
Product Total Price for WooCommerce Security & Risk Analysis
wordpress.org/plugins/product-total-price-for-woocommerceAn addon for WooCommerce that will help visitors to understand the final product price when product's quantity changes.
Is Product Total Price for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Product Total Price for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The product-total-price-for-woocommerce plugin version 1.1.4 exhibits a generally strong security posture based on the static analysis provided. It demonstrates good practices by having no direct SQL injection vulnerabilities, utilizing prepared statements exclusively for its queries, and having no external HTTP requests or file operations. The absence of recorded CVEs and vulnerabilities in its history further suggests a well-maintained and secure codebase.
However, there are some areas that raise concerns. The plugin has a low percentage of properly escaped output (33%), which could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. While the attack surface is small, the lack of capability checks on the single shortcode entry point is a notable weakness. A lack of explicit capability checks means that any authenticated user, regardless of their role, could potentially trigger the shortcode's functionality. The absence of nonce checks, especially in conjunction with the unprotected shortcode, further exacerbates this risk.
In conclusion, while the plugin benefits from a clean vulnerability history and secure data handling for SQL, the identified output escaping and capability check deficiencies present potential security risks. Addressing these issues would significantly strengthen the plugin's overall security. The current risk is moderate, leaning towards low due to the limited attack surface and lack of historical vulnerabilities.
Key Concerns
- Low output escaping percentage
- Missing capability checks on shortcode
- Missing nonce checks
Product Total Price for WooCommerce Security Vulnerabilities
Product Total Price for WooCommerce Code Analysis
Output Escaping
Product Total Price for WooCommerce Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Product Total Price for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Product Total Price for WooCommerce Alternatives
Tiered Pricing Table for WooCommerce
tier-pricing-table
Offer quantity-based discounts with flexible display templates. Boost sales using role-based pricing, quantity limits, cart upsells, and more.
Variation Price Display Range for WooCommerce
variation-price-display
Adds lots of advanced options to control how you display the price for your WooCommerce variable products.
Role Based Pricing for Woo by Meow Crew
role-and-customer-based-pricing-for-woocommerce
Create individual pricing for customers based on their role or account. Works with all types of products along with Import-Export tools
Variation Price Display For WooCommerce
disable-variable-product-price-range-show-only-lowest-price-in-variable-products
Disable the WooCommerce variation price range and show the lowest price in WooCommerce variable products.
Pay What You Want
pay-what-you-want
This plugin will help you to set your product price to an open price/ a set of predefined prices or it can create a fraction of the price based on the …
Product Total Price for WooCommerce Developer Profile
3 plugins · 110 total installs
How We Detect Product Total Price for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-total-price-for-woocommerce/assets/js/attrchange.js/wp-content/plugins/product-total-price-for-woocommerce/assets/js/script.jsassets/js/attrchange.jsassets/js/script.jsproduct-total-price-for-woocommerce/assets/js/attrchange.js?ver=product-total-price-for-woocommerce/assets/js/script.js?ver=HTML / DOM Fingerprints
wcptp-total-pricewcptp_data[WOO-TOTAL-PRICE]