
WC Total Price with Tax Security & Risk Analysis
wordpress.org/plugins/wc-total-price-with-taxA user-friendly plugin to calculate and display the total price, including taxes, for products, shipping, and fees on WooCommerce admin orders
Is WC Total Price with Tax Safe to Use in 2026?
Generally Safe
Score 92/100WC Total Price with Tax has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-total-price-with-tax" plugin version 1.5 exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the plugin's attack surface. Furthermore, the absence of dangerous function calls, file operations, external HTTP requests, and the complete reliance on prepared statements for SQL queries are excellent security practices. The lack of any recorded vulnerabilities in its history is also a positive indicator.
However, a significant concern arises from the output escaping. With 2 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed to users that is not properly escaped could be manipulated by attackers to inject malicious scripts. While the taint analysis shows no critical or high severity flows, the potential for XSS due to unescaped output is a concrete and exploitable risk. The absence of capability checks and nonce checks, while not directly flagged as issues due to the zero attack surface, would become critical vulnerabilities if any entry points were introduced in future versions without proper security measures.
In conclusion, the plugin demonstrates a commendable effort in minimizing its attack surface and adhering to secure coding practices for database interactions. However, the complete lack of output escaping presents a critical weakness that needs immediate attention. Until this is rectified, the plugin carries a notable XSS risk. Future development should also prioritize implementing capability and nonce checks if any user-facing functionalities are added.
Key Concerns
- Unescaped output detected
WC Total Price with Tax Security Vulnerabilities
WC Total Price with Tax Code Analysis
Output Escaping
WC Total Price with Tax Attack Surface
WordPress Hooks 2
Maintenance & Trust
WC Total Price with Tax Maintenance & Trust
Maintenance Signals
Community Trust
WC Total Price with Tax Alternatives
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
Order Export & Order Import for WooCommerce
order-import-export-for-woocommerce
The best order export import plugin for WooCommerce. Easily import and export WooCommerce orders and WooCommerce coupons using CSV.
ATUM WooCommerce Inventory Management and Stock Tracking
atum-stock-manager-for-woocommerce
WooCommerce Full Inventory Management, Purchase Orders, Suppliers, Inbound Stock, Inventory Logs, WooCommerce Sales Statistics, and More.
Pre-Orders, Product Labels, Buy Now, Quick View, Discount Rules and More for WooCommerce – Merchant
merchant
Enhance your WooCommerce store with 40+ modules including Pre-Orders, Product Labels, Buy Now, Quick View & more
Orders Tracking for WooCommerce
woo-orders-tracking
Easily import/manage your tracking numbers, add tracking numbers to PayPal and send email notifications to customers.
WC Total Price with Tax Developer Profile
2 plugins · 50 total installs
How We Detect WC Total Price with Tax
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-total-price-with-tax/HTML / DOM Fingerprints
total_pricesortabledata-sort="total_price"