
ingenidev Small Order Fee Security & Risk Analysis
wordpress.org/plugins/ingenidev-small-order-feeNEW Plugin! This Plugin allows you to put in place a small order fee and configure the threshold as well as the value of the fee.
Is ingenidev Small Order Fee Safe to Use in 2026?
Generally Safe
Score 100/100ingenidev Small Order Fee has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ingenidev-small-order-fee' plugin, in version 1.0.2, demonstrates a generally good security posture regarding common WordPress vulnerabilities. The code analysis indicates a lack of dangerous functions, all SQL queries use prepared statements, and all identified outputs are properly escaped. Furthermore, there are no recorded vulnerabilities (CVEs) for this plugin, suggesting a history of stable and secure development. The absence of file operations and external HTTP requests also limits potential attack vectors.
However, a significant concern is the presence of one AJAX handler that lacks authentication checks. This represents a direct, unprotected entry point into the plugin's functionality. While no critical or high-severity taint flows were identified, and no explicit capability checks are missing, this single unprotected AJAX endpoint could potentially be exploited by an authenticated user (or in certain scenarios, even an unauthenticated one depending on the handler's logic) to perform unintended actions. The lack of nonce checks on this AJAX handler further exacerbates this risk, as it makes the endpoint susceptible to Cross-Site Request Forgery (CSRF) attacks.
In conclusion, while the plugin's codebase is largely free from common pitfalls like unescaped output or raw SQL, the unprotected AJAX handler is a critical weakness. This single entry point, combined with the absence of nonce checks, requires immediate attention to secure the plugin against potential exploitation.
Key Concerns
- AJAX handler without auth checks
- AJAX handler without nonce checks
ingenidev Small Order Fee Security Vulnerabilities
ingenidev Small Order Fee Code Analysis
Output Escaping
ingenidev Small Order Fee Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
ingenidev Small Order Fee Maintenance & Trust
Maintenance Signals
Community Trust
ingenidev Small Order Fee Alternatives
RSS Links Manager
rss-links-manager
Manage and customise your RSS feed links.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
ingenidev Small Order Fee Developer Profile
11 plugins · 1K total installs
How We Detect ingenidev Small Order Fee
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ingenidev-small-order-fee/js/ingenidev_sof_dismiss_notice.js/wp-content/plugins/ingenidev-small-order-fee/js/ingenidev_sof_dismiss_notice.jsingenidev-small-order-fee/js/ingenidev_sof_dismiss_notice.js?ver=1.0.0HTML / DOM Fingerprints
notice-successis-dismissibleingenidev-welcome-noticename="ingenidev_sof_minimum_order_amount"name="ingenidev_sof_small_order_fee"ingenidev_sof_ajax_obj/wp-json/ingenidev_sof_dismiss_welcome_notice