Fand Pickup Points : Ultimate Edition for WCFM Security & Risk Analysis

wordpress.org/plugins/fand-pickup-points-ultimate-edition-for-wcfm

WCFM Pickup Points allows each store on a marketplace to individualize their own pickup locations with custom opening hours.

0 active installs v1.0.3 PHP 8.2+ WP 6.9+ Updated Mar 11, 2026
marketplacepickup-pointsvendor-locationswcfmwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Fand Pickup Points : Ultimate Edition for WCFM Safe to Use in 2026?

Generally Safe

Score 100/100

Fand Pickup Points : Ultimate Edition for WCFM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 23d ago
Risk Assessment

The plugin "fand-pickup-points-ultimate-edition-for-wcfm" v1.0.3 exhibits a generally good security posture with several positive indicators. The presence of nonce checks on all AJAX handlers and capability checks on at least one entry point are strong security practices. The high percentage of SQL queries using prepared statements (83%) and properly escaped outputs (90%) further contribute to a robust defense against common web vulnerabilities like SQL injection and cross-site scripting. The absence of file operations and external HTTP requests at entry points also reduces potential attack vectors.

However, the taint analysis reveals specific areas of concern. Five out of seven analyzed flows have unsanitized paths, with two classified as high severity. This suggests potential vulnerabilities where user-supplied data might be processed in an unsafe manner, potentially leading to code execution or data manipulation if these flows are exposed to untrusted input. While the plugin has no recorded CVEs, the taint analysis findings should be treated as potential zero-day risks that require immediate attention and remediation. The presence of a bundled library, Select2, also warrants a check for its version and known vulnerabilities.

In conclusion, the plugin demonstrates a strong foundation in secure coding practices. Nevertheless, the high severity taint flows indicate a significant risk that overshadows the positive aspects. The lack of known vulnerabilities is reassuring but does not negate the risks identified through static and taint analysis. Prioritizing the remediation of the high severity taint flows is crucial to improving the plugin's overall security.

Key Concerns

  • High severity taint flows found
  • Unsanitized paths in taint flows
  • Bundled library (Select2) requires version check
Vulnerabilities
None known

Fand Pickup Points : Ultimate Edition for WCFM Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Fand Pickup Points : Ultimate Edition for WCFM Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
30 prepared
Unescaped Output
31
274 escaped
Nonce Checks
9
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

83% prepared36 total queries

Output Escaping

90% escaped305 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

7 flows5 with unsanitized paths
fandpipo_render_liste_categories_page (plugin.php:211)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Fand Pickup Points : Ultimate Edition for WCFM Attack Surface

Entry Points9
Unprotected0

AJAX Handlers 8

authwp_ajax_fandpipo_save_pickup_hoursClasses\Controllers\pickuphoursController.php:15
noprivwp_ajax_fandpipo_save_pickup_hoursClasses\Controllers\pickuphoursController.php:16
authwp_ajax_fandpipo_load_pickup_hours_templateClasses\Controllers\pickuphoursController.php:17
noprivwp_ajax_fandpipo_load_pickup_hours_templateClasses\Controllers\pickuphoursController.php:18
authwp_ajax_fandpipo_get_address_from_gpsClasses\Controllers\RoutesController.php:12
noprivwp_ajax_fandpipo_get_address_from_gpsClasses\Controllers\RoutesController.php:13
authwp_ajax_fandpipo_get_vendor_categoriesClasses\Controllers\StoreCategoryController.php:16
noprivwp_ajax_fandpipo_get_vendor_categoriesClasses\Controllers\StoreCategoryController.php:17

Shortcodes 1

[fandpipo_map] plugin.php:27
WordPress Hooks 18
filterdisplay_post_statesClasses\Admin\PageManager.php:13
actionwp_enqueue_scriptsClasses\Admin\Scripts.php:17
actionwp_enqueue_scriptsClasses\Admin\Scripts.php:18
actioninitClasses\Controllers\RoutesController.php:15
filterquery_varsClasses\Controllers\RoutesController.php:16
filtertemplate_includeClasses\Controllers\RoutesController.php:17
actionwpClasses\Controllers\RoutesController.php:18
actionwoocommerce_after_shop_loop_itemClasses\Controllers\RoutesController.php:19
filterdocument_title_partsClasses\Controllers\RoutesController.php:21
filterbody_classClasses\Controllers\RoutesController.php:62
actionwcfm_vendor_settings_updateClasses\Controllers\StoreCategoryController.php:13
actionplugins_loadedfand-pickup-points-ultimate-edition-for-wcfm.php:32
filterwoocommerce_subscriptions_object_data_cache_enabledfand-pickup-points-ultimate-edition-for-wcfm.php:34
filterdoing_it_wrong_trigger_errorfand-pickup-points-ultimate-edition-for-wcfm.php:38
actionwp_loadedfand-pickup-points-ultimate-edition-for-wcfm.php:53
actionadmin_menuplugin.php:30
actioninitplugin.php:32
actionplugins_loadedplugin.php:33
Maintenance & Trust

Fand Pickup Points : Ultimate Edition for WCFM Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version8.2
Downloads305

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Fand Pickup Points : Ultimate Edition for WCFM Developer Profile

Florence ANDROLUS

3 plugins · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fand Pickup Points : Ultimate Edition for WCFM

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fand-pickup-points-ultimate-edition-for-wcfm/assets/css/style.css/wp-content/plugins/fand-pickup-points-ultimate-edition-for-wcfm/assets/js/pickup-admin.js
Script Paths
/wp-content/plugins/fand-pickup-points-ultimate-edition-for-wcfm/assets/js/pickup-admin.js
Version Parameters
fand-pickup-points-ultimate-edition-for-wcfm/assets/css/style.css?ver=fand-pickup-points-ultimate-edition-for-wcfm/assets/js/pickup-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
fandpipo_mapfandpipo_info_window
HTML Comments
<!-- ON DÉCLARE LA FONCTION ICI (Avant le namespace pour qu'elle soit globale) --><!-- Fix pour l'erreur WooCommerce Subscriptions --><!-- Empêche l'accès direct au fichier --><!-- Conditions de chargement -->+15 more
Data Attributes
data-latdata-lngdata-zoomdata-iddata-namedata-category+4 more
JS Globals
fandpipo_pickup_datafandpipo_map_data
FAQ

Frequently Asked Questions about Fand Pickup Points : Ultimate Edition for WCFM