Product Total Price for WooCommerce Security & Risk Analysis

wordpress.org/plugins/product-total-price-for-woocommerce

An addon for WooCommerce that will help visitors to understand the final product price when product's quantity changes.

100 active installs v1.1.4 PHP 5.3+ WP 4.0.0+ Updated Apr 10, 2023
dynamic-priceprice-displayprice-previewprice-sub-totalsubtotal
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Product Total Price for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Product Total Price for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The product-total-price-for-woocommerce plugin version 1.1.4 exhibits a generally strong security posture based on the static analysis provided. It demonstrates good practices by having no direct SQL injection vulnerabilities, utilizing prepared statements exclusively for its queries, and having no external HTTP requests or file operations. The absence of recorded CVEs and vulnerabilities in its history further suggests a well-maintained and secure codebase.

However, there are some areas that raise concerns. The plugin has a low percentage of properly escaped output (33%), which could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. While the attack surface is small, the lack of capability checks on the single shortcode entry point is a notable weakness. A lack of explicit capability checks means that any authenticated user, regardless of their role, could potentially trigger the shortcode's functionality. The absence of nonce checks, especially in conjunction with the unprotected shortcode, further exacerbates this risk.

In conclusion, while the plugin benefits from a clean vulnerability history and secure data handling for SQL, the identified output escaping and capability check deficiencies present potential security risks. Addressing these issues would significantly strengthen the plugin's overall security. The current risk is moderate, leaning towards low due to the limited attack surface and lack of historical vulnerabilities.

Key Concerns

  • Low output escaping percentage
  • Missing capability checks on shortcode
  • Missing nonce checks
Vulnerabilities
None known

Product Total Price for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Product Total Price for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped9 total outputs
Attack Surface

Product Total Price for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[WOO-TOTAL-PRICE] init.php:129
WordPress Hooks 6
filterwp_localize_wcptp_dataincludes\functions.php:6
filterwcptp_allowed_product_typeincludes\functions.php:37
actionadmin_noticesinit.php:35
actioninitinit.php:109
actionwoocommerce_loadedinit.php:113
actionwp_enqueue_scriptsinit.php:131
Maintenance & Trust

Product Total Price for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 10, 2023
PHP min version5.3
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Product Total Price for WooCommerce Developer Profile

autocircle

3 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Product Total Price for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-total-price-for-woocommerce/assets/js/attrchange.js/wp-content/plugins/product-total-price-for-woocommerce/assets/js/script.js
Script Paths
assets/js/attrchange.jsassets/js/script.js
Version Parameters
product-total-price-for-woocommerce/assets/js/attrchange.js?ver=product-total-price-for-woocommerce/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wcptp-total-price
JS Globals
wcptp_data
Shortcode Output
[WOO-TOTAL-PRICE]
FAQ

Frequently Asked Questions about Product Total Price for WooCommerce