
WHMCS Price Security & Risk Analysis
wordpress.org/plugins/whmcs-priceDynamic way for extracting product & domain price from WHMCS.
Is WHMCS Price Safe to Use in 2026?
Generally Safe
Score 85/100WHMCS Price has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "whmcs-price" v1.3 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions and exclusively using prepared statements for SQL queries. All identified outputs are properly escaped, and there are no external HTTP requests or recorded vulnerabilities, suggesting a well-maintained codebase.
However, there are areas that warrant attention. The presence of file operations without explicit mention of sanitization or validation, coupled with a lack of nonce and capability checks across the plugin's entry points, presents potential attack vectors. While the static analysis didn't reveal specific taint flows or unpatched CVEs, these missing security controls could be exploited if user-supplied data is processed in sensitive file operations or if the shortcode is used in an unexpected context that bypasses WordPress's default security.
The absence of any vulnerability history is a positive indicator, suggesting a mature and secure development process. Nonetheless, the lack of robust authentication and authorization mechanisms on its single entry point (the shortcode) is a notable weakness that could be leveraged in conjunction with other potential flaws. Overall, while the plugin has strong foundations, the gaps in input validation and authorization for its entry points introduce an element of risk.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- File operations without clear sanitization/validation
WHMCS Price Security Vulnerabilities
WHMCS Price Code Analysis
Output Escaping
WHMCS Price Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
WHMCS Price Maintenance & Trust
Maintenance Signals
Community Trust
WHMCS Price Alternatives
Show Pages IDs
show-posts-and-pages-id
This plugin will show the IDs of posts and pages on the admin bar and on the admin panel.
Hide Content by User Role for WPBakery
hide-content-by-role-for-wpbakery
Hide/show/restrict elements based on user roles like administrator in WPBakery page builder (formerly Visual Composer).
Show Current Template – CTI
current-template-info
CTI is a WordPress plugin which show current template name file and post information(post id, post type, post taxonomy).
Simple SEO Slideshow
simple-seo-slideshow
A plugin to display slideshow in a widget with title, description and custom link from page or post gallery.
Paged Post List Shortcode
paged-post-list-shortcode
Display a list of items (posts or pages) with pagination. Use shortcode: [list_posts_paged]
WHMCS Price Developer Profile
1 plugin · 100 total installs
How We Detect WHMCS Price
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
NA