
Hide Price Until Login Security & Risk Analysis
wordpress.org/plugins/hide-price-until-loginHide product price until the correct password is entered or until login.
Is Hide Price Until Login Safe to Use in 2026?
Generally Safe
Score 85/100Hide Price Until Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hide-price-until-login" plugin v1.1.1 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers, representing its entire attack surface. While the plugin demonstrates good practices in its handling of SQL queries (100% prepared statements) and avoids dangerous functions, these strengths are overshadowed by the lack of authentication checks on all its entry points.
The static analysis reveals that all 7 AJAX handlers lack authentication. This means any unauthenticated user could potentially trigger these handlers, opening up possibilities for various attacks if the handlers perform sensitive actions or expose information. The taint analysis, while not revealing critical or high severity flows, does indicate 4 flows with unsanitized paths, which, combined with the unprotected AJAX handlers, represents a significant risk. The external HTTP request also warrants attention, as it could be a vector for further compromise if not handled securely.
The vulnerability history of this plugin is notably clean, with no recorded CVEs. This absence of past vulnerabilities is positive, suggesting a historical tendency towards secure coding. However, the current code analysis reveals immediate and substantial risks that are not mitigated by past performance. The plugin's overall security is weakened by its extensive unprotected attack surface, despite its good SQL practices and lack of past vulnerabilities.
Key Concerns
- All AJAX handlers are unprotected
- Significant number of unprotected entry points
- Taint flows with unsanitized paths (4 total)
- External HTTP request present
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
- Output escaping at 56% is not ideal
Hide Price Until Login Security Vulnerabilities
Hide Price Until Login Release Timeline
Hide Price Until Login Code Analysis
Output Escaping
Data Flow Analysis
Hide Price Until Login Attack Surface
AJAX Handlers 7
WordPress Hooks 77
Maintenance & Trust
Hide Price Until Login Maintenance & Trust
Maintenance Signals
Community Trust
Hide Price Until Login Alternatives
CedCommerce Connector for Miravia
cedcommerce-connector-for-miravia
This plugin enables seamless integration with Miravia, providing advanced features like managing products listing and order synchronization.
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
EmailKit – Email Customizer for WooCommerce & WP
emailkit
EmailKit is a powerful WordPress and WooCommerce email customizer tool, free for everyone! It allows users to customize and design templates that show …
reGenerate Thumbnails Advanced
regenerate-thumbnails-advanced
Regenerate thumbnails quickly and easily, including forced regeneration; very useful when changing a theme or adding new thumbnail sizes.
Brave Popup Builder – Popup, Optins, Lead Generation, Survey & Interactive Content
brave-popup-builder
The best drag-and-drop Popup Builder for WordPress. Create Popups, exit-intent popups, slide-ins, and lead generation forms & Woocommerce popups i …
Hide Price Until Login Developer Profile
25 plugins · 5K total installs
How We Detect Hide Price Until Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hide-price-until-login/assets/js/ced_hide_price_until_login.min.js/wp-content/plugins/hide-price-until-login/assets/css/hide_tbl.css/wp-content/plugins/hide-price-until-login/assets/css/pop_up.css/wp-content/plugins/hide-price-until-login/assets/css/pop_up.min.css/wp-content/plugins/hide-price-until-login/assets/css/hide_tbl.min.css/wp-content/plugins/hide-price-until-login/assets/js/ced_hide_price.min.jshttps://www.google.com/recaptcha/api.jshide-price-until-login/assets/js/ced_hide_price_until_login.min.js?ver=hide-price-until-login/assets/js/ced_hide_price.min.js?ver=HTML / DOM Fingerprints
g-recaptchadata-sitekeyglobalsglobal