
Flexible Fees Manager for WooCommerce Security & Risk Analysis
wordpress.org/plugins/flexible-fees-manager-for-woocommerceAdd conditional fees to WooCommerce based on cart, products, shipping, payment methods, location, and more — without writing any code.
Is Flexible Fees Manager for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Flexible Fees Manager for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries by using prepared statements exclusively, and it has a clean vulnerability history with no known CVEs. The extensive use of nonce and capability checks (17 and 20 respectively) suggests an intent to implement security controls. However, a significant concern is the substantial attack surface created by 15 AJAX handlers, all of which lack authentication checks. This makes them prime targets for unauthenticated users to trigger potentially unintended actions. Furthermore, the taint analysis reveals 8 flows with unsanitized paths, though none reached a critical or high severity, indicating a potential for vulnerabilities if user input is not handled carefully in these flows.
While the absence of historical vulnerabilities is a positive indicator of past security diligence, it does not guarantee future security, especially given the current open attack vectors. The large number of unprotected AJAX endpoints is the most pressing issue. The high percentage of properly escaped outputs (80%) is good, but the remaining 20% could still lead to issues if sensitive data is involved. In conclusion, the plugin has some strong security fundamentals in place, but the lack of authentication on all AJAX handlers presents a significant and immediate risk that needs addressing.
Key Concerns
- All AJAX handlers lack authentication checks
- 8 taint flows with unsanitized paths
- 20% of outputs are not properly escaped
Flexible Fees Manager for WooCommerce Security Vulnerabilities
Flexible Fees Manager for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Flexible Fees Manager for WooCommerce Attack Surface
AJAX Handlers 15
WordPress Hooks 33
Maintenance & Trust
Flexible Fees Manager for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Flexible Fees Manager for WooCommerce Alternatives
Extra Fees for WooCommerce
woo-conditional-product-fees-for-checkout
Charge extra fees in cart, based on the combination of multiple conditional rules that you configure.
WooCommerce Product Fees
woocommerce-product-fees
WooCommerce Product Fees allows you to add additional fees at checkout based on products that are in the cart.
WooBooster Additional Charges for WooCommerce
wb-additional-charges-for-woocommerce
Our plugin will provide you option to add additional fees directly from the WordPress admin panel and display on the checkout page.
Extra Amount Option For WooCommerce Checkout (BASIC)
extra-amount-on-checkout
Auto apply extra amount on woocommerce checkout based on payment gateway, shipping, product category, product type, and individual product.
Product Fees Toolkit for WooCommerce
product-fees-toolkit-for-woocommerce
Add product-level fees in WooCommerce. Fixed or percentage per product or variation, with tax, quantity and coupon support.
Flexible Fees Manager for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect Flexible Fees Manager for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flexible-fees-manager-for-woocommerce/admin/css/ffmw-admin-style.css/wp-content/plugins/flexible-fees-manager-for-woocommerce/admin/js/ffmw-admin-script.js/wp-content/plugins/flexible-fees-manager-for-woocommerce/public/css/ffmw-public-style.css/wp-content/plugins/flexible-fees-manager-for-woocommerce/public/js/ffmw-public-script.js/wp-content/plugins/flexible-fees-manager-for-woocommerce/admin/js/ffmw-admin-script.js/wp-content/plugins/flexible-fees-manager-for-woocommerce/public/js/ffmw-public-script.jsflexible-fees-manager-for-woocommerce/admin/css/ffmw-admin-style.css?ver=flexible-fees-manager-for-woocommerce/admin/js/ffmw-admin-script.js?ver=flexible-fees-manager-for-woocommerce/public/css/ffmw-public-style.css?ver=flexible-fees-manager-for-woocommerce/public/js/ffmw-public-script.js?ver=HTML / DOM Fingerprints
ffmw-admin-containerffmw-noticeffmw-field-wrapperffmw-fees-tableffmw-fee-rowffmw-fee-fielddata-ffmw-iddata-ffmw-actionffmw_admin_paramsffmw_public_paramsffmw_var/wp-json/ffmw/v1/fees