
Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Security & Risk Analysis
wordpress.org/plugins/woocommerce-extra-price-fieldsExtra Price Fields for Woocommerce is Plugin for adding extra price description to show in front end.
Is Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Safe to Use in 2026?
Generally Safe
Score 100/100Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "woocommerce-extra-price-fields" v2.0.1 plugin indicates a remarkably strong security posture. The absence of any identified dangerous functions, external HTTP requests, file operations, or direct SQL queries (all SQL queries utilize prepared statements) is commendable. Furthermore, the perfect scores for output escaping and the complete lack of any identified taint flows suggest that the code is designed with security in mind, preventing common injection and data leakage vulnerabilities.
However, the analysis does reveal some areas for concern, primarily related to the plugin's attack surface and authentication mechanisms. The complete absence of nonce checks and capability checks across all entry points is a significant weakness. While the current attack surface appears small (0 AJAX, REST API, shortcodes, or cron events), this lack of built-in protection means that if any new entry points are introduced in future versions, they will inherently be unprotected. The plugin's vulnerability history is also clean, with no recorded CVEs. This is a positive sign, but the lack of security checks in the code itself means the plugin relies heavily on its current lack of exposure rather than inherent security measures.
In conclusion, while the "woocommerce-extra-price-fields" v2.0.1 plugin demonstrates excellent coding practices concerning dangerous functions, SQL, and output handling, its complete disregard for nonce and capability checks presents a notable risk. This omission creates a potential for vulnerabilities if the attack surface expands or if unintended access routes are discovered. The clean vulnerability history is a strength, but it should not be mistaken for inherent invulnerability given the identified gaps in authentication.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Security Vulnerabilities
Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Release Timeline
Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Code Analysis
Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Attack Surface
WordPress Hooks 6
Maintenance & Trust
Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Maintenance & Trust
Maintenance Signals
Community Trust
Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Alternatives
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Mollie Payments for WooCommerce
mollie-payments-for-woocommerce
Accept all major payment methods in WooCommerce today. Credit cards, iDEAL and more! Fast, safe and intuitive.
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
Mercado Pago payments for WooCommerce
woocommerce-mercadopago
Offer to your clients the best experience in e-Commerce by using Mercado Pago as your payment method.
WPML Multilingual & Multicurrency for WooCommerce
woocommerce-multilingual
Make your store multilingual and enable multiple currencies.
Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Developer Profile
11 plugins · 8K total installs
How We Detect Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wc_input_price_extra_infowc_input_price_extra_info_positionpro_price_extra_info