
YayExtra – WooCommerce Extra Product Options Security & Risk Analysis
wordpress.org/plugins/yayextraYayExtra – Product Options for WooCommerce lets you add customizable options and extra fields to your products.
Is YayExtra – WooCommerce Extra Product Options Safe to Use in 2026?
Generally Safe
Score 93/100YayExtra – WooCommerce Extra Product Options has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "yayextra" v2.0.1 plugin exhibits a generally good security posture based on static analysis, with robust use of prepared statements for SQL queries and high percentages of properly escaped output. The absence of direct file operations and external HTTP requests further strengthens its security. Nonce and capability checks are implemented extensively, covering all identified AJAX entry points, which is a positive indicator of secure development practices for handling user interactions.
However, a significant concern arises from the plugin's vulnerability history. The presence of three known CVEs, including one critical vulnerability, suggests a pattern of past security weaknesses. While no CVEs are currently unpatched, the historical types of vulnerabilities (SQL Injection, Missing Authorization, Unrestricted Upload) indicate recurring security flaws that the developers have had to address. The recent vulnerability in July 2025 is particularly concerning, implying that even recent versions have had exploitable issues.
In conclusion, while "yayextra" v2.0.1 demonstrates good practices in its current static analysis, the historical vulnerability data necessitates caution. The past critical SQL injection, missing authorization, and unrestricted upload vulnerabilities, even if patched, point to potential areas where future vulnerabilities might emerge. Users should remain vigilant and ensure they are always running the latest patched version of the plugin, alongside other WordPress security best practices.
Key Concerns
- History of critical vulnerability
- History of medium vulnerabilities (2)
- Flow with unsanitized path detected
YayExtra – WooCommerce Extra Product Options Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
YayExtra <= 1.5.5 - Authenticated (Administrator+) SQL Injection
YayExtra <= 1.5.2 - Missing Authorization
YayExtra – WooCommerce Extra Product Options <= 1.3.7 - Unauthenticated Arbitrary File Upload via handle_upload_file Function
YayExtra – WooCommerce Extra Product Options Release Timeline
YayExtra – WooCommerce Extra Product Options Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
YayExtra – WooCommerce Extra Product Options Attack Surface
AJAX Handlers 3
WordPress Hooks 55
Maintenance & Trust
YayExtra – WooCommerce Extra Product Options Maintenance & Trust
Maintenance Signals
Community Trust
YayExtra – WooCommerce Extra Product Options Alternatives
Product Addons for Woocommerce – Product Options with Custom Fields
woo-custom-product-addons
WooCommerce Product Addons Add custom fields to your WooCommerce product page. With an easy-to-use Custom Form Builder.
Extra Product Options For WooCommerce | Custom Product Addons and Fields
woo-extra-product-options
WooCommerce Extra Product Options plugin lets you add product addons (custom products field) of 20 different field types to your product page.
PPOM – Product Addons & Custom Fields for WooCommerce
woocommerce-product-addon
Easily add a range of custom fields to WooCommerce products, from text boxes to date selectors, allowing customers to personalize their orders.
YITH WooCommerce Product Add-Ons
yith-woocommerce-product-add-ons
Increase average order value by letting your customers purchase additional options on your products.
Product Addons and Product Options With Custom Fields – WowAddons
product-addons
Product addons for WooCommerce is the ultimate plugin that lets you add extra product options, product fields, and WooCommerce product fields.
YayExtra – WooCommerce Extra Product Options Developer Profile
16 plugins · 78K total installs
How We Detect YayExtra – WooCommerce Extra Product Options
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yayextra/assets/css/yayextra.css/wp-content/plugins/yayextra/assets/js/jquery.datetimepicker.min.js/wp-content/plugins/yayextra/assets/js/yayextra.js/wp-content/plugins/yayextra/assets/js/yayextra.js/wp-content/plugins/yayextra/assets/js/jquery.datetimepicker.min.jsyayextra.css?ver=jquery.datetimepicker.min.js?ver=yayextra.js?ver=HTML / DOM Fingerprints
yay-uiyayextra-sectionid="yayextra-section"yaye_data/yayextra/v1