignment) were preserved.
  • The previous settings template was kept as a fallback for installs on the old interface (templates/actions-legacy/), so the update does not break them.
1.6.4.1 March 21, 2016
Fixed a minor error
1.6.4 March 17, 2016
1. Separation basket - the contents of the basket are not included in the quick order
2. Fixed bugs
1.6.3 September 1, 2015
Fixed a minor error
1.6.2 August 10, 2015
1. Fixed bug with empty orders when product is no longer in stock
2. Added ability to disable the vertical alignment for the order form
3. Fixed some minor bugs
1.6.1 July 17, 2015
Fixed a minor error
1.6 July 16, 2015
1. Added the ability to display the button in the list of goods (category). Pattern list-thums.html
2. Added the ability to display on the order form the name and image of the goods
3. Improved plugin settings page
4. The tag <style> is now located between the <head> </head>
5. Fixed a minor error
1.5.1 July 4, 2015
fixed minor bug
1.5 June 26, 2015
1. Fixed bug with duplicate orders
2. added the ability to assign the class for the button "Buy one click" and "Order", for styling buttons
3. Separated settings button "buy one click" for shopping cart and cards goods
1.4 May 8, 2015
1. Minor bugs fixed
2. The ability to edit "The caption on button" and leaving it active for the case when the goods are unavailable
3. The possibility of changing the name of a button on the order form
4. Content editor for the "description" settings
5. The ability to add "Buy one click" button to cart, including any position in cart.html template using code
{shopStorequickorderPlugin::cart_button()}

6. For additional scripts functions
function storequickorder_event_set_visibility_button_false() {
alert('Кнопка Купить в 1 клик стала неактивной, т.к товар недоступен ');
}
function storequickorder_event_set_visibility_button_true() {
alert('Кнопка Купить в 1 клик стала активной, товар есть в наличии ');
}

7. The ability to customize goal for Yandex Metrics and Google-Analytics
July 23, 2014
First version released.