
Checkout Field Manager (Checkout Manager) for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-checkout-managerCheckout Field Manager (Checkout Manager) for WooCommerce is the most advanced plugin to customize checkout fields on your WooCommerce checkout page.
Is Checkout Field Manager (Checkout Manager) for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Checkout Field Manager (Checkout Manager) for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The WooCommerce Checkout Manager plugin v7.8.8 exhibits a mixed security posture. On the positive side, the static analysis reveals a zero-attack surface for AJAX handlers, REST API routes, shortcodes, and cron events, with no identified dangerous functions. The plugin also demonstrates good practices in output escaping, with 93% of outputs properly handled, and includes nonce and capability checks. However, the presence of two SQL queries that do not utilize prepared statements is a significant concern, potentially leading to SQL injection vulnerabilities. The plugin also makes one external HTTP request, which could be a vector for various attacks if not handled securely.
The plugin's vulnerability history is a major red flag. With a total of 5 known CVEs, including one high-severity vulnerability, and past occurrences of missing authorization and cross-site scripting, it indicates a pattern of past security weaknesses. The fact that there are currently no unpatched vulnerabilities is a positive sign, but the history suggests a need for continued vigilance and thorough auditing. The last recorded vulnerability in 2026 suggests the data might be future-looking or include placeholders, but the historical trends remain a valid concern.
In conclusion, while the current version shows some improvements in its attack surface and output escaping, the reliance on raw SQL queries and the concerning history of multiple vulnerabilities, particularly those related to authorization and XSS, necessitate caution. Developers should prioritize addressing the unparameterized SQL queries and remain aware of the plugin's past security issues when considering its use.
Key Concerns
- SQL queries without prepared statements
- History of multiple CVEs
- High-severity vulnerability in history
- Common vulnerability types: Missing Authorization
- Common vulnerability types: Cross-site Scripting
- External HTTP requests
Checkout Field Manager (Checkout Manager) for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.5 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
Checkout Field Manager (Checkout Manager) for WooCommerce <= 7.8.1 - Unauthenticated Limited File Upload
WooCommerce Checkout Manager <= 7.3.0 - Missing Authorization
Checkout Fields Manager for WooCommerce <= 5.5.6 - Reflected Cross-Site Scripting
WooCommerce Checkout Manager <= 4.2.6 - Unauthenticated Arbitrary Media Deletion
Checkout Field Manager (Checkout Manager) for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Checkout Field Manager (Checkout Manager) for WooCommerce Attack Surface
WordPress Hooks 21
Maintenance & Trust
Checkout Field Manager (Checkout Manager) for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Checkout Field Manager (Checkout Manager) for WooCommerce Alternatives
Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager
flexible-checkout-fields
The best WooCommerce checkout manager. Edit, remove or add checkout fields. Customize WooCommerce checkout with this checkout field customizer.
Checkout Field Editor and Manager for WooCommerce
extra-checkout-fields-for-woocommerce
A simple WooCommerce Checkout Field Editor and Manager plugin to edit WooCommerce checkout fields, add custom checkout fields and more.
Checkout Field Editor for WooCommerce – Checkout Manager
checkout-field-editor-and-manager-for-woocommerce
WooCommerce checkout field editor and manager helps to manage checkout fields in WooCommerce
Custom WooCommerce Checkout Fields Editor
add-fields-to-checkout-page-woocommerce
Custom WooCommerce Checkout Fields Editor
Checkout Field Editor for WooCommerce – Checkout Page Manager
woo-checkout-regsiter-field-editor
Checkout Field Editor for WooCommerce is the leading plugin for customizing, editing, removing, and managing your WooCommerce checkout fields.
Checkout Field Manager (Checkout Manager) for WooCommerce Developer Profile
17 plugins · 654K total installs
How We Detect Checkout Field Manager (Checkout Manager) for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-checkout-manager/assets/css/frontend.css/wp-content/plugins/woocommerce-checkout-manager/assets/css/admin.css/wp-content/plugins/woocommerce-checkout-manager/assets/js/frontend.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/admin.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/libs/inputmask/inputmask.min.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/libs/sweetalert2/sweetalert2.min.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/frontend.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/admin.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/libs/inputmask/inputmask.min.js/wp-content/plugins/woocommerce-checkout-manager/assets/js/libs/sweetalert2/sweetalert2.min.jswoocommerce-checkout-manager/assets/css/frontend.css?ver=woocommerce-checkout-manager/assets/css/admin.css?ver=woocommerce-checkout-manager/assets/js/frontend.js?ver=woocommerce-checkout-manager/assets/js/admin.js?ver=woocommerce-checkout-manager/assets/js/libs/inputmask/inputmask.min.js?ver=woocommerce-checkout-manager/assets/js/libs/sweetalert2/sweetalert2.min.js?ver=HTML / DOM Fingerprints
wooccm-wrapperwooccm-checkout-fieldwooccm-form-rowwooccm-admin-sectionwooccm-field-settingsdata-wooccm-field-iddata-wooccm-field-typewooccm_params