Prices Only Members for Woocommerce Security & Risk Analysis

wordpress.org/plugins/prices-only-members-for-woocommerce

Prices Only Members for Woocommerce allows you to display the prices only to registered users.

10 active installs v1.0.1 PHP + WP 3.0.1+ Updated Mar 18, 2017
members-onlypricesprices-only-memberswoocommercewoocommerce-prices
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Prices Only Members for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Prices Only Members for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The security posture of "prices-only-members-for-woocommerce" v1.0.1 appears to be mixed, with some positive indicators but also significant areas of concern. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and demonstrates good practices by exclusively using prepared statements for its SQL queries and having no external HTTP requests or file operations. The attack surface is also relatively small, with no unprotected entry points identified in the static analysis, and there are no reported critical or high severity taint flows.

However, the static analysis reveals a critical weakness: 100% of the output is not properly escaped. This means that any data displayed to users, especially if it originates from user input or external sources, is vulnerable to Cross-Site Scripting (XSS) attacks. While the plugin lacks certain security checks like nonce and capability checks on its entry points, the absence of direct data flow analysis (taint analysis) and the small number of entry points might mitigate immediate risks in this specific version. The lack of recorded vulnerabilities historically is a positive sign, suggesting a potential for stable code, but it does not negate the identified static code weaknesses.

In conclusion, the plugin has strengths in its database interaction and avoidance of common external attack vectors. Nevertheless, the pervasive lack of output escaping presents a significant XSS risk that could be exploited. The absence of common security checks like nonces and capability checks on its entry points, while not directly leading to identified vulnerabilities in this analysis, represents a missed opportunity for robust security implementation and increases the potential risk should an attacker find a way to inject data. The plugin is not inherently insecure due to its history, but the unescaped output is a clear and present danger.

Key Concerns

  • Unescaped output across all outputs
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Prices Only Members for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Prices Only Members for Woocommerce Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Prices Only Members for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Prices Only Members for Woocommerce Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[login] includes/class-dc-pomfw.php:158
[register] includes/class-dc-pomfw.php:159
WordPress Hooks 8
actionplugins_loadedincludes/class-dc-pomfw.php:139
actionadmin_menuincludes/class-dc-pomfw.php:156
actionadmin_initincludes/class-dc-pomfw.php:157
actionadmin_noticesincludes/class-dc-pomfw.php:161
actionplugins_loadedincludes/class-dc-pomfw.php:164
filterwoocommerce_initincludes/class-dc-pomfw.php:183
filterwoocommerce_before_main_contentincludes/class-dc-pomfw.php:185
filterwoocommerce_get_price_htmlincludes/class-dc-pomfw.php:188
Maintenance & Trust

Prices Only Members for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedMar 18, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Prices Only Members for Woocommerce Developer Profile

dcurasi

4 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Prices Only Members for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/prices-only-members-for-woocommerce/css/dc-pomfw-admin.css/wp-content/plugins/prices-only-members-for-woocommerce/js/dc-pomfw-admin.js
Script Paths
/wp-content/plugins/prices-only-members-for-woocommerce/js/dc-pomfw-admin.js
Version Parameters
dc-pomfw-admin.css?ver=dc-pomfw-admin.js?ver=

HTML / DOM Fingerprints

Shortcode Output
<a href="">
FAQ

Frequently Asked Questions about Prices Only Members for Woocommerce