Royal Checkout Field Manager for WooCommerce Security & Risk Analysis

wordpress.org/plugins/royal-checkout-field-manager

Add custom checkout fields with visibility conditions and optional fees for WooCommerce. 100% GPL, no tracking, WordPress.org compliant.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Mar 28, 2026
checkoutcheckout-fieldscustom-fieldsformswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Royal Checkout Field Manager for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Royal Checkout Field Manager for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin 'royal-checkout-field-manager' v1.0.0 demonstrates a generally strong security posture based on the static analysis. The code employs prepared statements for all SQL queries and has excellent output escaping, with 99% of 344 outputs being properly escaped. The presence of 4 nonce checks and 4 capability checks further indicates a good effort to secure its entry points. Notably, there are no recorded vulnerabilities (CVEs) for this plugin, suggesting a history of stable and secure development.

However, the analysis did reveal two flows with unsanitized paths. While the severity of these is not explicitly stated as critical or high, unsanitized paths can lead to various security issues depending on the context, such as local file inclusion or path traversal vulnerabilities. The plugin's attack surface consists of 3 AJAX handlers, and crucially, none of these are identified as unprotected. This is a positive sign, indicating that the developers have implemented some form of authentication or authorization for these handlers.

In conclusion, 'royal-checkout-field-manager' v1.0.0 appears to be a well-developed plugin with a strong emphasis on secure coding practices, particularly regarding database interactions and output handling. The absence of known vulnerabilities and the protected entry points are significant strengths. The primary concern, albeit with unknown severity, lies in the two identified flows with unsanitized paths. Further investigation into these specific flows would be recommended to confirm their impact.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

Royal Checkout Field Manager for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Royal Checkout Field Manager for WooCommerce Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Royal Checkout Field Manager for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
2
342 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

99% escaped344 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
saved_notice (includes/class-admin.php:153)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Royal Checkout Field Manager for WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_royalcfm_save_fieldincludes/class-admin.php:81
authwp_ajax_royalcfm_delete_fieldincludes/class-admin.php:82
authwp_ajax_royalcfm_get_visibility_optionsincludes/class-admin.php:83
WordPress Hooks 25
actionadmin_menuincludes/class-admin.php:76
actionadmin_initincludes/class-admin.php:77
actionadmin_initincludes/class-admin.php:78
actionadmin_noticesincludes/class-admin.php:79
actionadmin_enqueue_scriptsincludes/class-admin.php:80
actionwoocommerce_cart_calculate_feesincludes/class-fees.php:33
actionwoocommerce_checkout_update_order_reviewincludes/class-fees.php:34
filterwoocommerce_checkout_fieldsincludes/class-frontend.php:33
filterwoocommerce_default_address_fieldsincludes/class-frontend.php:34
actionwoocommerce_checkout_update_order_metaincludes/class-frontend.php:35
actionwoocommerce_checkout_processincludes/class-frontend.php:36
actionwoocommerce_admin_order_data_after_billing_addressincludes/class-frontend.php:37
actionwoocommerce_admin_order_data_after_shipping_addressincludes/class-frontend.php:38
actionwoocommerce_email_after_order_tableincludes/class-frontend.php:39
filterwoocommerce_order_formatted_billing_addressincludes/class-frontend.php:40
filterwoocommerce_order_formatted_shipping_addressincludes/class-frontend.php:41
actionwoocommerce_order_details_after_order_tableincludes/class-frontend.php:42
actionwoocommerce_checkout_update_order_reviewincludes/class-frontend.php:43
filterwoocommerce_ajax_get_cart_item_productincludes/class-frontend.php:44
filterwoocommerce_checkout_get_valueincludes/class-frontend.php:45
actionwp_enqueue_scriptsincludes/class-frontend.php:46
filterwoocommerce_form_fieldincludes/class-frontend.php:47
actionbefore_woocommerce_initincludes/class-hpos.php:23
actionplugins_loadedincludes/class-plugin.php:70
actionadmin_noticesincludes/class-plugin.php:79
Maintenance & Trust

Royal Checkout Field Manager for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 28, 2026
PHP min version7.4
Downloads67

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Royal Checkout Field Manager for WooCommerce Developer Profile

sonianant

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Royal Checkout Field Manager for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/royal-checkout-field-manager/assets/css/admin.css/wp-content/plugins/royal-checkout-field-manager/assets/js/admin.js/wp-content/plugins/royal-checkout-field-manager/assets/vendor/select2/select2.min.css/wp-content/plugins/royal-checkout-field-manager/assets/vendor/select2/select2.min.js/wp-content/plugins/royal-checkout-field-manager/assets/vendor/wp-color-picker-alpha/wp-color-picker-alpha.js
Script Paths
/wp-content/plugins/royal-checkout-field-manager/assets/js/admin.js
Version Parameters
royal-checkout-field-manager/assets/css/admin.css?ver=royal-checkout-field-manager/assets/js/admin.js?ver=royal-checkout-field-manager/assets/vendor/select2/select2.min.css?ver=royal-checkout-field-manager/assets/vendor/select2/select2.min.js?ver=royal-checkout-field-manager/assets/vendor/wp-color-picker-alpha/wp-color-picker-alpha.js?ver=

HTML / DOM Fingerprints

CSS Classes
royalcfm-field-typeroyalcfm-sectionroyalcfm-requiredroyalcfm-save-metaroyalcfm-conditionalroyalcfm-conditional-targetroyalcfm-conditional-operatorroyalcfm-conditional-value+5 more
HTML Comments
<!-- Start Royal Checkout Field Manager admin settings --><!-- End Royal Checkout Field Manager admin settings -->
Data Attributes
data-field-iddata-field-typedata-field-labeldata-field-sectiondata-field-requireddata-field-save-meta+10 more
JS Globals
RoyalCFMAdminroyalcfm_params
REST Endpoints
/wp-json/royalcfm/v1/save_field/wp-json/royalcfm/v1/delete_field/wp-json/royalcfm/v1/visibility_options
FAQ

Frequently Asked Questions about Royal Checkout Field Manager for WooCommerce