Checkout Field Manager (Checkout Manager) for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocommerce-checkout-manager

Checkout Field Manager (Checkout Manager) for WooCommerce is the most advanced plugin to customize checkout fields on your WooCommerce checkout page.

90K active installs v7.8.8 PHP 5.6+ WP 4.7+ Updated Mar 11, 2026
checkout-editorcheckout-field-customizercheckout-fieldscheckout-managerwoocommerce-checkout
92
A · Safe
CVEs total5
Unpatched0
Last CVEFeb 18, 2026
Safety Verdict

Is Checkout Field Manager (Checkout Manager) for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Checkout Field Manager (Checkout Manager) for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Feb 18, 2026Updated 23d ago
Risk Assessment

The WooCommerce Checkout Manager plugin v7.8.8 exhibits a mixed security posture. On the positive side, the static analysis reveals a zero-attack surface for AJAX handlers, REST API routes, shortcodes, and cron events, with no identified dangerous functions. The plugin also demonstrates good practices in output escaping, with 93% of outputs properly handled, and includes nonce and capability checks. However, the presence of two SQL queries that do not utilize prepared statements is a significant concern, potentially leading to SQL injection vulnerabilities. The plugin also makes one external HTTP request, which could be a vector for various attacks if not handled securely.

The plugin's vulnerability history is a major red flag. With a total of 5 known CVEs, including one high-severity vulnerability, and past occurrences of missing authorization and cross-site scripting, it indicates a pattern of past security weaknesses. The fact that there are currently no unpatched vulnerabilities is a positive sign, but the history suggests a need for continued vigilance and thorough auditing. The last recorded vulnerability in 2026 suggests the data might be future-looking or include placeholders, but the historical trends remain a valid concern.

In conclusion, while the current version shows some improvements in its attack surface and output escaping, the reliance on raw SQL queries and the concerning history of multiple vulnerabilities, particularly those related to authorization and XSS, necessitate caution. Developers should prioritize addressing the unparameterized SQL queries and remain aware of the plugin's past security issues when considering its use.

Key Concerns

  • SQL queries without prepared statements
  • History of multiple CVEs
  • High-severity vulnerability in history
  • Common vulnerability types: Missing Authorization
  • Common vulnerability types: Cross-site Scripting
  • External HTTP requests
Vulnerabilities
5

Checkout Field Manager (Checkout Manager) for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2019
2019
1 CVE in 2022
2022
1 CVE in 2023
2023
2 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

High
1
Medium
4

5 total CVEs

CVE-2025-13930medium · 5.3Missing Authorization

Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

Feb 18, 2026 Patched in 7.8.6 (1d)
CVE-2025-12500medium · 5.3Unrestricted Upload of File with Dangerous Type

Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.1 - Unauthenticated Limited File Upload

Feb 18, 2026 Patched in 7.8.2 (1d)
CVE-2023-47681medium · 6.5Missing Authorization

WooCommerce Checkout Manager <= 7.3.0 - Missing Authorization

Nov 9, 2023 Patched in 7.3.1 (75d)
WF-11aec50c-2531-4d30-92da-8513fdca741e-woocommerce-checkout-managermedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Checkout Fields Manager for WooCommerce <= 5.5.6 - Reflected Cross-Site Scripting

Jun 14, 2022 Patched in 5.5.7 (588d)
CVE-2019-11807high · 7.5Missing Authorization

WooCommerce Checkout Manager <= 4.2.6 - Unauthenticated Arbitrary Media Deletion

Apr 25, 2019 Patched in 4.3 (1734d)
Code Analysis
Analyzed Mar 16, 2026

Checkout Field Manager (Checkout Manager) for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
8
109 escaped
Nonce Checks
2
Capability Checks
5
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

