Fermo!Point Woocommerce Security & Risk Analysis

wordpress.org/plugins/fermopoint-for-woocommerce

Tags: woocommerce, fermopoint, shipping Version: 1.3.1 Requires at least: 3.0.1 Tested up to: 4.9.6 Stable tag: 4.9.6 License: GPLv2 or later Licens …

10 active installs v1.3.1 PHP + WP + Updated Jun 20, 2018
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fermo!Point Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Fermo!Point Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "fermopoint-for-woocommerce" plugin version 1.3.1 exhibits a concerning security posture primarily due to its unprotected entry points. While the plugin demonstrates good practices in SQL query handling by exclusively using prepared statements and does not appear to bundle any libraries, its static analysis reveals a significant vulnerability. All six identified AJAX handlers lack authentication checks, presenting a wide attack surface for unauthenticated users. Furthermore, the output escaping is only at 35%, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities in the outputs of these unprotected AJAX handlers. The absence of any recorded historical vulnerabilities is a positive sign, suggesting the developers may be diligent, but it does not negate the critical flaws identified in the current code analysis. The lack of nonce checks on AJAX handlers compounds the risk, making it easier for attackers to trigger these endpoints with malicious intent. The plugin's strength lies in its clean SQL handling, but this is heavily overshadowed by the numerous unprotected entry points and poor output sanitization.

Key Concerns

  • AJAX handlers without authentication checks
  • Low percentage of properly escaped output
  • AJAX handlers without nonce checks
Vulnerabilities
None known

Fermo!Point Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Fermo!Point Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
33
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
12
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

35% escaped51 total outputs
Attack Surface
6 unprotected

Fermo!Point Woocommerce Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

noprivwp_ajax_callfermopointapipublic\class-fermopoint-public-legacy.php:111
authwp_ajax_callfermopointapipublic\class-fermopoint-public-legacy.php:113
authwp_ajax_resetfermopointpublic\class-fermopoint-public-legacy.php:115
noprivwp_ajax_resetfermopointpublic\class-fermopoint-public-legacy.php:117
authwp_ajax_currentpagepublic\class-fermopoint-public-legacy.php:121
noprivwp_ajax_currentpagepublic\class-fermopoint-public-legacy.php:123
WordPress Hooks 40
filterplugin_row_metaadmin\class-fermopoint-admin - Copia.php:135
actionwoocommerce_admin_order_data_after_shipping_addressadmin\class-fermopoint-admin - Copia.php:139
actionwoocommerce_order_status_changedadmin\class-fermopoint-admin - Copia.php:143
actionwoocommerce_email_before_order_tableadmin\class-fermopoint-admin - Copia.php:147
actionadmin_menuadmin\class-fermopoint-admin - Copia.php:151
actionwoocommerce_after_mini_cartadmin\class-fermopoint-admin - Copia.php:381
actionwoocommerce_shipping_initadmin\class-fermopoint-admin - Copia.php:761
filterwoocommerce_shipping_methodsadmin\class-fermopoint-admin - Copia.php:781
filterplugin_row_metaadmin\class-fermopoint-admin-legacy.php:135
actionwoocommerce_admin_order_data_after_shipping_addressadmin\class-fermopoint-admin-legacy.php:139
actionwoocommerce_order_status_changedadmin\class-fermopoint-admin-legacy.php:143
actionwoocommerce_email_before_order_tableadmin\class-fermopoint-admin-legacy.php:147
actionadmin_menuadmin\class-fermopoint-admin-legacy.php:151
actionwoocommerce_after_mini_cartadmin\class-fermopoint-admin-legacy.php:381
actionwoocommerce_shipping_initadmin\class-fermopoint-admin-legacy.php:761
filterwoocommerce_shipping_methodsadmin\class-fermopoint-admin-legacy.php:781
filterplugin_row_metaadmin\class-fermopoint-admin.php:77
actionwoocommerce_admin_order_data_after_shipping_addressadmin\class-fermopoint-admin.php:81
actionwoocommerce_email_before_order_tableadmin\class-fermopoint-admin.php:83
actionwoocommerce_order_status_failedadmin\class-fermopoint-admin.php:89
actionwoocommerce_order_status_processingadmin\class-fermopoint-admin.php:91
actionwoocommerce_order_status_completedadmin\class-fermopoint-admin.php:93
actionwoocommerce_order_status_refundedadmin\class-fermopoint-admin.php:95
actionwoocommerce_order_status_cancelledadmin\class-fermopoint-admin.php:97
actionwoocommerce_after_mini_cartadmin\class-fermopoint-admin.php:474
actionwoocommerce_shipping_initadmin\class-fermopoint-admin.php:635
filterwoocommerce_shipping_methodsadmin\class-fermopoint-admin.php:649
actionadmin_menuadmin\includes\settings-general-fermopoint.php:5
actionadmin_initadmin\includes\settings-general-fermopoint.php:9
actionadmin_initadmin\includes\settings-general-fermopoint.php:13
actionwoocommerce_before_order_notesfunction.php:69
actionplugins_loadedincludes\class-fermopoint.php:313
actionadmin_enqueue_scriptsincludes\class-fermopoint.php:343
actionadmin_enqueue_scriptsincludes\class-fermopoint.php:345
actionwp_enqueue_scriptsincludes\class-fermopoint.php:375
actionwp_enqueue_scriptsincludes\class-fermopoint.php:377
actionwoocommerce_checkout_fieldspublic\class-fermopoint-public-legacy.php:129
actionwoocommerce_checkout_update_order_metapublic\class-fermopoint-public-legacy.php:131
filterwoocommerce_ship_to_different_address_checkedpublic\class-fermopoint-public-legacy.php:601
actionwoocommerce_checkout_update_order_metapublic\class-fermopoint-public.php:213
Maintenance & Trust

Fermo!Point Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJun 20, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Fermo!Point Woocommerce Alternatives

No alternatives data available yet.

Developer Profile

Fermo!Point Woocommerce Developer Profile

digitalissimo

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fermo!Point Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fermopoint-for-woocommerce/css/fermopoint-admin.css/wp-content/plugins/fermopoint-for-woocommerce/js/fermopoint-admin.js
Script Paths
/wp-content/plugins/fermopoint-for-woocommerce/js/fermopoint-admin.js
Version Parameters
fermopoint-admin.css?ver=fermopoint-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
fermopoint-admin-css
Data Attributes
data-fermopoint-checkout
JS Globals
fermopoint_php_var
Shortcode Output
[fermopoint_checkout]
FAQ

Frequently Asked Questions about Fermo!Point Woocommerce