
NF Conditional Actions Security & Risk Analysis
wordpress.org/plugins/nf-conditional-actionsNF Conditional Actions adds a action type for conditional messages or emails.
Is NF Conditional Actions Safe to Use in 2026?
Generally Safe
Score 85/100NF Conditional Actions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'nf-conditional-actions' v2.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerability history, suggesting a proactive approach to security or a lack of past exploitation. However, significant concerns arise from the static analysis. The presence of two unprotected AJAX handlers creates a substantial attack surface, making these entry points vulnerable to unauthorized execution of plugin functions. Furthermore, the use of the `unserialize` function, flagged as a dangerous function, introduces the potential for remote code execution if improperly handled or if attacker-controlled serialized data can be introduced. The low percentage of properly escaped output also indicates a risk of cross-site scripting (XSS) vulnerabilities.
While the lack of known CVEs and taint analysis issues is encouraging, the identified weaknesses in AJAX handler authentication and the use of `unserialize` are critical. The plugin needs immediate attention to secure its AJAX endpoints and review its usage of `unserialize` to mitigate potential security risks. The absence of nonce checks and capability checks further exacerbates the vulnerabilities presented by the unprotected AJAX handlers.
Key Concerns
- Unprotected AJAX handlers present significant risk
- Use of dangerous unserialize function
- Low percentage of properly escaped output
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
NF Conditional Actions Security Vulnerabilities
NF Conditional Actions Release Timeline
NF Conditional Actions Code Analysis
Dangerous Functions Found
Output Escaping
NF Conditional Actions Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
NF Conditional Actions Maintenance & Trust
Maintenance Signals
Community Trust
NF Conditional Actions Alternatives
Sectors – Conditional Templates & Hooks
sectors
What if you could add templates, actions, and filters depending on the context?
Complianz – Terms and Conditions
complianz-terms-conditions
Configure your own Terms and Conditions specific to your service or webshop.
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
iubenda-cookie-law-solution
The solution for GDPR compliance + more. Get your cookie banner, privacy policy, terms and conditions and handle cookie consent in just one plugin.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
NF Conditional Actions Developer Profile
2 plugins · 20 total installs
How We Detect NF Conditional Actions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nf-conditional-actions/css/nf-conditional-actions-no-js-style.css/wp-content/plugins/nf-conditional-actions/js/nf-conditional-actions-script.js/wp-content/plugins/nf-conditional-actions/js/nf-conditional-actions-script.jsnf-conditional-actions/js/nf-conditional-actions-script.js?ver=HTML / DOM Fingerprints
nf-tokenizedata-token-limitdata-keydata-typenf_conditional_actions