Fellow Lasku for WooCommerce Security & Risk Analysis

wordpress.org/plugins/fellow-lasku-for-woocommerce

Fellow Lasku on kuluttajamyyntiin tarkoitettu lasku- ja osamaksupalvelu. Maksutapa on kauppiaalle ilmainen ja tilitämme ostokset jo seuraavana arkipäi …

10 active installs v1.0.5 PHP 7.0+ WP 5.4+ Updated Jun 1, 2021
fellow-financefellow-laskupayment-gatewaywoocommerce-payment-gateway
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fellow Lasku for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Fellow Lasku for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin "fellow-lasku-for-woocommerce" v1.0.5 exhibits a mixed security posture. While the static analysis shows no direct vulnerabilities like dangerous functions, raw SQL queries, or critical taint flows, significant concerns arise from the lack of security checks on its entry points. The absence of nonce checks and capability checks on all identified entry points (even though the total is zero, this indicates a potential oversight if any were added later) is a notable weakness. Furthermore, a very low percentage of output escaping (8%) presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially with 13 output instances identified. The presence of file operations and external HTTP requests without explicit security checks also warrants caution, as these can be exploited if not handled securely.

The vulnerability history is positive, with no known CVEs recorded, which is a strong indicator of good historical security. However, this historical data should not be relied upon solely, given the concerning signals from the current static analysis. The lack of any taint flows analyzed might suggest the analysis tools were limited or the code structure didn't lend itself to such analysis, but it doesn't negate the risks identified by other means.

In conclusion, the plugin has a clean vulnerability history and avoids common pitfalls like raw SQL. However, the critical shortcomings in output escaping and the potential for unauthenticated actions due to missing capability and nonce checks present substantial security risks that require immediate attention. The file operations and external HTTP requests also require careful scrutiny.

Key Concerns

  • Low output escaping percentage
  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Fellow Lasku for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Fellow Lasku for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

8% escaped13 total outputs
Attack Surface

Fellow Lasku for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedfellow-lasku-for-woocommerce.php:40
actionadmin_enqueue_scriptsfellow-lasku-for-woocommerce.php:61
filterwoocommerce_payment_gatewaysfellow-lasku-for-woocommerce.php:67
actionsave_postfellow-lasku-for-woocommerce.php:107
actionwoocommerce_order_status_changedfellow-lasku-for-woocommerce.php:109
filterwoocommerce_available_payment_gatewaysfellow-lasku-for-woocommerce.php:112
actionwoocommerce_admin_order_data_after_order_detailsfellow-lasku-for-woocommerce.php:113
filterwoocommerce_gateway_iconfellow-lasku-for-woocommerce.php:114
filterwoocommerce_rest_api_get_rest_namespacesfellow-lasku-for-woocommerce.php:115
Maintenance & Trust

Fellow Lasku for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJun 1, 2021
PHP min version7.0
Downloads985

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Fellow Lasku for WooCommerce Developer Profile

fellowfinance

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fellow Lasku for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fellow-lasku-for-woocommerce/assets/fellow-finance.js
Script Paths
/wp-content/plugins/fellow-lasku-for-woocommerce/assets/fellow-finance.js

HTML / DOM Fingerprints

CSS Classes
fellow_lasku_marketing_link
Data Attributes
name="ff_action"value="ff_activate"name="woocommerce_fellow_finance_settings"
REST Endpoints
/wp-json/wc/v3/fellow_rest
FAQ

Frequently Asked Questions about Fellow Lasku for WooCommerce