
Checkout Field Editor (Checkout Manager) for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-checkout-field-editor-proCheckout Field Editor (Checkout Manager) for WooCommerce – The best WooCommerce checkout manager plugin to manage WooCommerce checkout fields.
Is Checkout Field Editor (Checkout Manager) for WooCommerce Safe to Use in 2026?
Generally Safe
Score 93/100Checkout Field Editor (Checkout Manager) for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin exhibits several positive security practices, including 100% use of prepared statements for SQL queries and proper output escaping, indicating good defensive coding in these areas. The presence of numerous nonce and capability checks also suggests an effort to secure its functionality. However, the static analysis reveals a significant concern with one of its two AJAX handlers lacking authentication checks, creating a direct entry point for potential unauthorized actions.
Taint analysis shows a flow with an unsanitized path, which, while not flagged as critical or high severity in this scan, warrants attention as it represents a potential avenue for injecting malicious data. The plugin's vulnerability history is a major red flag. With 3 previously disclosed CVEs, including 2 high and 1 medium severity, and a recent vulnerability in 2026, it indicates a pattern of past security weaknesses that required external patching. The historical vulnerability types like Cross-site Scripting and Deserialization of Untrusted Data are common and can be severe if exploited.
Overall, while the code demonstrates strengths in areas like SQL and output handling, the unprotected AJAX handler and the historical vulnerability record significantly elevate the risk profile. The potential for unauthenticated access to an AJAX endpoint coupled with past exploitable vulnerabilities suggests that users should exercise caution. Continued vigilance and prompt patching of future vulnerabilities are crucial.
Key Concerns
- Unprotected AJAX handler
- Flow with unsanitized path (taint analysis)
- 3 known CVEs (2 high, 1 medium)
Checkout Field Editor (Checkout Manager) for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.1.7 - Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field
Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.0.3 - Reflected Cross-Site Scripting via render_review_request_notice
Checkout Field Editor <= 1.7.2 - Authenticated (Admin+) PHP Object Injection
Checkout Field Editor (Checkout Manager) for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Checkout Field Editor (Checkout Manager) for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 65
Maintenance & Trust
Checkout Field Editor (Checkout Manager) for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Checkout Field Editor (Checkout Manager) for WooCommerce Alternatives
Custom WooCommerce Checkout Fields Editor
add-fields-to-checkout-page-woocommerce
Custom WooCommerce Checkout Fields Editor
Checkout Field Editor / Checkout Manager for WooCommerce
checkout-field-editor
Checkout Field Editor /Checkout Manager for WooCommerce - WooCommerce checkout editor plugin to manage your WooCommerce checkout fields.
Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager
flexible-checkout-fields
The best WooCommerce checkout manager. Edit, remove or add checkout fields. Customize WooCommerce checkout with this checkout field customizer.
Checkout Field Editor for WooCommerce – Checkout Page Manager
woo-checkout-regsiter-field-editor
Checkout Field Editor for WooCommerce is the leading plugin for customizing, editing, removing, and managing your WooCommerce checkout fields.
FEWC – Extra Checkout Fields For WooCommerce
fewc-extra-checkout-fields-for-woocommerce
Easily customize your checkout page: add custom fields, enable/disable fields, rearrange their positions, and preview changes in the WP Customizer
Checkout Field Editor (Checkout Manager) for WooCommerce Developer Profile
16 plugins · 579K total installs
How We Detect Checkout Field Editor (Checkout Manager) for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-checkout-field-editor-pro/admin/assets/css/thwcfd-admin.css/wp-content/plugins/woo-checkout-field-editor-pro/admin/assets/js/thwcfd-admin.js/wp-content/plugins/woo-checkout-field-editor-pro/admin/assets/images/logo.svg/wp-content/plugins/woo-checkout-field-editor-pro/admin/assets/js/thwcfd-admin.min.jswoo-checkout-field-editor-pro/admin/assets/css/thwcfd-admin.css?ver=woo-checkout-field-editor-pro/admin/assets/js/thwcfd-admin.js?ver=HTML / DOM Fingerprints
thwcfd-wrapth-block-warning-msgth-warning-message-panel__textth-warning-message-panel__text--centerth-warning-imgth-warningth-warning-message-panel__inner-text<!-- Block Compatibility Warning -->THWCFD_URL