
g-FFL Checkout Security & Risk Analysis
wordpress.org/plugins/g-ffl-checkoutBuilt by a FFL, for FFL's. This plugin will add a FFL search & selection widget to your checkout page for products requiring FFL Shipment.
Is g-FFL Checkout Safe to Use in 2026?
Generally Safe
Score 94/100g-FFL Checkout has a strong security track record. Known vulnerabilities have been patched promptly.
The g-ffl-checkout v2.1.4 plugin exhibits a mixed security posture. While it demonstrates good practices in output escaping (92% properly escaped) and has a relatively low number of critical taint flows, several areas raise significant concerns. The plugin has a substantial attack surface with 14 unprotected AJAX handlers, representing a considerable risk for unauthorized actions. The complete absence of prepared statements for its single SQL query is a major vulnerability that could lead to SQL injection attacks. The plugin's vulnerability history includes one critical CVE related to unrestricted file uploads with dangerous types, and while it is currently patched, this pattern suggests potential for similar vulnerabilities if not rigorously monitored. The presence of file operations and external HTTP requests also warrants careful scrutiny to ensure these functions are not exploited.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
- Critical CVE in history (Unrestricted Upload)
g-FFL Checkout Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
g-FFL Checkout <= 2.1.0 - Unauthenticated Arbitrary File Upload
g-FFL Checkout Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
g-FFL Checkout Attack Surface
AJAX Handlers 43
WordPress Hooks 52
Scheduled Events 2
Maintenance & Trust
g-FFL Checkout Maintenance & Trust
Maintenance Signals
Community Trust
g-FFL Checkout Alternatives
FFL Dealers
ff-dealers
FFL Dealers simplifies the checkout phase on online gun stores that can implement user-friendly features for the benefit to the dealers and their cus …
Advance Bank Payment Transfer Gateway
advance-bank-payment-transfer-gateway
Short Description: This plugin clones the Direct Bank Transfer gateway to create another offline payment method. License: GPLv2 or later
g-FFL Cockpit
g-ffl-cockpit
Built by a FFL, for FFL's. Automate inventory synchronization and order fulfillment with multiple distributors.
Raffle Ticket Generator – Woocommerce
raffle-ticket-generator
This plugin is used with WooCommerce to generate raffle ticket numbers that are emailed to customers.
Phone Order Gateway for WooCommerce
woocommerce-phone-order-gateway
This plugin adds Phone Order gateway to the WooCommerce plugin.
g-FFL Checkout Developer Profile
2 plugins · 1K total installs
How We Detect g-FFL Checkout
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/g-ffl-checkout/admin/css/ffl-api-admin.cssg-ffl-checkout/admin/css/ffl-api-admin.css?ver=g-ffl-api?ver=HTML / DOM Fingerprints
ffl-api-settingsdata-g-ffl-api-fieldg_ffl_api_params/wp-json/g-ffl-api/v1/ffl/check/wp-json/g-ffl-api/v1/ffl/submit/wp-json/g-ffl-api/v1/ffl/upload/wp-json/g-ffl-api/v1/ffl/get/wp-json/g-ffl-api/v1/ffl/delete/wp-json/g-ffl-api/v1/ffl/bulk_delete/wp-json/g-ffl-api/v1/documents/upload/wp-json/g-ffl-api/v1/documents/download/wp-json/g-ffl-api/v1/documents/admin/download/wp-json/g-ffl-api/v1/documents/admin/upload/wp-json/g-ffl-api/v1/documents/admin/delete/wp-json/g-ffl-api/v1/documents/admin/delete_admin/wp-json/g-ffl-api/v1/cleanup/now/wp-json/g-ffl-api/v1/cleanup/stats/wp-json/g-ffl-api/v1/blacklist/search/wp-json/g-ffl-api/v1/blacklist/add/wp-json/g-ffl-api/v1/blacklist/remove/wp-json/g-ffl-api/v1/blacklist/get/wp-json/g-ffl-api/v1/blacklist/bulk_remove