
Fand Pickup Points : Ultimate Edition for WCFM Security & Risk Analysis
wordpress.org/plugins/fand-pickup-points-ultimate-edition-for-wcfmWCFM Pickup Points allows each store on a marketplace to individualize their own pickup locations with custom opening hours.
Is Fand Pickup Points : Ultimate Edition for WCFM Safe to Use in 2026?
Generally Safe
Score 100/100Fand Pickup Points : Ultimate Edition for WCFM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "fand-pickup-points-ultimate-edition-for-wcfm" v1.0.3 exhibits a generally good security posture with several positive indicators. The presence of nonce checks on all AJAX handlers and capability checks on at least one entry point are strong security practices. The high percentage of SQL queries using prepared statements (83%) and properly escaped outputs (90%) further contribute to a robust defense against common web vulnerabilities like SQL injection and cross-site scripting. The absence of file operations and external HTTP requests at entry points also reduces potential attack vectors.
However, the taint analysis reveals specific areas of concern. Five out of seven analyzed flows have unsanitized paths, with two classified as high severity. This suggests potential vulnerabilities where user-supplied data might be processed in an unsafe manner, potentially leading to code execution or data manipulation if these flows are exposed to untrusted input. While the plugin has no recorded CVEs, the taint analysis findings should be treated as potential zero-day risks that require immediate attention and remediation. The presence of a bundled library, Select2, also warrants a check for its version and known vulnerabilities.
In conclusion, the plugin demonstrates a strong foundation in secure coding practices. Nevertheless, the high severity taint flows indicate a significant risk that overshadows the positive aspects. The lack of known vulnerabilities is reassuring but does not negate the risks identified through static and taint analysis. Prioritizing the remediation of the high severity taint flows is crucial to improving the plugin's overall security.
Key Concerns
- High severity taint flows found
- Unsanitized paths in taint flows
- Bundled library (Select2) requires version check
Fand Pickup Points : Ultimate Edition for WCFM Security Vulnerabilities
Fand Pickup Points : Ultimate Edition for WCFM Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Fand Pickup Points : Ultimate Edition for WCFM Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
Fand Pickup Points : Ultimate Edition for WCFM Maintenance & Trust
Maintenance Signals
Community Trust
Fand Pickup Points : Ultimate Edition for WCFM Alternatives
WCFM – WCFM Marketplace integrate Elementor
wc-frontend-manager-elementor
Create your marketplace store page using Elementor with your own design. Easily and Beatifully.
WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace
wc-frontend-manager-direct-paypal
Direct pay in vendor's PayPal account from customer account.
Dynamic Customer Shopping Tag for WooCommerce
dynamic-customer-shopping-tag-for-woocommerce
Show shipping tags on WooCommerce products based on vendor and customer country to improve transparency. = 2.1.4 = * Compatibility: Tested and verifie …
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
dokan-lite
Transform your WooCommerce site into a multivendor marketplace with Dokan – an AI powered & advanced WooCommerce marketplace solution
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
wc-frontend-manager
Vendor frontend store/shop manager for WC Marketplace, WC Vendors, WC Product Vendors & Dokan with Bookings, Listings & Subscriptions compatib …
Fand Pickup Points : Ultimate Edition for WCFM Developer Profile
3 plugins · 30 total installs
How We Detect Fand Pickup Points : Ultimate Edition for WCFM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fand-pickup-points-ultimate-edition-for-wcfm/assets/css/style.css/wp-content/plugins/fand-pickup-points-ultimate-edition-for-wcfm/assets/js/pickup-admin.js/wp-content/plugins/fand-pickup-points-ultimate-edition-for-wcfm/assets/js/pickup-admin.jsfand-pickup-points-ultimate-edition-for-wcfm/assets/css/style.css?ver=fand-pickup-points-ultimate-edition-for-wcfm/assets/js/pickup-admin.js?ver=HTML / DOM Fingerprints
fandpipo_mapfandpipo_info_window<!-- ON DÉCLARE LA FONCTION ICI (Avant le namespace pour qu'elle soit globale) --><!-- Fix pour l'erreur WooCommerce Subscriptions --><!-- Empêche l'accès direct au fichier --><!-- Conditions de chargement -->+15 moredata-latdata-lngdata-zoomdata-iddata-namedata-category+4 morefandpipo_pickup_datafandpipo_map_data