Conditional Fees for WooCommerce Lite Security & Risk Analysis

wordpress.org/plugins/woo-add-custom-fee

Conditional Fees for WooCommerce allows businesses to streamline their pricing strategies. They can apply correct tax rate & abide by regional tax …

500 active installs v1.7.1 PHP + WP 4.0+ Updated Jan 31, 2025
additional-feecart-feecustom-feeextra-feewoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Conditional Fees for WooCommerce Lite Safe to Use in 2026?

Generally Safe

Score 92/100

Conditional Fees for WooCommerce Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "woo-add-custom-fee" plugin, version 1.7.1, demonstrates a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, the exclusive use of prepared statements for SQL queries, and proper output escaping are all positive indicators. Furthermore, the plugin appears to have no recorded vulnerabilities, including CVEs, which suggests a history of responsible development and maintenance. The limited attack surface with no identified entry points without authentication checks is also a significant strength. The bundled Freemius library is at version 1.0, which is noted but without specific version-related security concerns flagged in this analysis.

However, the static analysis reveals a complete lack of nonces and capability checks across all identified entry points. While the current attack surface is zero, if any entry points were to be introduced or if existing ones are not strictly controlled externally, this absence could create a security weakness. The taint analysis also reported zero flows, which is excellent, but it's important to remember that static analysis is not foolproof and complex or subtle vulnerabilities might be missed. The bundled Freemius library at version 1.0 is a minor concern; while no specific vulnerability is indicated, outdated bundled libraries can sometimes harbor known or unknown issues.

In conclusion, the plugin is currently in a good security state with a clean vulnerability history and sound coding practices regarding SQL and output handling. The primary area for improvement and potential future risk lies in the complete absence of nonce and capability checks, which, while not immediately exploitable given the current zero attack surface, is a deviation from best practices for web application security. The outdated bundled library is a minor, passive risk.

Key Concerns

  • Complete absence of nonce checks
  • Complete absence of capability checks
  • Bundled Freemius library v1.0 outdated
Vulnerabilities
None known

Conditional Fees for WooCommerce Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Conditional Fees for WooCommerce Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped2 total outputs
Attack Surface

Conditional Fees for WooCommerce Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitconditional-fees-for-woocommerce-lite.php:78
actionbefore_woocommerce_initconditional-fees-for-woocommerce-lite.php:81
actionadmin_noticesconditional-fees-for-woocommerce-lite.php:91
actionwoocommerce_settings_tabs_arrayincludes\admin\class-cffw-settings.php:12
actionwoocommerce_settings_tabs_settings_wacfincludes\admin\class-cffw-settings.php:13
actionwoocommerce_update_options_settings_wacfincludes\admin\class-cffw-settings.php:14
actionadmin_enqueue_scriptsincludes\admin\class-cffw-settings.php:15
actionwoocommerce_cart_calculate_feesincludes\public\class-cffw-front.php:12
Maintenance & Trust

Conditional Fees for WooCommerce Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 31, 2025
PHP min version
Downloads21K

Community Trust

Rating86/100
Number of ratings3
Active installs500
Developer Profile

Conditional Fees for WooCommerce Lite Developer Profile

Saad Iqbal

84 plugins · 1.4M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
287 days
View full developer profile
Detection Fingerprints

How We Detect Conditional Fees for WooCommerce Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-add-custom-fee/assets/admin/cffw-backend-script.js/wp-content/plugins/woo-add-custom-fee/assets/admin/cffw-admin.css
Script Paths
/wp-content/plugins/woo-add-custom-fee/freemius/start.php
Version Parameters
woo-add-custom-fee/assets/admin/cffw-backend-script.js?ver=woo-add-custom-fee/assets/admin/cffw-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
wacf_enablewacf_fee_labelwacf_typewacf_amountwacf_percentagewacf_min_amountwacf_max_amountwacf_cart_total+12 more
HTML Comments
<!-- Freemius Integration Start--><!-- Freemius Integration End--><!-- WC requires at least: 3.0 --><!-- WC tested up to: 9.6 -->+30 more
Data Attributes
id="wacf_enable"id="wacf_fee_label"id="wacf_type"id="wacf_amount"id="wacf_percentage"id="wacf_min_amount"+34 more
JS Globals
cfl_fswacf
FAQ

Frequently Asked Questions about Conditional Fees for WooCommerce Lite