
Extra Product Options Builder for WooCommerce Security & Risk Analysis
wordpress.org/plugins/additional-product-fields-for-woocommerceThe most customizable extra product options builder for WooCommerce. You will love how many fields and features the free version has.
Is Extra Product Options Builder for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Extra Product Options Builder for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "additional-product-fields-for-woocommerce" v1.2.158 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and having no external HTTP requests, significant concerns arise from its attack surface and historical vulnerabilities.
The static analysis reveals a single AJAX handler that lacks authentication checks, presenting a direct entry point for potential exploitation. The presence of the `unserialize` function is a notable concern, as improper handling of unserialized data can lead to severe vulnerabilities if not carefully sanitized. Although the taint analysis did not find critical or high-severity issues in the analyzed flows, the single flow with unsanitized paths warrants attention. The output escaping is also a weakness, with only 56% of outputs being properly escaped, increasing the risk of cross-site scripting (XSS).
The vulnerability history indicates a pattern of medium-severity issues, primarily XSS and CSRF, with the most recent vulnerability being in late 2024. The absence of currently unpatched vulnerabilities is positive, but the recurring nature of these vulnerability types suggests potential ongoing weaknesses in input validation and output sanitization. Overall, the plugin has some strengths in secure coding practices but needs improvement in securing its entry points and ensuring comprehensive output sanitization to mitigate identified risks.
Key Concerns
- AJAX handler without auth check
- Presence of unserialize function
- Only 56% of outputs properly escaped
- Flow with unsanitized paths
- 2 medium severity vulnerabilities historically
Extra Product Options Builder for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Extra Product Options Builder for WooCommerce <= 1.2.133 - Unauthenticated Stored Cross-Site Scripting
Extra Product Options Builder for WooCommerce <= 1.2.104 - Cross-Site Request Forgery to Notice Dismissal
Extra Product Options Builder for WooCommerce Release Timeline
Extra Product Options Builder for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Extra Product Options Builder for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 36
Maintenance & Trust
Extra Product Options Builder for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Extra Product Options Builder for WooCommerce Alternatives
QODE Product Extra Options for WooCommerce
qode-product-extra-options-for-woocommerce
QODE Product Extra Options for WooCommerce elevates the eCommerce experience by providing your shoppers with selectable advanced product options.
Extra Product Options For WooCommerce | Custom Product Addons and Fields
woo-extra-product-options
WooCommerce Extra Product Options plugin lets you add product addons (custom products field) of 20 different field types to your product page.
Simple Registration for WooCommerce
woocommerce-simple-registration
A simple plugin to add a [woocommerce_simple_registration] shortcode to display the registration form on a separate page.
Product Addons and Product Options With Custom Fields – WowAddons
product-addons
Product addons for WooCommerce is the ultimate plugin that lets you add extra product options, product fields, and WooCommerce product fields.
YayExtra – WooCommerce Extra Product Options
yayextra
YayExtra – Product Options for WooCommerce lets you add customizable options and extra fields to your products.
Extra Product Options Builder for WooCommerce Developer Profile
19 plugins · 12K total installs
How We Detect Extra Product Options Builder for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/additional-product-fields-for-woocommerce/styles/cart.css/wp-content/plugins/additional-product-fields-for-woocommerce/scripts/admin.js/wp-content/plugins/additional-product-fields-for-woocommerce/assets/js/main.js/wp-content/plugins/additional-product-fields-for-woocommerce/assets/css/main.cssrednaowooextraproduct/core/Managers/WooStagesManager.phpadditional-product-fields-for-woocommerce/style.css?ver=additional-product-fields-for-woocommerce/script.js?ver=HTML / DOM Fingerprints
rednao-woo-extra-product-fieldrednao-woo-extra-product-inputrednao-woo-extra-product-selectrednao-woo-extra-product-textarearednao-woo-extra-product-radiorednao-woo-extra-product-checkboxrednao-woo-extra-product-color-pickerrednao-woo-extra-product-date+2 moredata-field-iddata-field-typedata-product-idRednaoWooExtraProductRednaoWooExtraProductData/wp-json/rednaowooextraproduct/v1/options