
Flexible Quantity – Measurement Price Calculator for WooCommerce Security & Risk Analysis
wordpress.org/plugins/flexible-quantity-measurement-price-calculator-for-woocommerceWooCommerce price calculator. Sell products by unit, dimension or volume. Calculate quantity increment and final price for a new unit of measure.
Is Flexible Quantity – Measurement Price Calculator for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Flexible Quantity – Measurement Price Calculator for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "flexible-quantity-measurement-price-calculator-for-woocommerce" v2.3.15 presents a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and demonstrates good practices like utilizing prepared statements for a majority of its SQL queries and implementing nonce and capability checks on its entry points. The attack surface appears minimal and protected, with no REST API routes or cron events found, and the identified AJAX handler and shortcode are not explicitly listed as unprotected.
However, the static analysis reveals several significant concerns. The presence of dangerous functions such as 'assert', 'unserialize', 'proc_open', and 'shell_exec' is a red flag, indicating potential avenues for code execution or deserialization vulnerabilities if input is not rigorously sanitized. Furthermore, the taint analysis highlights two flows with unsanitized paths, rated as high severity, which could lead to the exploitation of these dangerous functions or other injection-like vulnerabilities. The fact that only 40% of output is properly escaped also raises concerns about potential cross-site scripting (XSS) vulnerabilities.
The plugin's vulnerability history is a strength, showing no recorded CVEs. This suggests either a historically secure codebase or potentially limited discovery of vulnerabilities, rather than an inherent guarantee of current security. In conclusion, while the plugin has a clean history and some good security implementations, the identified dangerous functions, unsanitized taint flows, and insufficient output escaping warrant careful attention and remediation.
Key Concerns
- High severity unsanitized taint flows
- Presence of dangerous functions (unserialize, shell_exec, etc.)
- Low percentage of properly escaped output
- Unsanitized paths in taint analysis
Flexible Quantity – Measurement Price Calculator for WooCommerce Security Vulnerabilities
Flexible Quantity – Measurement Price Calculator for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Flexible Quantity – Measurement Price Calculator for WooCommerce Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 89
Maintenance & Trust
Flexible Quantity – Measurement Price Calculator for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Flexible Quantity – Measurement Price Calculator for WooCommerce Alternatives
AForms — Form Builder for Price Calculator & Cost Estimation
aforms-form-builder-for-price-calculator-cost-estimation
Form builder for Cost estimation and Custom order.
SMNTCS Quantity Increment Buttons for WooCommerce
smntcs-woocommerce-quantity-buttons
Display the quantity increment buttons on the WooCommerce product page and the WooCommerce cart page.
Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator
stylish-cost-calculator
Cost calculator for WordPress: 🌟 Engage visitors and boost conversions with interactive calculations, lead capture, and payment integrations.
Maximum Products per User for WooCommerce
maximum-products-per-user-for-woocommerce
Limit number of items your WooCommerce customers can buy (lifetime or in selected date range).
ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators
convertcalculator
Easily build calculators for your landing pages and web applications with Convert_'s intuitive calculator builder.
Flexible Quantity – Measurement Price Calculator for WooCommerce Developer Profile
23 plugins · 127K total installs
How We Detect Flexible Quantity – Measurement Price Calculator for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/js/front.js/wp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/css/main.css/wp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/js/custom-units-page.js/wp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/js/product-options.jswp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/js/front.jswp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/js/custom-units-page.jswp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/js/product-options.js/wp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/js/front.js?ver=/wp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/css/main.css?ver=/wp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/js/custom-units-page.js?ver=/wp-content/plugins/flexible-quantity-measurement-price-calculator-for-woocommerce/vendor_prefixed/wpdesk/flexible-quantity-core/js/product-options.js?ver=HTML / DOM Fingerprints
fq-product-optionsTHIS VARIABLE CAN BE CHANGED AUTOMATICALLYdata-fq_product_iddata-fq_product_typefq_price_calculator_params