
WPC Name Your Price for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wpc-name-your-priceA simple plugin for enabling open pricing and letting your customers request a preferred price to pay or make a donation of their choice.
Is WPC Name Your Price for WooCommerce Safe to Use in 2026?
Generally Safe
Score 97/100WPC Name Your Price for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The 'wpc-name-your-price' v2.2.2 plugin exhibits a generally strong security posture, with a commendable emphasis on secure coding practices such as using prepared statements for all SQL queries and a very high rate of proper output escaping. The lack of direct entry points like shortcodes and cron events, along with protected AJAX handlers and REST API routes, further contributes to a reduced attack surface. However, the presence of the `unserialize` function is a notable concern, as it can lead to deserialization vulnerabilities if not handled with extreme caution and proper input validation.
The vulnerability history, while showing no currently unpatched CVEs, does indicate a past high-severity vulnerability. The nature of this vulnerability being 'Client-Side Enforcement of Server-Side Security' suggests a pattern of potential issues that might arise from how the plugin interacts with user input or relies on front-end validation for security, which is inherently less secure than server-side validation. While the static analysis shows no direct taint flows indicating immediate critical or high risks, the combination of the dangerous function and past vulnerability type warrants careful monitoring and potential review.
In conclusion, the plugin demonstrates many strengths in its security implementation, particularly regarding data handling and input validation. The core code appears robust. Nevertheless, the inherent risks associated with `unserialize` and the historical context of past vulnerabilities necessitate vigilance. Developers should ensure all instances of `unserialize` are strictly controlled and that future development prioritizes robust server-side validation to prevent similar past issues from recurring.
Key Concerns
- Use of dangerous unserialize function
- Past high severity vulnerability
WPC Name Your Price for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price Alteration
WPC Name Your Price for WooCommerce Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WPC Name Your Price for WooCommerce Attack Surface
AJAX Handlers 5
WordPress Hooks 25
Maintenance & Trust
WPC Name Your Price for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WPC Name Your Price for WooCommerce Alternatives
WPC Smart Quick View for WooCommerce
woo-smart-quick-view
WPC Smart Quick View allows users to get a quick look at products without opening the product page.
WPC Smart Wishlist for WooCommerce
woo-smart-wishlist
WPC Smart Wishlist is a simple but powerful tool that can help your customer save products for buying later.
WPC Smart Compare for WooCommerce
woo-smart-compare
It helps customers compare products with mighty AJAX, doesn't require opening a new page or iframe, and allows drag-and-drop functionality.
Product Addons for Woocommerce – Product Options with Custom Fields
woo-custom-product-addons
WooCommerce Product Addons Add custom fields to your WooCommerce product page. With an easy-to-use Custom Form Builder.
WPC Product Bundles for WooCommerce
woo-product-bundle
WPC Product Bundles is a plugin that helps you bundle a few products, offer them at a discount, and watch the sales go up!
WPC Name Your Price for WooCommerce Developer Profile
71 plugins · 441K total installs
How We Detect WPC Name Your Price for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpc-name-your-price/assets/css/backend.css/wp-content/plugins/wpc-name-your-price/assets/js/backend.js/wp-content/plugins/wpc-name-your-price/assets/css/frontend.css/wp-content/plugins/wpc-name-your-price/assets/js/frontend.js/wp-content/plugins/wpc-name-your-price/assets/js/backend.js/wp-content/plugins/wpc-name-your-price/assets/js/frontend.jswpc-name-your-price/assets/css/backend.css?ver=wpc-name-your-price/assets/js/backend.js?ver=wpc-name-your-price/assets/css/frontend.css?ver=wpc-name-your-price/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wpclever_settings_pagewpclever_settings_page_headerwpclever_settings_page_header_logowpclever_settings_page_header_textwpclever_settings_page_titlewoonp-backenddata-roundingdata-default_valuedata-price_decimalswoonp_vars