
ShopBoost – WooCommerce Toolkit Security & Risk Analysis
wordpress.org/plugins/flexible-minimum-orderWooCommerce toolkit with minimum order amounts, auto-add products, and direct checkout links. Increase order value with modern admin interface.
Is ShopBoost – WooCommerce Toolkit Safe to Use in 2026?
Generally Safe
Score 100/100ShopBoost – WooCommerce Toolkit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'flexible-minimum-order' v1.4.1 demonstrates a generally good security posture with several strong security practices in place. The absence of known CVEs and a complete lack of unpatched vulnerabilities in its history is a very positive sign, suggesting a mature and well-maintained codebase. The code analysis also reveals a robust implementation of security features, with all identified entry points (AJAX handlers, REST API routes, shortcodes) having appropriate authentication and permission checks. Furthermore, the high percentage of properly escaped output and a significant portion of SQL queries utilizing prepared statements indicate a conscious effort to prevent common web vulnerabilities like Cross-Site Scripting (XSS) and SQL Injection. The presence of numerous nonce and capability checks further reinforces this strong security foundation.
However, a closer look at the taint analysis reveals a single flow with unsanitized paths, categorized as high severity. While this is a solitary finding and not a critical one, it still represents a potential security risk that should not be overlooked. The presence of file operations, even without specific details on their nature, warrants careful review to ensure they are not susceptible to path traversal or other manipulation. The attack surface is moderate with 16 AJAX handlers, and while they are reported as having auth checks, a deeper dive into the implementation of these checks is always recommended to ensure they are truly robust against all attack vectors. Overall, the plugin is in good shape, but the single high-severity taint flow necessitates attention to mitigate any potential exploit.
Key Concerns
- High severity unsanitized path taint flow
ShopBoost – WooCommerce Toolkit Security Vulnerabilities
ShopBoost – WooCommerce Toolkit Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ShopBoost – WooCommerce Toolkit Attack Surface
AJAX Handlers 16
Shortcodes 2
WordPress Hooks 67
Maintenance & Trust
ShopBoost – WooCommerce Toolkit Maintenance & Trust
Maintenance Signals
Community Trust
ShopBoost – WooCommerce Toolkit Alternatives
Single Product in Cart
single-product-in-cart
Allows only one product in the WooCommerce cart at a time. When a new product is added, it replaces the existing product without any warning.
Auto Register for WooCommerce
auto-register-for-woocommerce
Once activated, Auto Register for WooCommerce will create a WordPress user account for your customer
Minimum Order Value for WooCommerce
minimum-order-value-for-woocommerce
Set a minimum order amount for WooCommerce with customizable cart/checkout messages and product/category exclusions.
One Click Buy Now Button
one-click-buy-now-button
Add a fully customizable "Buy Now" button under WooCommerce Add to Cart. Secure, lightweight and works with both simple and variable products.
Minimum order for WooCommerce
pedido-minimo-for-woocommerce
Set a minimum order amount in your WooCommerce store to be able to check out. Simple, lightweight, and effective.
ShopBoost – WooCommerce Toolkit Developer Profile
3 plugins · 10 total installs
How We Detect ShopBoost – WooCommerce Toolkit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flexible-minimum-order/assets/css/admin.css/wp-content/plugins/flexible-minimum-order/assets/css/frontend.css/wp-content/plugins/flexible-minimum-order/assets/js/admin.js/wp-content/plugins/flexible-minimum-order/assets/js/frontend.js/wp-content/plugins/flexible-minimum-order/assets/js/admin.js/wp-content/plugins/flexible-minimum-order/assets/js/frontend.jsflexible-minimum-order/assets/css/admin.css?ver=flexible-minimum-order/assets/css/frontend.css?ver=flexible-minimum-order/assets/js/admin.js?ver=flexible-minimum-order/assets/js/frontend.js?ver=HTML / DOM Fingerprints
flexmior-cart-noticeflexmior-minimum-order-noticedata-flexmior-amountdata-flexmior-messageFLEXMIOR_ADMIN_DATAFLEXMIOR_FRONTEND_DATA