
Custom WooCommerce Checkout Fields Editor Security & Risk Analysis
wordpress.org/plugins/add-fields-to-checkout-page-woocommerceCustom WooCommerce Checkout Fields Editor
Is Custom WooCommerce Checkout Fields Editor Safe to Use in 2026?
Use With Caution
Score 66/100Custom WooCommerce Checkout Fields Editor has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin 'add-fields-to-checkout-page-woocommerce' v1.3.4 presents a mixed security posture. While it demonstrates good practices like using prepared statements for SQL queries and implementing nonce and capability checks, there are significant areas of concern. The static analysis reveals a relatively small attack surface with no unprotected entry points, which is positive. However, a notable weakness is the low rate of proper output escaping (58%), suggesting potential for Cross-Site Scripting (XSS) vulnerabilities, especially when dealing with user-provided input.
The vulnerability history is a major red flag. The plugin has a history of four known CVEs, with one currently unpatched. The common vulnerability types listed (Missing Authorization, CSRF, XSS) align with the potential XSS risk identified in the static analysis and indicate a pattern of recurring security flaws. The presence of an unpatched vulnerability, even if medium severity, poses an immediate risk to users and suggests a lack of ongoing security maintenance or timely patching by the developers.
In conclusion, while the plugin has some strengths in its basic security implementations, the history of multiple vulnerabilities, particularly the unpatched one, and the concerning rate of unescaped output significantly elevate its risk profile. Users should exercise caution and prioritize updating or seeking alternative solutions.
Key Concerns
- Unpatched CVE
- Medium severity vulnerabilities in history (4)
- Low output escaping rate (58%)
- Bundled Freemius v1.0 library
Custom WooCommerce Checkout Fields Editor Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Custom WooCommerce Checkout Fields Editor <= 1.3.4 - Cross-Site Request Forgery
Custom WooCommerce Checkout Fields Editor <= 1.3.1 - Missing Authorization
Custom WooCommerce Checkout Fields Editor <= 1.3.0 - Cross-Site Request Forgery
Custom WooCommerce Checkout Fields Editor <= 1.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Custom WooCommerce Checkout Fields Editor Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Custom WooCommerce Checkout Fields Editor Attack Surface
AJAX Handlers 1
WordPress Hooks 40
Maintenance & Trust
Custom WooCommerce Checkout Fields Editor Maintenance & Trust
Maintenance Signals
Community Trust
Custom WooCommerce Checkout Fields Editor Alternatives
Checkout Field Editor for WooCommerce – Checkout Page Manager
woo-checkout-regsiter-field-editor
Checkout Field Editor for WooCommerce is the leading plugin for customizing, editing, removing, and managing your WooCommerce checkout fields.
Checkout Field Editor and Manager for WooCommerce
extra-checkout-fields-for-woocommerce
A simple WooCommerce Checkout Field Editor and Manager plugin to edit WooCommerce checkout fields, add custom checkout fields and more.
Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager
flexible-checkout-fields
The best WooCommerce checkout manager. Edit, remove or add checkout fields. Customize WooCommerce checkout with this checkout field customizer.
FEWC – Extra Checkout Fields For WooCommerce
fewc-extra-checkout-fields-for-woocommerce
Easily customize your checkout page: add custom fields, enable/disable fields, rearrange their positions, and preview changes in the WP Customizer
Qodax Checkout Manager – Checkout Field Editor for WooCommerce
qodax-checkout-manager
Customize and manage checkout fields in your WooCommerce store with a simple and user-friendly interface.
Custom WooCommerce Checkout Fields Editor Developer Profile
6 plugins · 10K total installs
How We Detect Custom WooCommerce Checkout Fields Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-fields-to-checkout-page-woocommerce/assets/js/wcfe-checkout-field-editor-frontend.js/wp-content/plugins/add-fields-to-checkout-page-woocommerce/assets/js/wcfe-checkout-field-editor-frontend.js/add-fields-to-checkout-page-woocommerce/assets/js/wcfe-checkout-field-editor-frontend.js?ver=HTML / DOM Fingerprints
<!-- WooCommerce Checkout & Account Field Editor Lite -->data-field_typedata-field_iddata-field_labelWCFE_VERSIONWCFE_URL