
Conditional Fees for WooCommerce Lite Security & Risk Analysis
wordpress.org/plugins/woo-add-custom-feeConditional Fees for WooCommerce allows businesses to streamline their pricing strategies. They can apply correct tax rate & abide by regional tax …
Is Conditional Fees for WooCommerce Lite Safe to Use in 2026?
Generally Safe
Score 92/100Conditional Fees for WooCommerce Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-add-custom-fee" plugin, version 1.7.1, demonstrates a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, the exclusive use of prepared statements for SQL queries, and proper output escaping are all positive indicators. Furthermore, the plugin appears to have no recorded vulnerabilities, including CVEs, which suggests a history of responsible development and maintenance. The limited attack surface with no identified entry points without authentication checks is also a significant strength. The bundled Freemius library is at version 1.0, which is noted but without specific version-related security concerns flagged in this analysis.
However, the static analysis reveals a complete lack of nonces and capability checks across all identified entry points. While the current attack surface is zero, if any entry points were to be introduced or if existing ones are not strictly controlled externally, this absence could create a security weakness. The taint analysis also reported zero flows, which is excellent, but it's important to remember that static analysis is not foolproof and complex or subtle vulnerabilities might be missed. The bundled Freemius library at version 1.0 is a minor concern; while no specific vulnerability is indicated, outdated bundled libraries can sometimes harbor known or unknown issues.
In conclusion, the plugin is currently in a good security state with a clean vulnerability history and sound coding practices regarding SQL and output handling. The primary area for improvement and potential future risk lies in the complete absence of nonce and capability checks, which, while not immediately exploitable given the current zero attack surface, is a deviation from best practices for web application security. The outdated bundled library is a minor, passive risk.
Key Concerns
- Complete absence of nonce checks
- Complete absence of capability checks
- Bundled Freemius library v1.0 outdated
Conditional Fees for WooCommerce Lite Security Vulnerabilities
Conditional Fees for WooCommerce Lite Code Analysis
Bundled Libraries
Output Escaping
Conditional Fees for WooCommerce Lite Attack Surface
WordPress Hooks 8
Maintenance & Trust
Conditional Fees for WooCommerce Lite Maintenance & Trust
Maintenance Signals
Community Trust
Conditional Fees for WooCommerce Lite Alternatives
Cart Additional Fee For WooCommerce
woo-cart-additional-fee
Add Additional Fee to your Customer Cart Based on Some Filters.
PiWeb Conditional cart fee / Extra charge rule for WooCommerce
conditional-extra-fees-for-woocommerce
Add conditional cart fee / Payment processing fee / Extra cost / Extra fees plugin for WooCommerce / Additional fees / Service charge at checkout for …
Extra Fees for WooCommerce
woo-conditional-product-fees-for-checkout
Charge extra fees in cart, based on the combination of multiple conditional rules that you configure.
WooBooster Additional Charges for WooCommerce
wb-additional-charges-for-woocommerce
Our plugin will provide you option to add additional fees directly from the WordPress admin panel and display on the checkout page.
Product Fee for Woocommerce
woo-product-fee
This plugin allows you to add custom fee per product. You can also decide whether this fee should be visible customer or not.
Conditional Fees for WooCommerce Lite Developer Profile
84 plugins · 1.4M total installs
How We Detect Conditional Fees for WooCommerce Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-add-custom-fee/assets/admin/cffw-backend-script.js/wp-content/plugins/woo-add-custom-fee/assets/admin/cffw-admin.css/wp-content/plugins/woo-add-custom-fee/freemius/start.phpwoo-add-custom-fee/assets/admin/cffw-backend-script.js?ver=woo-add-custom-fee/assets/admin/cffw-admin.css?ver=HTML / DOM Fingerprints
wacf_enablewacf_fee_labelwacf_typewacf_amountwacf_percentagewacf_min_amountwacf_max_amountwacf_cart_total+12 more<!-- Freemius Integration Start--><!-- Freemius Integration End--><!-- WC requires at least: 3.0 --><!-- WC tested up to: 9.6 -->+30 moreid="wacf_enable"id="wacf_fee_label"id="wacf_type"id="wacf_amount"id="wacf_percentage"id="wacf_min_amount"+34 morecfl_fswacf