
Free Product Samples for WooCommerce – Try Before You Buy, Request Samples by Mail Security & Risk Analysis
wordpress.org/plugins/free-product-sampleAdvanced Product Sample for WooCommerce does one thing, and it does it well. It lets you order product as a product sample.
Is Free Product Samples for WooCommerce – Try Before You Buy, Request Samples by Mail Safe to Use in 2026?
Generally Safe
Score 100/100Free Product Samples for WooCommerce – Try Before You Buy, Request Samples by Mail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "free-product-sample" plugin v1.4.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, exclusively using prepared statements, and a high percentage of output escaping, indicating a general awareness of preventing common web vulnerabilities. The absence of known CVEs and vulnerabilities in its history is also a positive sign. However, the plugin presents a significant concern with its attack surface. Out of 11 identified entry points, a concerning 10 are AJAX handlers that lack proper authentication checks. This means that potentially sensitive actions could be triggered by unauthenticated users, creating a substantial risk of unauthorized operations or data manipulation. The analysis also shows that while nonce checks are present for all AJAX handlers, the lack of capability checks for these handlers is a critical oversight.
The taint analysis revealing no unsanitized paths or flows is reassuring, suggesting that data processed by the plugin is less likely to be exploited for remote code execution or command injection through typical input sanitization weaknesses. The presence of bundled libraries like Select2 and Freemius v1.0, while not inherently a security risk, does introduce a dependency on the security of those libraries, particularly Freemius v1.0 which might have its own security considerations depending on its implementation within the plugin. The limited number of external HTTP requests (4) is relatively low, reducing the risk of related vulnerabilities like SSRF. Overall, the plugin's strength lies in its data handling and output sanitization, but the extensive unprotected AJAX endpoints significantly overshadow these strengths, making it a considerable risk for unauthorized access and actions.
Key Concerns
- 10 AJAX handlers without auth checks
- 0 capability checks found
- Bundled Freemius v1.0 library
Free Product Samples for WooCommerce – Try Before You Buy, Request Samples by Mail Security Vulnerabilities
Free Product Samples for WooCommerce – Try Before You Buy, Request Samples by Mail Code Analysis
Bundled Libraries
Output Escaping
Free Product Samples for WooCommerce – Try Before You Buy, Request Samples by Mail Attack Surface
AJAX Handlers 10
Shortcodes 1
WordPress Hooks 57
Maintenance & Trust
Free Product Samples for WooCommerce – Try Before You Buy, Request Samples by Mail Maintenance & Trust
Maintenance Signals
Community Trust
Free Product Samples for WooCommerce – Try Before You Buy, Request Samples by Mail Alternatives
Free Product Sample for WooCommerce
woo-free-product-sample
The easy way to handle free product sample for WooCommerce. Promote your business in minutes!
Free Product for WooCommerce
free-product-for-woocommerce
Display FREE if WooCommerce Product Price is Zero or Empty.
Document Preview For WooCommerce
woo-document-preview
This will allow you to add document preview at single product page. Which helps to offer more better idea when you are selling ebooks, pdf or some doc …
Simple Product Sample
simple-product-sample-for-woocommerce
Add a button to "Request sample" on the WooCommerce product page. It is possible to activate the sample and configure its price for each product.
Stock Manager for WooCommerce
woocommerce-stock-manager
WooCommerce stock management plugin to manage and edit product stock and their variables from a single dashboard. Stock log, import/export, filters!
Free Product Samples for WooCommerce – Try Before You Buy, Request Samples by Mail Developer Profile
37 plugins · 95K total installs
How We Detect Free Product Samples for WooCommerce – Try Before You Buy, Request Samples by Mail
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/free-product-sample/assets/css/admin.css/wp-content/plugins/free-product-sample/assets/css/style.css/wp-content/plugins/free-product-sample/assets/js/admin.js/wp-content/plugins/free-product-sample/assets/js/frontend.js/wp-content/plugins/free-product-sample/assets/js/admin.js/wp-content/plugins/free-product-sample/assets/js/frontend.jsfree-product-sample/assets/css/admin.css?ver=free-product-sample/assets/css/style.css?ver=free-product-sample/assets/js/admin.js?ver=free-product-sample/assets/js/frontend.js?ver=HTML / DOM Fingerprints
dsfps-request-sample-buttondsfps-sample-added-noticedsfps-sample-request-form-wrapperdsfps-modal-wrapperdsfps-sample-product-galleryds-wizard-wrapds-wizard-content<!-- Start: Plugin Header --><!-- End: Plugin Header --><!-- Start: Setup Wizard Section --><!-- End: Setup Wizard Section -->+2 moredata-dsfps-product-iddata-dsfps-add-to-cart-urldata-dsfps-product-titledsfps_frontend_params/wp-json/free-product-sample/v1/add-to-cart/wp-json/free-product-sample/v1/request-sample[dsfps_sample_request_form][dsfps_product_samples]