
NS Free Price and Donation for WooCommerce Security & Risk Analysis
wordpress.org/plugins/ns-free-price-and-donation-for-woocommerceLet user can pay how much they like by setting one or more product with this plugin
Is NS Free Price and Donation for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100NS Free Price and Donation for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'ns-free-price-and-donation-for-woocommerce' version 2.4.4 exhibits a concerning security posture primarily due to its unprotected entry points. The analysis reveals two AJAX handlers that lack any authentication or capability checks. This means that any user, including unauthenticated visitors, could potentially trigger these handlers, leading to unintended actions or information disclosure. The taint analysis also indicates two flows with unsanitized paths, which, while not classified as critical or high severity in this specific scan, warrant attention as they represent potential avenues for injection attacks if the data is not handled meticulously within the AJAX handlers.
Despite these significant concerns with the attack surface, the plugin demonstrates good practices in other areas. It shows no dangerous functions being used, all SQL queries are properly prepared, and there are no file operations or bundled libraries to worry about. The external HTTP requests are also a minimal concern in isolation. The plugin's history is also clean, with no recorded vulnerabilities, suggesting that past versions may have been more secure or that the current issues have not yet been exploited. However, the presence of unprotected AJAX endpoints creates a substantial risk that cannot be ignored. The conclusion is that while the plugin has some strengths, the unprotected entry points represent a critical weakness that significantly lowers its overall security.
Key Concerns
- AJAX handlers without auth checks
- Taint flow with unsanitized path
- Missing nonce checks on AJAX
- Low output escaping percentage
- Missing capability checks on AJAX
NS Free Price and Donation for WooCommerce Security Vulnerabilities
NS Free Price and Donation for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
NS Free Price and Donation for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 19
Maintenance & Trust
NS Free Price and Donation for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
NS Free Price and Donation for WooCommerce Alternatives
Donation Platform for WooCommerce: Fundraising & Donation Management
wc-donation-platform
Open source donation system for your fundraising that supports recurring donations and more
Donation or Tip For WooCommerce
donation-or-tip-for-woocommerce
Add a customizable donation or tip field to your WooCommerce cart and checkout page. Support fixed amounts, percentage tips, and custom input — no cod …
Simple checkout page donations/tips for WooCommerce
simple-checkout-page-donationstips-for-woocommerce
This plugin lets you add custom tips for display in the checkout page. These tips are optional for the customer to add to the cart fee.
Simple Donation For Woo Lite
simple-donation-for-woo-lite
Accept donations for WooCommerce-powered eCommerce site. This plugin will add powerful donation functionality to your website.
Potent Donations for WooCommerce
donations-for-woocommerce
Easily accept donations of varying amounts through your WooCommerce store.
NS Free Price and Donation for WooCommerce Developer Profile
24 plugins · 4K total installs
How We Detect NS Free Price and Donation for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ns-free-price-and-donation-for-woocommerce/css/ns-free-price-and-donation-for-woocommerce-admin.css/wp-content/plugins/ns-free-price-and-donation-for-woocommerce/css/ns-free-price-and-donation-for-woocommerce.cssHTML / DOM Fingerprints
ns-free-price-and-donation-for-woocommerce-adminns_gift_price_custom_tab