Simple Price Fee Security & Risk Analysis

wordpress.org/plugins/simple-price-fee

Adds a fixed fee or discount to the WooCommerce cart total based on subtotal ranges, with a customizable label shown at checkout and in the cart.

20 active installs v1.0.3 PHP 7.2+ WP 5.0+ Updated Jun 19, 2025
cartcheckoutdiscountfeewoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Price Fee Safe to Use in 2026?

Generally Safe

Score 92/100

Simple Price Fee has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the 'simple-price-fee' v1.0.3 plugin indicates a generally strong security posture. There are no identified vulnerabilities in the code, including dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or taint flows. The plugin also demonstrates good practices by using prepared statements for all SQL queries and properly escaping all output. The absence of any recorded CVEs further strengthens this positive assessment.

However, a significant concern arises from the complete lack of any security checks like nonces or capability checks, and the absence of any identified entry points (AJAX, REST API, shortcodes, cron events). While this can be interpreted as a small attack surface, it also suggests that if any entry points were to be introduced in future versions or were present but not detected by the analysis, they would likely be completely unprotected. This lack of built-in security mechanisms is a potential weakness that could be exploited if the plugin's functionality evolves to include user-interactive features.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Simple Price Fee Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Price Fee Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Simple Price Fee Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped22 total outputs
Attack Surface

Simple Price Fee Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptssimple-price-fee.php:26
actionadmin_initsimple-price-fee.php:34
filterpre_delete_option_at24spf_settingssimple-price-fee.php:41
actionadmin_menusimple-price-fee.php:78
actionwoocommerce_cart_calculate_feessimple-price-fee.php:138
Maintenance & Trust

Simple Price Fee Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedJun 19, 2025
PHP min version7.2
Downloads751

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Simple Price Fee Developer Profile

Autotech24 EU

1 plugin · 20 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Price Fee

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-price-fee/assets/admin.js/wp-content/plugins/simple-price-fee/assets/admin.css
Script Paths
/wp-content/plugins/simple-price-fee/assets/admin.js
Version Parameters
simple-price-fee/assets/admin.js?ver=1.0simple-price-fee/assets/admin.css?ver=1.0

HTML / DOM Fingerprints

CSS Classes
wrapform-tablewidefatfixed
Data Attributes
name="at24spf_settings[label]"name="at24spf_settings[rules][name="at24spf_settings[rules][][min]"name="at24spf_settings[rules][][max]"name="at24spf_settings[rules][][amount]"id="at24spf_rules_table"+2 more
FAQ

Frequently Asked Questions about Simple Price Fee