
Easy Upload Files During Checkout Security & Risk Analysis
wordpress.org/plugins/easy-upload-files-during-checkoutAttach files during checkout process on cart page with ease.
Is Easy Upload Files During Checkout Safe to Use in 2026?
Generally Safe
Score 93/100Easy Upload Files During Checkout has a strong security track record. Known vulnerabilities have been patched promptly.
The 'easy-upload-files-during-checkout' plugin v3.0.1 presents a mixed security posture. While it demonstrates some good practices like a significant percentage of properly escaped outputs and a majority of SQL queries using prepared statements, there are notable concerns. The presence of two AJAX handlers without authentication checks creates an immediate attack surface that could be exploited by unauthenticated users. Furthermore, the taint analysis revealed one high-severity flow with unsanitized paths, indicating a potential for privilege escalation or unauthorized file access. The plugin's vulnerability history, including a past critical vulnerability and a general pattern of missing authorization and unrestricted file uploads, is a significant red flag. Although there are no currently unpatched CVEs, the recurring nature of these vulnerability types suggests persistent coding weaknesses that could be re-introduced or exploited in future versions. The plugin's strengths lie in its relative lack of dangerous functions and no obvious REST API vulnerabilities. However, the combination of unprotected entry points, high-severity taint flows, and historical vulnerability patterns warrants caution.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow
- Past critical CVE
- Historical missing authorization
- Historical unrestricted file upload
Easy Upload Files During Checkout Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Easy Upload Files During Checkout <= 3.0.0 - Missing Authorization
Easy Upload Files During Checkout <= 2.9.8 - Unauthenticated Arbitrary JavaScript File Upload
Easy Upload Files During Checkout Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Easy Upload Files During Checkout Attack Surface
AJAX Handlers 7
WordPress Hooks 40
Maintenance & Trust
Easy Upload Files During Checkout Maintenance & Trust
Maintenance Signals
Community Trust
Easy Upload Files During Checkout Alternatives
File Uploader for WooCommerce
file-uploader-for-woocommerce
Allows to attach files from different sources to WooCommerce customer orders.
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
limit-login-attempts-reloaded
Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.
WPS Hide Login
wps-hide-login
Change wp-login.php to anything you want.
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Easy Upload Files During Checkout Developer Profile
40 plugins · 33K total installs
How We Detect Easy Upload Files During Checkout
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-upload-files-during-checkout/css/jquery-ui.css/wp-content/plugins/easy-upload-files-during-checkout/css/style.css/wp-content/plugins/easy-upload-files-during-checkout/js/main.js/wp-content/plugins/easy-upload-files-during-checkout/js/upload.js/wp-content/plugins/easy-upload-files-during-checkout/js/jquery-ui.js/wp-content/plugins/easy-upload-files-during-checkout/js/main.js/wp-content/plugins/easy-upload-files-during-checkout/js/upload.js/wp-content/plugins/easy-upload-files-during-checkout/js/jquery-ui.jseasy-upload-files-during-checkout/css/jquery-ui.css?ver=easy-upload-files-during-checkout/css/style.css?ver=easy-upload-files-during-checkout/js/main.js?ver=easy-upload-files-during-checkout/js/upload.js?ver=easy-upload-files-during-checkout/js/jquery-ui.js?ver=HTML / DOM Fingerprints
eufdc-upload-main-diveufdc-upload-contentEasy Upload Files During CheckoutAttach files during checkout process on cart page with ease.Author: Fahad MahmoodPlugin URI: https://androidbubble.com/blog/wordpress/plugins/easy-upload-files-during-checkout+2 moredata-eufdc-iddata-max-sizedata-file-typesdata-is-requiredeufdc_obj