shouldiuse.io

VERDICT

Should I use FunnelKit?

FunnelKit is the sales funnel builder for WordPress and WooCommerce with conversion optimized templates, frictionless checkout, upsells/downsells and order bumps. - funnelkit.com

Depends. Buy if you run WooCommerce and want order bumps, one-click upsells, and a better checkout on your own WordPress site. Avoid if you're not on WordPress or won't patch security flaws fast.

Confidence

Medium. Based on 20+ public sources: review sites, Reddit threads, CVE databases, and pricing pages.

Ratings

  • Value for money
  • Ease of useNo direct ease-of-use evidence found
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

Lite

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Professional$199.50/yr
Higher bundles$249–$399/yr

Best for

  • WooCommerce stores optimizing order value
  • WordPress sellers replacing ClickFunnels
  • Marketers wanting self-hosted checkout funnels

Not for

  • Non-WordPress or non-WooCommerce sites
  • Stores that won't apply urgent plugin patches
  • Simple shops happy with default WooCommerce checkout
  • Buyers wanting zero-maintenance hosted SaaS

Gotchas - check before you buy

high

Critical checkout vulnerabilities have been actively exploited — patch immediately when alerts land

medium

Upper tiers run $249–$399/year; check renewal pricing, not intro offers

medium

Guess: funnels are built inside WordPress — migrating away means rebuilding them elsewhere

low

Guess: self-hosted automations and large email lists can strain typical shared hosting

Pros and cons

Pros

  • High ratings: 4.8/5 Trustpilot, 5.0 on WPBeginner (270 reviews)
  • All-in-one: checkout, funnels, order bumps, upsells, downsells, automations
  • Free Lite version available
  • Vendor pitches it against rivals charging $300/month
  • One user reports processing 3,000+ orders through it

Cons

  • Critical checkout-skimming vulnerability actively exploited, ~40,000 sites at risk
  • Multiple CVEs: auth bypasses, local file inclusion, stored XSS
  • Automations reportedly takes time to master
  • Automations has fewer features than some rivals like FluentCRM
  • Upper tiers cost $249–$399/year per third-party review

Sources & method

Analyzed 9/21/2026 - 13 sources - Repeat CVEs since 2025, including a critical checkout-skimming flaw actively exploited across ~40,000 sites; fixes shipped in updates.

official x2review x7security x4
  • Actively exploited checkout-skimming flaw in Funnel Builder, Critical vulnerability exploited in the wild, putting ~40,000 WordPress sites at risk of WooCommerce checkout skimming.
  • CVE-2025-1562 — Automations auth bypass, Authentication bypass vulnerability in FunnelKit Automations.
  • CVE-2025-54750 — Local file inclusion, PHP local file inclusion vulnerability in FunnelKit Funnel Builder.
  • Stored XSS in Funnel Builder, Authenticated contributor/author-level stored cross-site scripting vulnerabilities in the plugin.

Key stats

  • Value for money: 3/5

    Rating

  • Free

    Starting price

  • 13

    Sources

  • Analyzed

  • Value for money: 3/5. Capable, but $249–$399/yr at upper tiers
  • Ease of use. No direct ease-of-use evidence found
  • Feature depth: 5/5. All-in-one: checkout, funnels, bumps, upsells, automations
  • Support quality: 4/5. 4.8/5 Trustpilot across 182 reviews
  • Security posture: 2/5. Multiple CVEs; critical flaw actively exploited
  • 4.8/5 Trustpilot rating 182 reviews
  • 5.0/5 G2 rating only 3 reviews
  • Free (Lite) Starting price Professional $199.50/yr
  • 40,300+ Vendor-claimed users store owners

Pricing

Lite

Free

  • Basic funnel and checkout features
  • WordPress.org plugin

Professional

$199.50/yr

  • Full funnel builder and checkout
  • Order bumps, one-click upsells

Higher bundles

$249–$399/yr

  • Adds Automations email marketing
  • Per third-party reviews

Security

Repeat CVEs since 2025, including a critical checkout-skimming flaw actively exploited across ~40,000 sites; fixes shipped in updates.

  • Actively exploited checkout-skimming flaw in Funnel BuilderCritical vulnerability exploited in the wild, putting ~40,000 WordPress sites at risk of WooCommerce checkout skimming.10
  • CVE-2025-1562 — Automations auth bypassAuthentication bypass vulnerability in FunnelKit Automations.12
  • CVE-2025-54750 — Local file inclusionPHP local file inclusion vulnerability in FunnelKit Funnel Builder.
  • Stored XSS in Funnel BuilderAuthenticated contributor/author-level stored cross-site scripting vulnerabilities in the plugin.13

What users say

Reviews skew very positive on checkout and funnel features (4.8/5 Trustpilot; G2 is 5.0 but from just 3 reviews), with some reliability gripes.

“The Best Funnel Builder I've Used…When It Works”
WordPress.org support forum
“I've processed 3,000+ orders with Fun…”
WordPress.org support forum
“FunnelKit has 5 stars!”
Trustpilot reviewer
Full analysis

Based on 20+ public sources: review sites, Reddit threads, CVE databases, and pricing pages.

Well-reviewed WooCommerce funnel builder — but actively exploited checkout CVEs mean you must patch fast.

Methodology

Based on 20+ public sources: review sites, Reddit threads, CVE databases, and pricing pages.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. review
  7. review
  8. official
  9. official
  10. security
  11. security
  12. security
  13. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.