Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Security & Risk Analysis

wordpress.org/plugins/woocommerce-extra-price-fields

Extra Price Fields for Woocommerce is Plugin for adding extra price description to show in front end.

2K active installs v2.0.1 PHP + WP 3.0.0+ Updated Sep 22, 2025
ecommercewoocommercewoocommerce-price-extension
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Safe to Use in 2026?

Generally Safe

Score 100/100

Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The static analysis of the "woocommerce-extra-price-fields" v2.0.1 plugin indicates a remarkably strong security posture. The absence of any identified dangerous functions, external HTTP requests, file operations, or direct SQL queries (all SQL queries utilize prepared statements) is commendable. Furthermore, the perfect scores for output escaping and the complete lack of any identified taint flows suggest that the code is designed with security in mind, preventing common injection and data leakage vulnerabilities.

However, the analysis does reveal some areas for concern, primarily related to the plugin's attack surface and authentication mechanisms. The complete absence of nonce checks and capability checks across all entry points is a significant weakness. While the current attack surface appears small (0 AJAX, REST API, shortcodes, or cron events), this lack of built-in protection means that if any new entry points are introduced in future versions, they will inherently be unprotected. The plugin's vulnerability history is also clean, with no recorded CVEs. This is a positive sign, but the lack of security checks in the code itself means the plugin relies heavily on its current lack of exposure rather than inherent security measures.

In conclusion, while the "woocommerce-extra-price-fields" v2.0.1 plugin demonstrates excellent coding practices concerning dangerous functions, SQL, and output handling, its complete disregard for nonce and capability checks presents a notable risk. This omission creates a potential for vulnerabilities if the attack surface expands or if unintended access routes are discovered. The clean vulnerability history is a strength, but it should not be mistaken for inherent invulnerability given the identified gaps in authentication.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
Vulnerabilities
None known

Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Release Timeline

v2.0.1Current
v1.5.2
v1.5.1
v1.5
v1.2
v1.1.1
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwoocommerce_product_options_advancedwoocommerce-extra-price-fields.php:52
actionwoocommerce_product_options_general_product_datawoocommerce-extra-price-fields.php:54
actionwoocommerce_process_product_metawoocommerce-extra-price-fields.php:72
actionwoocommerce_process_product_meta_variablewoocommerce-extra-price-fields.php:73
filterwoocommerce_get_price_htmlwoocommerce-extra-price-fields.php:110
filterwoocommerce_get_variation_price_htmlwoocommerce-extra-price-fields.php:111
Maintenance & Trust

Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 22, 2025
PHP min version
Downloads35K

Community Trust

Rating96/100
Number of ratings13
Active installs2K
Developer Profile

Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products Developer Profile

Aman

11 plugins · 8K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
138 days
View full developer profile
Detection Fingerprints

How We Detect Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wc_input_price_extra_infowc_input_price_extra_info_positionpro_price_extra_info
FAQ

Frequently Asked Questions about Extra Price Fields for Woocommerce- Display extra price info on Woocommerce products