
Extra Settings for WooCommerce Security & Risk Analysis
wordpress.org/plugins/extra-settings-for-woocommerceEasily customize and enhance WooCommerce store with highly demanded settings and additional features. Includes settings for Storefront theme.
Is Extra Settings for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Extra Settings for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'extra-settings-for-woocommerce' v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, making no external HTTP requests, and having no known vulnerabilities in its history. All SQL queries are properly prepared, and file operations are absent, which are strong indicators of secure coding. However, a significant concern arises from the presence of an unprotected AJAX handler, which represents a direct entry point into the application without any authentication or authorization checks. This alone creates a substantial risk that could be exploited by attackers.
While the taint analysis shows no critical or high-severity unsanitized flows, and the output escaping is at a reasonable 67%, the unprotected AJAX handler remains the most critical weakness. The absence of nonce checks and capability checks on this handler further amplifies the risk. The lack of any recorded vulnerabilities in the past could be interpreted as either a testament to its current security or simply due to a lack of targeted analysis or exploitation attempts. Overall, the plugin has several strong security foundations, but the unprotected AJAX endpoint is a glaring vulnerability that needs immediate attention to mitigate potential risks.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
- Output escaping is not 100%
Extra Settings for WooCommerce Security Vulnerabilities
Extra Settings for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Extra Settings for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 34
Maintenance & Trust
Extra Settings for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Extra Settings for WooCommerce Alternatives
Extra Product Options For WooCommerce | Custom Product Addons and Fields
woo-extra-product-options
WooCommerce Extra Product Options plugin lets you add product addons (custom products field) of 20 different field types to your product page.
Product Addons and Product Options With Custom Fields – WowAddons
product-addons
Product addons for WooCommerce is the ultimate plugin that lets you add extra product options, product fields, and WooCommerce product fields.
Extra Product Options Builder for WooCommerce
additional-product-fields-for-woocommerce
The most customizable extra product options builder for WooCommerce. You will love how many fields and features the free version has.
Product Options and Price Calculation Formulas for WooCommerce – Uni CPO
uni-woo-custom-product-options
Offers the ability to add extra product options and calculate the price dynamically based on the selected options using custom mathematical formulas!
YayExtra – WooCommerce Extra Product Options
yayextra
YayExtra – Product Options for WooCommerce lets you add customizable options and extra fields to your products.
Extra Settings for WooCommerce Developer Profile
3 plugins · 19K total installs
How We Detect Extra Settings for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extra-settings-for-woocommerce/js/admin.js/wp-content/plugins/extra-settings-for-woocommerce/css/admin.css/wp-content/plugins/extra-settings-for-woocommerce/includes/eswc-feedback-notice.php/wp-content/plugins/extra-settings-for-woocommerce/js/admin.jsextra-settings-for-woocommerce/js/admin.js?ver=extra-settings-for-woocommerce/css/admin.css?ver=HTML / DOM Fingerprints
eswc_hide_for_variation_selectdata-eswc-color-pickereswc_admin_params