
F4 Shipping Phone and E-Mail for WooCommerce Security & Risk Analysis
wordpress.org/plugins/f4-woocommerce-shipping-phone-and-e-mailAdds fields for e-mail and/or telephone to the WooCommerce shipping address.
Is F4 Shipping Phone and E-Mail for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100F4 Shipping Phone and E-Mail for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "f4-woocommerce-shipping-phone-and-e-mail" plugin version 1.0.20 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface (AJAX, REST API, shortcodes, cron events) is a significant positive. Furthermore, the code signals indicate no dangerous functions, file operations, or external HTTP requests, and all SQL queries are properly prepared. The vulnerability history also shows no recorded CVEs, which is a very good sign for a plugin's security track record.
However, a critical concern arises from the output escaping analysis, where 100% of outputs are not properly escaped. This means that any data displayed by the plugin could potentially be vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied input is not sufficiently sanitized before being rendered. The absence of nonce and capability checks, while not directly exploitable due to the zero attack surface, indicates a potential weakness if the plugin were to expand its functionality in the future without implementing these essential security controls. The lack of taint analysis results is also noteworthy, as it might suggest a limited scope of analysis or that the tool did not identify any exploitable flows.
In conclusion, while the plugin demonstrates a commitment to secure coding practices in several key areas, the pervasive lack of output escaping presents a significant and immediate risk of XSS vulnerabilities. This weakness, coupled with the potential for future security issues if new entry points are added without proper authorization checks, warrants careful consideration and remediation.
Key Concerns
- Unescaped output found
- Missing nonce checks
- Missing capability checks
F4 Shipping Phone and E-Mail for WooCommerce Security Vulnerabilities
F4 Shipping Phone and E-Mail for WooCommerce Release Timeline
F4 Shipping Phone and E-Mail for WooCommerce Code Analysis
Output Escaping
F4 Shipping Phone and E-Mail for WooCommerce Attack Surface
WordPress Hooks 25
Maintenance & Trust
F4 Shipping Phone and E-Mail for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
F4 Shipping Phone and E-Mail for WooCommerce Alternatives
Comunas de Chile para WooCommerce
comunas-de-chile-para-woocommerce
Agrega las Comunas de Chile a WooCommerce para mejorar la experiencia de envío.
Remove Checkout Fields for Woocommerce
remove-default-checkout-fields-for-woocommerce
Remove Fields from woocommerce Checkout page
Ship to a Different Address Checked/Unchecked for WooCommerce
ship-to-a-different-address-checked-unchecked
Easily set WooCommerce's 'Ship to a different address' checkbox default to checked or unchecked on the checkout page.
Shipping Viet Nam WooCommerce
shipping-viet-nam-woocommerce
Plugin hỗ trợ toàn diện giao vận tại Việt Nam cho WooCommerce. Khách hàng chủ động chọn đơn vị giao vận và các gói giao vận ( Nhanh, Chuẩn, Tiết Kiệm ) tuỳ theo hầu bao của mình, việc này tạo sự tin tưởng cho người mua vì công khai chi phí ship giúp tăng tỉ lệ đặt hàng cho quản trị shop. Quản trị shop dễ dàng đăng vận đơn lên các đơn vị giao vận tuỳ theo lựa chọn của khách hàng khi đặt hàng chỉ với 1 Click, cùng với đó là tra cứu trạng thái vận đơn ngay từ trang quản trị.
My Country States For WooCommerce
my-country-states-for-woocommerce
Enhance accuracy, reduce errors, optimize shipping and tax calculations on WooCommerce checkout with auto-populated states for 160+ countries.
F4 Shipping Phone and E-Mail for WooCommerce Developer Profile
8 plugins · 4K total installs
How We Detect F4 Shipping Phone and E-Mail for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/f4-woocommerce-shipping-phone-and-e-mail/f4-woocommerce-shipping-phone-and-e-mail.phpf4-woocommerce-shipping-phone-and-e-mail/f4-woocommerce-shipping-phone-and-e-mail.php?ver=f4-woocommerce-shipping-phone-and-e-mail/modules/Core/Hooks.php?ver=HTML / DOM Fingerprints
f4-shipping-phone-fieldf4-shipping-email-fieldf4-shipping-phone-field-wrapperf4-shipping-email-field-wrapperdata-f4-shipping-phone-enableddata-f4-shipping-email-enabledF4_WCSPE_VERSIONF4_WCSPE_SLUGF4_WCSPE_MAIN_FILEF4_WCSPE_BASENAMEF4_WCSPE_PATHF4_WCSPE_URL+2 more