YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce Security & Risk Analysis

wordpress.org/plugins/yeecommerce-conditional-checkout-for-woocommerce

Create advanced conditional rules to control checkout behavior, payment methods, shipping destinations, and customer eligibility in WooCommerce.

0 active installs v1.0.2 PHP + WP 5.0+ Updated Feb 26, 2026
checkout-rulesconditional-checkoutconditional-paymentsconditional-shippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

Based on the provided static analysis, the "yeecommerce-conditional-checkout-for-woocommerce" plugin v1.0.2 exhibits a strong security posture in several key areas. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are excellent indicators of secure coding practices. Furthermore, the presence of nonce and capability checks on all identified entry points, including AJAX handlers, significantly mitigates the risk of common web attacks like Cross-Site Request Forgery (CSRF) and unauthorized access. The plugin also has no recorded vulnerability history, which suggests a history of responsible development and maintenance.

However, the static analysis did reveal two flows with unsanitized paths in the taint analysis. While these did not reach a critical or high severity in the provided data, they represent a potential area of concern. The presence of any unsanitized path, even if currently benign, could be exploited if a new vulnerability is introduced in future updates or if the context of their use changes. The relatively small attack surface (3 AJAX handlers) and the fact that all are protected are positive, but the taint analysis findings warrant attention to ensure these paths are robustly handled to prevent future security issues.

In conclusion, the plugin is generally well-secured, demonstrating good practices in critical areas like SQL handling, output escaping, and authentication checks. The lack of known CVEs and the protected entry points are significant strengths. The primary weakness identified is the presence of unsanitized paths in taint flows, which, while not currently rated as severe, should be reviewed and remediated as a proactive security measure.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce Release Timeline

v1.0.1
v1..0.2
Code Analysis
Analyzed Apr 16, 2026

YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
349 escaped
Nonce Checks
5
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped350 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
handle_rule_submission (backend/settings.php:111)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_yeekit_search_termsbackend/settings.php:14
authwp_ajax_yeekit_search_productsbackend/settings.php:16
authwp_ajax_yeekit_search_shipping_methodsbackend/settings.php:18
WordPress Hooks 10
filterwoocommerce_settings_tabs_arraybackend/settings.php:10
actionadmin_enqueue_scriptsbackend/settings.php:12
actionadmin_initbackend/settings.php:19
filterwoocommerce_available_payment_gatewaysfrontend/checkout.php:8
filterwoocommerce_package_ratesfrontend/checkout.php:9
filterwoocommerce_checkout_fieldsfrontend/checkout.php:10
actionwoocommerce_checkout_processfrontend/checkout.php:12
actionwoocommerce_checkout_update_order_reviewfrontend/checkout.php:14
actionwoocommerce_store_api_checkout_update_order_from_requestfrontend/checkout.php:16
actionbefore_woocommerce_inityeecommerce-conditional-checkout-for-woocommerce.php:26
Maintenance & Trust

YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version
Downloads193

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce Developer Profile

add-ons.org

59 plugins · 26K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
48 days
View full developer profile
Detection Fingerprints

How We Detect YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yeecommerce-conditional-checkout-for-woocommerce/assets/admin-rules.css/wp-content/plugins/yeecommerce-conditional-checkout-for-woocommerce/assets/admin-rules.js
Script Paths
/wp-content/plugins/yeecommerce-conditional-checkout-for-woocommerce/assets/admin-rules.js
Version Parameters
yeecommerce-conditional-checkout-for-woocommerce/assets/admin-rules.css?ver=yeecommerce-conditional-checkout-for-woocommerce/assets/admin-rules.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-tab="yeekit_conditional_checkout"
JS Globals
yeekitAdmin
REST Endpoints
/wp-json/yeekit/v1/search/products/wp-json/yeekit/v1/search/shipping-methods/wp-json/yeekit/v1/search/terms
FAQ

Frequently Asked Questions about YeeCheckout – Conditional Payments, Shipping & Fields for WooCommerce