F4 Shipping Phone and E-Mail for WooCommerce Security & Risk Analysis

wordpress.org/plugins/f4-woocommerce-shipping-phone-and-e-mail

Adds fields for e-mail and/or telephone to the WooCommerce shipping address.

800 active installs v1.0.20 PHP 7.0+ WP 5.0+ Updated Dec 16, 2025
checkoutemailshippingtelephonewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is F4 Shipping Phone and E-Mail for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

F4 Shipping Phone and E-Mail for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "f4-woocommerce-shipping-phone-and-e-mail" plugin version 1.0.20 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface (AJAX, REST API, shortcodes, cron events) is a significant positive. Furthermore, the code signals indicate no dangerous functions, file operations, or external HTTP requests, and all SQL queries are properly prepared. The vulnerability history also shows no recorded CVEs, which is a very good sign for a plugin's security track record.

However, a critical concern arises from the output escaping analysis, where 100% of outputs are not properly escaped. This means that any data displayed by the plugin could potentially be vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied input is not sufficiently sanitized before being rendered. The absence of nonce and capability checks, while not directly exploitable due to the zero attack surface, indicates a potential weakness if the plugin were to expand its functionality in the future without implementing these essential security controls. The lack of taint analysis results is also noteworthy, as it might suggest a limited scope of analysis or that the tool did not identify any exploitable flows.

In conclusion, while the plugin demonstrates a commitment to secure coding practices in several key areas, the pervasive lack of output escaping presents a significant and immediate risk of XSS vulnerabilities. This weakness, coupled with the potential for future security issues if new entry points are added without proper authorization checks, warrants careful consideration and remediation.

Key Concerns

  • Unescaped output found
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

F4 Shipping Phone and E-Mail for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

F4 Shipping Phone and E-Mail for WooCommerce Release Timeline

v1.0.20Current
v1.0.19
v1.0.18
v1.0.17
v1.0.16
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

F4 Shipping Phone and E-Mail for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

F4 Shipping Phone and E-Mail for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
actionplugins_loadedmodules\Core\Hooks.php:32
actioninitmodules\Core\Hooks.php:33
actionbefore_woocommerce_initmodules\Core\Hooks.php:47
filterwoocommerce_checkout_fieldsmodules\Core\Hooks.php:50
filterwoocommerce_shipping_fieldsmodules\Core\Hooks.php:51
filterwoocommerce_ajax_get_customer_detailsmodules\Core\Hooks.php:52
actionwoocommerce_after_checkout_validationmodules\Core\Hooks.php:53
filterwoocommerce_checkout_get_valuemodules\Core\Hooks.php:54
filterwoocommerce_order_formatted_shipping_addressmodules\Core\Hooks.php:57
filterwoocommerce_localisation_address_formatsmodules\Core\Hooks.php:58
filterwoocommerce_formatted_address_replacementsmodules\Core\Hooks.php:59
filterwoocommerce_get_settings_accountmodules\Core\Hooks.php:62
filterwoocommerce_customer_meta_fieldsmodules\Core\Hooks.php:63
filterwoocommerce_admin_shipping_fieldsmodules\Core\Hooks.php:64
actioncurrent_screenmodules\Core\Hooks.php:65
filterwoocommerce_admin_order_preview_get_order_detailsmodules\Core\Hooks.php:66
filterwoocommerce_paypal_argsmodules\Core\Hooks.php:70
filterwoocommerce_privacy_export_customer_personal_data_propsmodules\Core\Hooks.php:73
filterwoocommerce_privacy_export_customer_personal_data_prop_valuemodules\Core\Hooks.php:74
filterwoocommerce_privacy_export_order_personal_data_propsmodules\Core\Hooks.php:75
filterwoocommerce_privacy_export_order_personal_data_propmodules\Core\Hooks.php:76
filterwoocommerce_privacy_erase_customer_personal_data_propsmodules\Core\Hooks.php:78
filterwoocommerce_privacy_erase_customer_personal_data_propmodules\Core\Hooks.php:79
actionwoocommerce_privacy_remove_order_personal_data_metamodules\Core\Hooks.php:80
actionadmin_footermodules\Core\Hooks.php:559
Maintenance & Trust

F4 Shipping Phone and E-Mail for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 16, 2025
PHP min version7.0
Downloads16K

Community Trust

Rating100/100
Number of ratings8
Active installs800
Alternatives

F4 Shipping Phone and E-Mail for WooCommerce Alternatives

Developer Profile

F4 Shipping Phone and E-Mail for WooCommerce Developer Profile

FAKTOR VIER

8 plugins · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect F4 Shipping Phone and E-Mail for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/f4-woocommerce-shipping-phone-and-e-mail/f4-woocommerce-shipping-phone-and-e-mail.php
Version Parameters
f4-woocommerce-shipping-phone-and-e-mail/f4-woocommerce-shipping-phone-and-e-mail.php?ver=f4-woocommerce-shipping-phone-and-e-mail/modules/Core/Hooks.php?ver=

HTML / DOM Fingerprints

CSS Classes
f4-shipping-phone-fieldf4-shipping-email-fieldf4-shipping-phone-field-wrapperf4-shipping-email-field-wrapper
Data Attributes
data-f4-shipping-phone-enableddata-f4-shipping-email-enabled
JS Globals
F4_WCSPE_VERSIONF4_WCSPE_SLUGF4_WCSPE_MAIN_FILEF4_WCSPE_BASENAMEF4_WCSPE_PATHF4_WCSPE_URL+2 more
FAQ

Frequently Asked Questions about F4 Shipping Phone and E-Mail for WooCommerce