...Specifically, it lacks secure session ID's and has not been reviewed for XSS, SQL Injection, CSRF...
WARNING #2: This code is written for php3. Most people reading this have probably never even heard of php3. I just tested it out (2015) for fun and found that it doesn't work at all. Please, please; choose not just a different shopping cart, but perhaps a different language. The world has changed since 1998!
Why are ten people a week still downloading? (as of 2015)
PHPShopCart is an example single-script shopping-cart web application demo written in PHP and designed to connect to a MySQL database. ...