FFL Checkout by Texas Technology Group Security & Risk Analysis

wordpress.org/plugins/ffl-checkout-by-ttg-for-woocommerce

FFL Checkout plugin by Texas Technology Group links FFLs.com to WooCommerce for FFL-required items, and lets users manually upload their FFL license.

20 active installs v2.0.12 PHP 7.4+ WP 6.0+ Updated Jul 17, 2025
e-commerce-checkoutffl-checkoutffl-gun-dealersgun-dealermap
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FFL Checkout by Texas Technology Group Safe to Use in 2026?

Generally Safe

Score 100/100

FFL Checkout by Texas Technology Group has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "ffl-checkout-by-ttg-for-woocommerce" plugin v2.0.12 exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals show no dangerous functions, all SQL queries utilize prepared statements, and output escaping is nearly perfect. The taint analysis reveals no critical or high severity unsanitized flows, indicating that user-supplied data is handled with care.

While the plugin demonstrates good development practices, two external HTTP requests are a minor point of consideration. While not inherently insecure, they represent potential points of failure or compromise if the external services are affected or malicious. The plugin's vulnerability history is a significant strength, with zero recorded CVEs, suggesting a commitment to security and thoroughness in previous development cycles. This, combined with the strong static analysis, paints a picture of a well-secured plugin. The lack of capability checks is a potential concern, but given the extremely limited attack surface and lack of direct user input handling in exposed endpoints, the immediate risk appears low.

Key Concerns

  • External HTTP requests present
  • No capability checks on entry points
Vulnerabilities
None known

FFL Checkout by Texas Technology Group Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FFL Checkout by Texas Technology Group Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
131 escaped
Nonce Checks
6
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

98% escaped133 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
<api-key> (admin\pages\api-key.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FFL Checkout by Texas Technology Group Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 26
actionbefore_woocommerce_initffl-checkout-by-ttg-for-woocommerce.php:75
actionblock_categories_allffl-checkout-by-ttg-for-woocommerce.php:117
actionplugins_loadedincludes\plugin.php:109
actionadmin_enqueue_scriptsincludes\plugin.php:123
actionadmin_enqueue_scriptsincludes\plugin.php:124
actionadmin_menuincludes\plugin.php:126
actionwoocommerce_product_options_general_product_dataincludes\plugin.php:129
actionwoocommerce_process_product_metaincludes\plugin.php:130
actionwoocommerce_product_options_general_product_dataincludes\plugin.php:131
filterbulk_actions-edit-productincludes\plugin.php:134
filterhandle_bulk_actions-edit-productincludes\plugin.php:135
filtermanage_edit-product_columnsincludes\plugin.php:138
actionmanage_product_posts_custom_columnincludes\plugin.php:139
actionadd_meta_boxesincludes\plugin.php:142
actionadmin_noticesincludes\plugin.php:145
actionwp_enqueue_scriptsincludes\plugin.php:159
actionwoocommerce_after_checkout_validationincludes\plugin.php:161
actionwoocommerce_before_checkout_formincludes\plugin.php:162
filterrender_block_woocommerce/checkout-contact-information-blockincludes\plugin.php:164
actionwoocommerce_checkout_create_orderincludes\plugin.php:166
actionwoocommerce_store_api_checkout_update_order_from_requestincludes\plugin.php:167
filterwoocommerce_checkout_fieldsincludes\plugin.php:169
filterwoocommerce_checkout_get_valueincludes\plugin.php:170
actionwoocommerce_email_after_order_tableincludes\plugin.php:172
actionwoocommerce_blocks_loadedincludes\plugin.php:174
actionwoocommerce_blocks_checkout_block_registrationpublic\public.php:228
Maintenance & Trust

FFL Checkout by Texas Technology Group Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 17, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings5
Active installs20
Developer Profile

FFL Checkout by Texas Technology Group Developer Profile

Texas Technology Group

2 plugins · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FFL Checkout by Texas Technology Group

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ffl-checkout-by-ttg-for-woocommerce/assets/css/admin.css/wp-content/plugins/ffl-checkout-by-ttg-for-woocommerce/assets/js/ffl-checkout-by-ttg.js/wp-content/plugins/ffl-checkout-by-ttg-for-woocommerce/assets/js/admin.js
Script Paths
/wp-content/plugins/ffl-checkout-by-ttg-for-woocommerce/assets/js/ffl-checkout-by-ttg.js/wp-content/plugins/ffl-checkout-by-ttg-for-woocommerce/assets/js/admin.js
Version Parameters
ffl-checkout-by-ttg-for-woocommerce/assets/css/admin.css?ver=ffl-checkout-by-ttg-for-woocommerce/assets/js/ffl-checkout-by-ttg.js?ver=ffl-checkout-by-ttg-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ffl-checkout-by-ttg-requires-checkout
HTML Comments
<!-- FFL Checkout block by TTG -->
Data Attributes
data-ffl-checkout-requiredata-ffl-checkout-sot-license-require
JS Globals
FFLCheckoutByTTG
FAQ

Frequently Asked Questions about FFL Checkout by Texas Technology Group