Absolute 2fa For Woocommerce Security & Risk Analysis

wordpress.org/plugins/absolute-2fa-for-woocommerce

A Two Factor Authentication addon that will add 2fa settings page under WooCommerce's My Account Page.

10 active installs v1.0.1 PHP 5.6+ WP 4.5+ Updated Feb 17, 2022
2fagoogle-authenticatortfatwo-factortwo-factor-auth
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Absolute 2fa For Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Absolute 2fa For Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of the 'absolute-2fa-for-woocommerce' plugin version 1.0.1 reveals a generally strong security posture. The absence of any identified dangerous functions, raw SQL queries, file operations, external HTTP requests, and a complete lack of critical or high severity taint flows are all positive indicators. Furthermore, the plugin exhibits good practices in its limited output escaping and its reliance on prepared statements for SQL queries.

However, there are notable areas for concern. The complete absence of nonce checks and capability checks across all entry points is a significant weakness. While the current attack surface is reported as zero, this lack of protective measures means that if any new entry points are introduced or if the current analysis missed potential ones, they would be entirely unprotected against various cross-site scripting and privilege escalation attacks. The vulnerability history being entirely clean is a good sign, but it doesn't mitigate the inherent risks identified in the static analysis.

In conclusion, the plugin demonstrates some good coding practices, particularly regarding SQL and dangerous functions. Nevertheless, the lack of fundamental security checks like nonces and capability checks on potential entry points presents a substantial risk that should be addressed to improve its overall security. This could be a false positive in the analysis report regarding the attack surface being zero.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • Low percentage of properly escaped output
Vulnerabilities
None known

Absolute 2fa For Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Absolute 2fa For Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Absolute 2fa For Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedabsolute-2fa-for-woocommerce.php:25
filterwoocommerce_get_query_varsabsolute-2fa-for-woocommerce.php:32
filterwoocommerce_settings_pagesabsolute-2fa-for-woocommerce.php:36
filterwoocommerce_account_menu_itemsabsolute-2fa-for-woocommerce.php:53
filterwoocommerce_endpoint_2fa-settings_titleabsolute-2fa-for-woocommerce.php:68
actionwoocommerce_account_2fa-settings_endpointabsolute-2fa-for-woocommerce.php:71
actionadmin_noticesabsolute-2fa-for-woocommerce.php:75
Maintenance & Trust

Absolute 2fa For Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 17, 2022
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Absolute 2fa For Woocommerce Developer Profile

AbsolutePlugins

3 plugins · 420 total installs

72
trust score
Avg Security Score
69/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Absolute 2fa For Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[twofactor_user_settings]
FAQ

Frequently Asked Questions about Absolute 2fa For Woocommerce