
Checkout Fields for Blocks Security & Risk Analysis
wordpress.org/plugins/checkout-fields-for-blocksThe Checkout Fields for Blocks plugin allows adding new fields to the checkout form.
Is Checkout Fields for Blocks Safe to Use in 2026?
Generally Safe
Score 100/100Checkout Fields for Blocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "checkout-fields-for-blocks" version 1.2.2 exhibits a generally strong security posture with several good practices in place. The absence of any known CVEs, critical or high severity taint flows, and a relatively small attack surface with all entry points appearing to be protected are positive indicators. The plugin also demonstrates good use of nonces and capability checks in its code.
However, there are areas for concern that slightly detract from an otherwise solid security profile. The presence of two SQL queries that do not utilize prepared statements is a notable risk, as it could open the door to SQL injection vulnerabilities, especially if user input is ever directly incorporated into these queries. While 65% output escaping is decent, the remaining 35% that are not properly escaped could lead to Cross-Site Scripting (XSS) vulnerabilities. The file operations, while not inherently problematic, warrant careful review in the context of how they are implemented, as improper handling could lead to security issues.
Overall, the plugin's lack of historical vulnerabilities is a strong positive signal, suggesting a commitment to security or simply a history of robust development. Nevertheless, the identified areas of concern regarding unescaped output and raw SQL queries represent potential weaknesses that should be addressed to further harden the plugin's security.
Key Concerns
- SQL queries without prepared statements
- Percentage of unescaped output
Checkout Fields for Blocks Security Vulnerabilities
Checkout Fields for Blocks Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Checkout Fields for Blocks Attack Surface
AJAX Handlers 1
WordPress Hooks 23
Maintenance & Trust
Checkout Fields for Blocks Maintenance & Trust
Maintenance Signals
Community Trust
Checkout Fields for Blocks Alternatives
Custom Payment Gateways for WooCommerce
custom-payment-gateways-woocommerce
Custom payment gateways for WooCommerce - create custom payment gateways to never miss out any payments for your WooCommerce Store.
Czech QR Payments for WooCommerce
czech-qr-code-bank-transfer-payment-for-woocommerce
Payment method for fast QR code bank transfer payment from Czech banking mobile apps
Clean Checkout for WooCommerce
clean-checkout-for-woocommerce
Simplify WooCommerce checkout by disabling fields and adding a Full Name field — supports both classic and block checkout.
Pigee Shipping & Payments
pigee-shipping-payments
Pigee integration for WooCommerce – provide real-time shipping rates, insurance, and payments at checkout.
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Checkout Fields for Blocks Developer Profile
23 plugins · 127K total installs
How We Detect Checkout Fields for Blocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/checkout-fields-for-blocks/build/css/admin.css/wp-content/plugins/checkout-fields-for-blocks/build/css/frontend.csscheckout-fields-for-blocks/build/css/admin.asset.phpcheckout-fields-for-blocks/build/css/frontend.asset.phpHTML / DOM Fingerprints
wp/wp-json/checkout-fields-for-blocks/v1/settings