
Prices By User Role Lite Security & Risk Analysis
wordpress.org/plugins/prices-by-user-role-litePrices by User Role Lite it is a plugin designed to extend the default WooCommerce functionality by hiding Add to Cart button and product prices from …
Is Prices By User Role Lite Safe to Use in 2026?
Generally Safe
Score 85/100Prices By User Role Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "prices-by-user-role-lite" v1.0 plugin exhibits a generally positive security posture with no known historical vulnerabilities. The static analysis reveals a limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. Furthermore, the plugin does not perform file operations or make external HTTP requests, which are common vectors for attack. The use of prepared statements for all SQL queries is a significant strength, mitigating the risk of SQL injection vulnerabilities. The presence of a nonce check is also a good practice.
However, there are notable areas for improvement. The plugin's output escaping is poor, with only 20% of outputs properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is rendered without adequate sanitization. While no critical or high severity taint flows were detected, the analysis did reveal two flows with unsanitized paths, which warrants further investigation to understand their potential impact. The absence of capability checks on entry points, although the entry points themselves are currently zero, means that if future entry points are introduced without proper authorization, they would be vulnerable.
Given the lack of historical vulnerabilities and the absence of dangerous functions or raw SQL, the plugin appears to be developed with security in mind. The primary concerns stem from the weak output escaping and the identified unsanitized taint flows. A more robust approach to output sanitization and a thorough review of the unsanitized taint flows are recommended to further enhance the plugin's security.
Key Concerns
- Low output escaping coverage
- Unsanitized paths in taint flows
- No capability checks on entry points
Prices By User Role Lite Security Vulnerabilities
Prices By User Role Lite Code Analysis
Output Escaping
Data Flow Analysis
Prices By User Role Lite Attack Surface
Maintenance & Trust
Prices By User Role Lite Maintenance & Trust
Maintenance Signals
Community Trust
Prices By User Role Lite Alternatives
Add To Cart Button Customizations
add-to-cart-button-customizations
Add To Cart Button Customizations is a powerful WooCommerce extension that gives you complete control over your WooCommerce add to cart buttons.
Price & Cart Hider – WooCommerce Catalog Mode, Wholesale & B2B
price-cart-hider-for-woocommerce
Turn WooCommerce into Catalog Mode. Hide prices & Add to Cart. Perfect for Wholesale, B2B, and Members-only stores. No coding needed.
ELEX WooCommerce Catalog Mode
elex-woocommerce-catalog-mode
Easily turn your WooCommerce store into catalog mode with the best plugin designed for efficiency and effectiveness.
Product Enquiry for WooCommerce
gm-woocommerce-quote-popup
Allow customers to request quotes, send product enquiries, and run WooCommerce in catalog mode by hiding prices and replacing the Add to Cart button.
ELEX WooCommerce Role Based Pricing
elex-woocommerce-role-based-pricing-plugin-basic
Set User Role specific Prices to WooCommerce Products in your Store.
Prices By User Role Lite Developer Profile
1 plugin · 10 total installs
How We Detect Prices By User Role Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/prices-by-user-role-lite/assets/css/style.css/wp-content/plugins/prices-by-user-role-lite/assets/js/admin.js/wp-content/plugins/prices-by-user-role-lite/assets/js/front.js/wp-content/plugins/prices-by-user-role-lite/assets/js/admin.js/wp-content/plugins/prices-by-user-role-lite/assets/js/front.jsprices-by-user-role-lite/assets/css/style.css?ver=prices-by-user-role-lite/assets/js/admin.js?ver=prices-by-user-role-lite/assets/js/front.js?ver=HTML / DOM Fingerprints
festi-user-role-prices-top-border<!-- Premium Version --><!-- General Settings -->data-festi-user-role-prices-litepbr_admin_paramspbr_front_params