Custom Price Display for WooCommerce Security & Risk Analysis

wordpress.org/plugins/custom-price-display-for-woocommerce

Display the lowest or highest price of a variable product, with optional custom text before and after the price.

0 active installs v1.0.0 PHP 7.2+ WP 5.0+ Updated Oct 15, 2025
custom-priceprice-labelsvariable-pricewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Custom Price Display for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Custom Price Display for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The static analysis of the 'custom-price-display-for-woocommerce' plugin v1.0.0 reveals a generally strong security posture. The absence of any identified dangerous functions, raw SQL queries, unsanitized paths in taint analysis, and a complete lack of external HTTP requests are positive indicators. Furthermore, all identified output is properly escaped, and file operations are non-existent, significantly reducing the attack surface for common web vulnerabilities. The presence of nonce and capability checks, although limited in number, suggests some awareness of secure coding practices.

However, the analysis highlights a critical concern: the total absence of any identified entry points (AJAX, REST API, shortcodes, cron events). While this might seem like a strength, it's highly unusual for a functional plugin, especially one that modifies WooCommerce behavior. This could indicate that the plugin's functionality is implemented in a way that is not discoverable by the static analysis tools, or it might be entirely dependent on other plugins or themes, leaving its core logic and potential vulnerabilities unexamined. The presence of the Freemius v1.0 bundled library, without information on its specific version and potential vulnerabilities, also warrants a slight caution.

Given the complete lack of any recorded vulnerabilities, including CVEs, the plugin appears to have a clean history. This, combined with the positive static analysis findings, suggests a low immediate risk. Nevertheless, the mystery surrounding the zero attack surface and the potential implications of the bundled Freemius library prevent a perfect score. The plugin's effectiveness in securing its functionality relies heavily on the thoroughness of the static analysis and the absence of complex, indirect, or environment-dependent attack vectors that might not be visible in this report.

Key Concerns

  • Bundled Freemius v1.0 library
  • No identified AJAX handlers
  • No identified REST API routes
  • No identified shortcodes
  • No identified cron events
Vulnerabilities
None known

Custom Price Display for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Custom Price Display for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
172 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped172 total outputs
Attack Surface

Custom Price Display for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
actionadmin_noticescustom-price-display-for-woocommerce.php:28
actionadmin_footersrc\Components\WPEditor.php:16
filtermce_buttonssrc\Components\WPEditor.php:26
filtermce_external_pluginssrc\Components\WPEditor.php:35
actionadmin_noticessrc\Core\AdminNotifier.php:37
actionbefore_woocommerce_initsrc\CustomPriceDisplayPlugin.php:44
filterplugin_row_metasrc\CustomPriceDisplayPlugin.php:54
actioninitsrc\CustomPriceDisplayPlugin.php:89
actionadmin_enqueue_scriptssrc\CustomPriceDisplayPlugin.php:97
filtercustom_price_display/price_configsrc\Features\IndividualProductConfig\IndividualProductConfig.php:25
filterwoocommerce_product_data_tabssrc\Features\IndividualProductConfig\ProductTab.php:16
actionwoocommerce_product_data_panelssrc\Features\IndividualProductConfig\ProductTab.php:17
actionwoocommerce_process_product_metasrc\Features\IndividualProductConfig\ProductTab.php:18
actionadmin_menusrc\License.php:29
filterpricing/show_annual_in_monthlysrc\License.php:31
filterwoocommerce_get_price_htmlsrc\Services\VariableProductPriceService.php:18
filterwp_print_stylessrc\Services\VariableProductPriceService.php:24
filterwoocommerce_get_price_htmlsrc\Services\VariableProductPriceService.php:30
actionwp_footersrc\Services\VariableProductPriceService.php:36
actionwoocommerce_admin_settings_sanitize_optionsrc\Settings\CustomOptions\Checkbox.php:10
actionwoocommerce_admin_settings_sanitize_optionsrc\Settings\CustomOptions\MultipleTextInputs.php:12
actionwoocommerce_admin_settings_sanitize_optionsrc\Settings\CustomOptions\RichText.php:16
actionwoocommerce_admin_settings_sanitize_optionsrc\Settings\CustomOptions\SelectedProducts.php:13
filterwoocommerce_get_sections_productssrc\Settings\Settings.php:70
filterwoocommerce_get_settings_productssrc\Settings\Settings.php:71
actionadmin_enqueue_scriptssrc\Settings\Settings.php:79
actionadmin_footersrc\Settings\Settings.php:88
Maintenance & Trust

Custom Price Display for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 15, 2025
PHP min version7.2
Downloads159

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Custom Price Display for WooCommerce Developer Profile

Mykola Lukin

4 plugins · 10K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Price Display for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-price-display-for-woocommerce/admin/mce.js/wp-content/plugins/custom-price-display-for-woocommerce/css/admin.css/wp-content/plugins/custom-price-display-for-woocommerce/css/frontend.css
Script Paths
/wp-content/plugins/custom-price-display-for-woocommerce/vendor/freemius/wordpress-sdk/start.php
Version Parameters
custom-price-display-for-woocommerce/css/admin.css?ver=custom-price-display-for-woocommerce/css/frontend.css?ver=custom-price-display__mce-editor-localized?ver=custom-price-display-custom-mce-buttons?ver=

HTML / DOM Fingerprints

CSS Classes
cpdfw-message-template-mce
Data Attributes
data-id='20371'
JS Globals
custom_price_display_mce_data
FAQ

Frequently Asked Questions about Custom Price Display for WooCommerce