
Digital Goods (Checkout Field Editor) for WooCommerce Checkout Security & Risk Analysis
wordpress.org/plugins/woo-checkout-for-digital-goodsThis plugin will remove billing address fields for downloadable and virtual products.
Is Digital Goods (Checkout Field Editor) for WooCommerce Checkout Safe to Use in 2026?
Generally Safe
Score 100/100Digital Goods (Checkout Field Editor) for WooCommerce Checkout has a strong security track record. Known vulnerabilities have been patched promptly.
The "woo-checkout-for-digital-goods" plugin v3.8.3 exhibits a mixed security posture. While the absence of dangerous functions, 100% prepared SQL statements, and a low number of external HTTP requests are positive signs, significant concerns remain. The plugin has a total of one entry point, and critically, this single AJAX handler lacks authentication checks. This unprotected entry point presents a direct avenue for attackers to potentially interact with the plugin's functionality without proper authorization.
The vulnerability history shows one medium-severity CVE, identified as Cross-Site Request Forgery (CSRF), last patched in 2018. While there are no currently unpatched vulnerabilities, the past presence of CSRF, even at a medium level, highlights a historical weakness in handling user interactions securely. The taint analysis found no critical or high severity unsanitized flows, which is reassuring, but it analyzed only one flow, suggesting a limited scope of analysis or minimal complexity in this area.
In conclusion, the plugin demonstrates some good security practices, particularly with its SQL handling. However, the unprotected AJAX handler is a severe oversight that significantly elevates the risk. The outdated vulnerability history, while patched, serves as a reminder that the plugin may have had past security weaknesses. The overall risk is moderate, primarily due to the single, unprotected AJAX entry point.
Key Concerns
- Unprotected AJAX handler
- Bundled outdated Freemius library
- Past medium severity CVE (CSRF)
Digital Goods (Checkout Field Editor) for WooCommerce Checkout Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Digital Goods < 2.2 - Cross-Site Request Forgery
Digital Goods (Checkout Field Editor) for WooCommerce Checkout Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Digital Goods (Checkout Field Editor) for WooCommerce Checkout Attack Surface
AJAX Handlers 1
WordPress Hooks 44
Maintenance & Trust
Digital Goods (Checkout Field Editor) for WooCommerce Checkout Maintenance & Trust
Maintenance Signals
Community Trust
Digital Goods (Checkout Field Editor) for WooCommerce Checkout Alternatives
Checkout Field Editor (Checkout Manager) for WooCommerce
woo-checkout-field-editor-pro
Checkout Field Editor (Checkout Manager) for WooCommerce – The best WooCommerce checkout manager plugin to manage WooCommerce checkout fields.
Custom WooCommerce Checkout Fields Editor
add-fields-to-checkout-page-woocommerce
Custom WooCommerce Checkout Fields Editor
Qodax Checkout Manager – Checkout Field Editor for WooCommerce
qodax-checkout-manager
Customize and manage checkout fields in your WooCommerce store with a simple and user-friendly interface.
Checkout Field Editor / Checkout Manager for WooCommerce
checkout-field-editor
Checkout Field Editor /Checkout Manager for WooCommerce - WooCommerce checkout editor plugin to manage your WooCommerce checkout fields.
All in one checkout page builder for woocommerce
all-in-one-checkout-page-builder-for-woocommerce
Build fully customized WooCommerce checkout pages with drag-and-drop controls, flexible layouts, and smart field management.
Digital Goods (Checkout Field Editor) for WooCommerce Checkout Developer Profile
37 plugins · 95K total installs
How We Detect Digital Goods (Checkout Field Editor) for WooCommerce Checkout
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-checkout-for-digital-goods/admin/css/wcdg-admin-style.css/wp-content/plugins/woo-checkout-for-digital-goods/assets/css/wcdg-style.css/wp-content/plugins/woo-checkout-for-digital-goods/assets/js/wcdg-scripts.jshttps://ps.w.org/woo-checkout-for-digital-goods/trunk/woo-checkout-for-digital-goods.phphttps://ps.w.org/woo-checkout-for-digital-goods/assets/js/wcdg-scripts.js?ver=3.8.3woo-checkout-for-digital-goods/assets/css/wcdg-style.css?ver=3.8.3woo-checkout-for-digital-goods/assets/js/wcdg-scripts.js?ver=3.8.3HTML / DOM Fingerprints
wcdg-admin-csswcdg-custom-style<!-- WCDG --><!-- WCDG End -->data-wcdg-field-idwcdg_vars