93% escaped117 total outputs
Attack Surface

Checkout Field Manager (Checkout Manager) for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionwp_default_scriptsjetpack_vendor\automattic\jetpack-assets\actions.php:11
actionplugins_loadedjetpack_vendor\automattic\jetpack-assets\actions.php:12
filterwp_resource_hintsjetpack_vendor\automattic\jetpack-assets\src\class-assets.php:182
actionwp_loadedjetpack_vendor\automattic\jetpack-assets\src\class-script-data.php:38
actionenqueue_block_editor_assetsjetpack_vendor\automattic\jetpack-assets\src\class-script-data.php:52
actionshutdownjetpack_vendor\automattic\jetpack-status\src\class-errors.php:38
actionwp_network_dashboard_setupjetpack_vendor\quadlayers\wp-dashboard-widget-news\src\Load.php:36
actionwp_dashboard_setupjetpack_vendor\quadlayers\wp-dashboard-widget-news\src\Load.php:37
actionadmin_noticesjetpack_vendor\quadlayers\wp-notice-plugin-promote\src\Load.php:95
actionadmin_noticesjetpack_vendor\quadlayers\wp-notice-plugin-promote\src\Load.php:104
actionadmin_noticesjetpack_vendor\quadlayers\wp-notice-plugin-required\src\Load.php:40
actionplugins_loadedjetpack_vendor\quadlayers\wp-plugin-suggestions\src\Page.php:47
actionadmin_menujetpack_vendor\quadlayers\wp-plugin-suggestions\src\Page.php:50
actionadmin_initjetpack_vendor\quadlayers\wp-plugin-suggestions\src\Page.php:55
filternetwork_admin_urljetpack_vendor\quadlayers\wp-plugin-suggestions\src\Page.php:56
filterself_admin_urljetpack_vendor\quadlayers\wp-plugin-suggestions\src\Table.php:52
filternetwork_admin_urljetpack_vendor\quadlayers\wp-plugin-suggestions\src\Table.php:53
filterplugin_row_metajetpack_vendor\quadlayers\wp-plugin-table-links\src\Load.php:36
actioninitvendor_packages\wp-notice-plugin-promote.php:4
actioninitvendor_packages\wp-plugin-table-links.php:4
actionbefore_woocommerce_initwoocommerce-checkout-manager.php:83
Maintenance & Trust

Checkout Field Manager (Checkout Manager) for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version5.6
Downloads6.5M

Community Trust

Rating90/100
Number of ratings780
Active installs90K
Developer Profile

Checkout Field Manager (Checkout Manager) for WooCommerce Developer Profile

quadlayers

17 plugins · 654K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
501 days
View full developer profile
Detection Fingerprints

How We Detect Checkout Field Manager (Checkout Manager) for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-checkout-manager/assets/css/frontend.css/wp-content/plugins/woocommerce-checkout-manager/assets/css/admin.css/wp-content/plugins/woocommerce-checkout-manager/assets/js/frontend.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/admin.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/libs/inputmask/inputmask.min.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/libs/sweetalert2/sweetalert2.min.js
Script Paths
/wp-content/plugins/woocommerce-checkout-manager/assets/js/frontend.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/admin.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/libs/inputmask/inputmask.min.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/libs/sweetalert2/sweetalert2.min.js
Version Parameters
woocommerce-checkout-manager/assets/css/frontend.css?ver=woocommerce-checkout-manager/assets/css/admin.css?ver=woocommerce-checkout-manager/assets/js/frontend.js?ver=woocommerce-checkout-manager/assets/js/admin.js?ver=woocommerce-checkout-manager/assets/js/libs/inputmask/inputmask.min.js?ver=woocommerce-checkout-manager/assets/js/libs/sweetalert2/sweetalert2.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wooccm-wrapperwooccm-checkout-fieldwooccm-form-rowwooccm-admin-sectionwooccm-field-settings
Data Attributes
data-wooccm-field-iddata-wooccm-field-type
JS Globals
wooccm_params
FAQ

Frequently Asked Questions about Checkout Field Manager (Checkout Manager) for WooCommerce