Additional Charges on WC Checkout Security & Risk Analysis

wordpress.org/plugins/additional-charges-on-wc-checkout

Additional Charges on WC Checkout allow administrators to add custom fees to a customer's order total conditionally and easily.

0 active installs v2.0.0 PHP + WP 3.0.1+ Updated Jan 14, 2025
e-commerceextra-feeminimum-orderservice-chargewoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Additional Charges on WC Checkout Safe to Use in 2026?

Generally Safe

Score 92/100

Additional Charges on WC Checkout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "additional-charges-on-wc-checkout" v2.0.0 demonstrates a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or critical taint flows is highly commendable. Furthermore, the plugin utilizes prepared statements for all its SQL queries and properly escapes all its output, indicating good secure coding practices.

While the static analysis reveals an exceptionally clean codebase with no immediate exploitable vulnerabilities, the lack of any recorded vulnerability history, including past CVEs, might indicate either a consistently secure development or a lack of thorough past security audits. The presence of only one capability check and zero nonce checks on its zero AJAX handlers and zero REST API routes suggests that the plugin either doesn't require extensive user interaction that would necessitate these security measures, or that these protections might be missing if the attack surface is larger than indicated. Overall, the plugin appears very secure in its current version, with its primary potential weakness being the limited insight into its historical security landscape and the complete absence of nonce checks which are a standard security practice for AJAX handlers.

In conclusion, "additional-charges-on-wc-checkout" v2.0.0 is currently a very secure plugin, with no apparent exploitable flaws detected in static analysis or vulnerability history. The strict adherence to prepared statements and output escaping are significant strengths. However, the complete absence of nonce checks, even with a zero-entry point AJAX/REST API surface, warrants a minor note of caution, as it's a standard security layer that is missing. The clean history is positive, but does not guarantee future security.

Key Concerns

  • No nonce checks detected
Vulnerabilities
None known

Additional Charges on WC Checkout Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Additional Charges on WC Checkout Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Attack Surface

Additional Charges on WC Checkout Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initadditional-charges-on-wc-checkout.php:29
actionadmin_noticesadditional-charges-on-wc-checkout.php:32
actionwoocommerce_cart_calculate_feesinc\apply-charge-options.php:11
filterwoocommerce_get_sections_productsinc\get-settings-admin-options.php:11
filterwoocommerce_get_settings_productsinc\get-settings-admin-options.php:12
Maintenance & Trust

Additional Charges on WC Checkout Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 14, 2025
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Additional Charges on WC Checkout Developer Profile

dkgupta3507

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Additional Charges on WC Checkout

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Additional Charges on WC Checkout