Payment and Shipping Method Checkout Fee for WooCommerce Security & Risk Analysis

wordpress.org/plugins/payment-method-checkout-fee-for-woocommerce

Add a percentage or fixed fee to any WooCommerce payment method and shipping method at checkout.

300 active installs v2.1.0 PHP 8.0+ WP 6.2+ Updated May 15, 2026
checkoutfeepaymentshippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment and Shipping Method Checkout Fee for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Payment and Shipping Method Checkout Fee for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "payment-method-checkout-fee-for-woocommerce" plugin v2.0.1 exhibits a generally good security posture based on the provided static analysis. The absence of any registered AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis shows no dangerous functions, no raw SQL queries (all use prepared statements), no file operations, and no external HTTP requests. This indicates a careful implementation regarding common web application vulnerabilities.

However, a notable concern is the low percentage (35%) of properly escaped output. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly rendered without adequate sanitization. The absence of nonce checks and capability checks on any entry points (since there are none) is understandable but also means there's no demonstrated practice of implementing these critical security measures. The vulnerability history being completely clear is a strong positive indicator, suggesting the developers have historically maintained a secure codebase.

In conclusion, while the plugin has a very small attack surface and avoids several common pitfalls like raw SQL and dangerous functions, the unescaped output is a weakness that warrants attention. The lack of any recorded vulnerabilities in its history is a significant strength. The overall risk is moderate, primarily due to the potential for XSS if sensitive data is handled improperly.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Payment and Shipping Method Checkout Fee for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Payment and Shipping Method Checkout Fee for WooCommerce Release Timeline

v2.1.0Current
v2.0.1
v2.0.0
Code Analysis
Analyzed Mar 16, 2026

Payment and Shipping Method Checkout Fee for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

35% escaped17 total outputs
Attack Surface

Payment and Shipping Method Checkout Fee for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptscheckoutfee.php:58
filterwoocommerce_settings_tabs_arraycheckoutfee.php:80
actionwoocommerce_settings_tabs_checkout_feecheckoutfee.php:81
actionwoocommerce_update_options_checkout_feecheckoutfee.php:82
actionwp_loadedcheckoutfee.php:189
actionwoocommerce_cart_calculate_feescheckoutfee.php:249
actionwoocommerce_after_checkout_formcheckoutfee.php:256
Maintenance & Trust

Payment and Shipping Method Checkout Fee for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedMay 15, 2026
PHP min version8.0
Downloads7K

Community Trust

Rating100/100
Number of ratings5
Active installs300
Developer Profile

Payment and Shipping Method Checkout Fee for WooCommerce Developer Profile

Ivan Popov

3 plugins · 310 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment and Shipping Method Checkout Fee for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-method-checkout-fee-for-woocommerce/assets/css/admin_css.css/wp-content/plugins/payment-method-checkout-fee-for-woocommerce/assets/js/admin-settings.js
Script Paths
/wp-content/plugins/payment-method-checkout-fee-for-woocommerce/assets/js/admin-settings.js
Version Parameters
payment-method-checkout-fee-for-woocommerce/assets/css/admin_css.css?ver=payment-method-checkout-fee-for-woocommerce/assets/js/admin-settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
woocommerce_page_wc-settingswc-tab-checkout_fee
Data Attributes
id="wc_settings_tab_demo_section_end"id="wc_settings_id="wc_settings_tab_checkout_fee"id="_name_label"id="_fee_type"id="_name_percent"
FAQ

Frequently Asked Questions about Payment and Shipping Method Checkout Fee for WooCommerce