
WP e-Commerce Call for Price Security & Risk Analysis
wordpress.org/plugins/wp-e-commerce-call-for-priceThis is a WP e-Commerce plugin that allows you to hide the price of a specific product and replace it with a message asking your customers to call for …
Is WP e-Commerce Call for Price Safe to Use in 2026?
Generally Safe
Score 85/100WP e-Commerce Call for Price has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp-e-commerce-call-for-price" v1.0 exhibits a generally positive security posture based on the static analysis provided. The absence of any identified CVEs in its history, coupled with the low complexity of its attack surface (zero AJAX, REST API, shortcodes, or cron events), suggests a history of responsible development and maintenance. The code analysis also reveals good practices in handling SQL queries, with 100% of them utilizing prepared statements, which significantly mitigates SQL injection risks. File operations and external HTTP requests are also absent, further reducing potential attack vectors.
However, a significant concern arises from the output escaping. With 37 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend without proper sanitization or escaping can be exploited by attackers to inject malicious scripts. Additionally, the lack of nonce checks on any potential entry points, while the attack surface is currently zero, means that if new entry points are added in the future without proper security measures, they would be immediately vulnerable.
In conclusion, while the plugin avoids many common pitfalls like vulnerable SQL queries or unpatched CVEs, the pervasive lack of output escaping is a critical weakness that requires immediate attention. The developers have demonstrated good practices in other areas, but this oversight leaves the plugin susceptible to XSS attacks. Addressing the output escaping issue is paramount to improving its overall security.
Key Concerns
- 0% output escaping
- 0 nonce checks
WP e-Commerce Call for Price Security Vulnerabilities
WP e-Commerce Call for Price Code Analysis
SQL Query Safety
Output Escaping
WP e-Commerce Call for Price Attack Surface
WordPress Hooks 12
Maintenance & Trust
WP e-Commerce Call for Price Maintenance & Trust
Maintenance Signals
Community Trust
WP e-Commerce Call for Price Alternatives
GoUrl WP eCommerce – Bitcoin Altcoin Payment Gateway Addon
gourl-wp-ecommerce-bitcoin-altcoin-payment-gateway-addon
Provides Bitcoin/Altcoin Payment Gateway for WP eCommerce 3.8.10+ or higher. Accept Bitcoin, Bitcoin Cash, Litecoin, Dogecoin, Dash, etc Payments on Y …
Amazing WP e-Commerce
amazing-wp-e-commerce
Enable some of the WP e-Commerce disabled features and simplify your development.
qTranslate loves WPEC
qtranslate-loves-wp-e-commerce
Adds translatable form fields for wp e-commerce taxonomies (product categories, variations and product tags).
ShippingEasy for WP e-Commerce
shippingeasy-for-wp-ecommerce
ShippingEasy is a powerful online shipping platform that integrates seamlessly with your WordPress WP e-Commerce store to give you a complete end-to-e …
DropStream – Automated eCommerce Fulfillment
wp-dropstream
DropStream is a powerful eCommerce plugin that integrates your WordPress site with your shipping solution or third-party fulfillment provider, allowin …
WP e-Commerce Call for Price Developer Profile
1 plugin · 10 total installs
How We Detect WP e-Commerce Call for Price
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-e-commerce-call-for-price/js/admin.js/wp-content/plugins/wp-e-commerce-call-for-price/js/front.js/wp-content/plugins/wp-e-commerce-call-for-price/css/style.css/wp-content/plugins/wp-e-commerce-call-for-price/js/admin.js/wp-content/plugins/wp-e-commerce-call-for-price/js/front.jswp-e-commerce-call-for-price/css/style.css?ver=wp-e-commerce-call-for-price/js/admin.js?ver=wp-e-commerce-call-for-price/js/front.js?ver=HTML / DOM Fingerprints
cfp_iconsselecteddata-cfp-idcfp_selected_icon