
Unit Price for WooCommerce Security & Risk Analysis
wordpress.org/plugins/unit-price-for-woocommerceWooCommerce plugin for configuring products which are sold by units but priced by weight.
Is Unit Price for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Unit Price for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "unit-price-for-woocommerce" v1.2.5 plugin presents a significant security risk primarily due to its unprotected AJAX handlers. The static analysis reveals an attack surface consisting of 6 AJAX handlers, all of which lack authentication checks. This means any unauthenticated user could potentially trigger these functionalities, opening the door to various attacks depending on what these handlers do.
While the plugin demonstrates good practices by utilizing prepared statements for its SQL queries and avoiding file operations or external HTTP requests, the complete absence of nonces and capability checks on its entry points is a major concern. The taint analysis, though limited in scope, did identify a flow with unsanitized paths, which could potentially lead to issues if combined with the lack of proper input validation and sanitization on the AJAX handlers. The plugin's vulnerability history is clean, with no recorded CVEs, which might suggest past good security practices or simply a lack of past scrutiny. However, this does not negate the current risks identified in the code.
In conclusion, the plugin has some strengths, particularly in its database query handling and lack of external dependencies. However, the presence of multiple unprotected AJAX endpoints represents a critical weakness that severely undermines its overall security posture. This requires immediate attention and remediation to prevent potential exploitation.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks
- Missing capability checks
- Unsanitized path in taint flow
- Low percentage of properly escaped output
Unit Price for WooCommerce Security Vulnerabilities
Unit Price for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Unit Price for WooCommerce Attack Surface
AJAX Handlers 6
WordPress Hooks 64
Maintenance & Trust
Unit Price for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Unit Price for WooCommerce Alternatives
Enable Media Replace
enable-media-replace
Easily replace any attached image/file by simply uploading a new file in the Media Library edit view - a real time saver!
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
BuddyPress
buddypress
Get together safely, in your own way, in WordPress.
Companion Auto Update
companion-auto-update
Manage all updates on your WordPress site. Stay in the know with several optional e-mail notifications and logs. For free.
OoohBoi Steroids for Elementor
ooohboi-steroids-for-elementor
Boost your Elementor with some fresh and yet innovative options.
Unit Price for WooCommerce Developer Profile
7 plugins · 10K total installs
How We Detect Unit Price for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unit-price-for-woocommerce/assets/css/frontend/frontend.css/wp-content/plugins/unit-price-for-woocommerce/assets/js/frontend/frontend.js/wp-content/plugins/unit-price-for-woocommerce/assets/js/frontend/variable-frontend.js/wp-content/plugins/unit-price-for-woocommerce/assets/js/frontend/frontend.js/wp-content/plugins/unit-price-for-woocommerce/assets/js/frontend/variable-frontend.jsunit-price-for-woocommerce/assets/css/frontend/frontend.css?ver=unit-price-for-woocommerce/assets/js/frontend/frontend.js?ver=unit-price-for-woocommerce/assets/js/frontend/variable-frontend.js?ver=HTML / DOM Fingerprints
wc_upw_quantity_inputwc_upw_quantity_containerwc_upw_variable_quantity_inputwc-upw-add-to-cart-buttondata-unit-pricedata-unit-measurementdata-stepwc_upw_paramswc_upw_variable_params