
g-FFL Cockpit Security & Risk Analysis
wordpress.org/plugins/g-ffl-cockpitBuilt by a FFL, for FFL's. Automate inventory synchronization and order fulfillment with multiple distributors.
Is g-FFL Cockpit Safe to Use in 2026?
Generally Safe
Score 98/100g-FFL Cockpit has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'g-ffl-cockpit' v2.0.6 plugin demonstrates a generally good security posture with a low attack surface and strong adherence to best practices in areas like SQL query preparation and output escaping. The static analysis reveals a very low number of unprotected entry points, which is commendable. However, the absence of nonce checks across all entry points is a significant concern, potentially leaving the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks if any of its actions are sensitive. While taint analysis found no critical or high severity flows, the plugin's history of two medium-severity vulnerabilities, specifically related to improper authorization and missing authorization, warrants attention. These past issues, even if currently patched, suggest a pattern where authorization logic might be a recurring weak point. The presence of bundled libraries like Select2 and TinyMCE, while common, adds a dependency that could introduce vulnerabilities if not kept up-to-date by the plugin developer.
Key Concerns
- Missing nonce checks on entry points
- History of medium severity authorization vulnerabilities
- Bundled libraries (Select2, TinyMCE)
g-FFL Cockpit Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion
g-FFL Cockpit <= 1.7.1 - Missing Authorization to Unauthenticated Information Exposure
g-FFL Cockpit Release Timeline
g-FFL Cockpit Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
g-FFL Cockpit Attack Surface
REST API Routes 22
WordPress Hooks 31
Maintenance & Trust
g-FFL Cockpit Maintenance & Trust
Maintenance Signals
Community Trust
g-FFL Cockpit Alternatives
Automatic FFL
automatic-ffl-for-wc
Sell firearms on WooCommerce? Add FFL dealer selection to checkout with an interactive map. ATF-validated, block checkout ready.
eCheckpoint
echeckpoint
Robust compliance checks for firearms eCommerce. Verifies whether your customers can purchase products based on federal, state, and local sales laws.
Shiptastic for WooCommerce
shiptastic-for-woocommerce
Shiptastic for WooCommerce is your all-in-one shipping and fulfillment solution for WooCommerce.
Advance Bank Payment Transfer Gateway
advance-bank-payment-transfer-gateway
Short Description: This plugin clones the Direct Bank Transfer gateway to create another offline payment method. License: GPLv2 or later
eCommerce Shipping Dashboard by UPS for WooCommerce
ecommerce-shipping-dashboard-by-ups-for-woocommerce
Connect your WooCommerce Store to all the UPS Services you require and manage your orders, shipments and labels in your Shipping Dashboard.
g-FFL Cockpit Developer Profile
2 plugins · 1K total installs
How We Detect g-FFL Cockpit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/g-ffl-cockpit/assets/css/ffl-cockpit.css/wp-content/plugins/g-ffl-cockpit/assets/js/ffl-cockpit.js/wp-content/plugins/g-ffl-cockpit/assets/js/ffl-cockpit.js/wp-content/plugins/g-ffl-cockpit/assets/css/ffl-cockpit.css?ver=/wp-content/plugins/g-ffl-cockpit/assets/js/ffl-cockpit.js?ver=HTML / DOM Fingerprints
data-ffl-cockpit-api-urldata-ffl-cockpit-site-iddata-ffl-cockpit-site-tokenFFLCockpitSyncEndpointGFFLCockpitCart/wp-json/g-ffl-cockpit/v1/sync/wp-json/g-ffl-cockpit/v1/cart