Custom Thank You Page Customize For WooCommerce by Binary Carpenter Security & Risk Analysis

wordpress.org/plugins/bc-woo-custom-thank-you-pages

Create thank you pages for all products, per products or per category

2K active installs v1.4.22 PHP 5.3+ WP 5.0+ Updated Mar 3, 2025
custom-thank-you-pagethank-you-pagethank-you-page-builderwoocommercewoocommerce-thank-you-page
91
A · Safe
CVEs total1
Unpatched0
Last CVEApr 15, 2024
Safety Verdict

Is Custom Thank You Page Customize For WooCommerce by Binary Carpenter Safe to Use in 2026?

Generally Safe

Score 91/100

Custom Thank You Page Customize For WooCommerce by Binary Carpenter has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 15, 2024Updated 1yr ago
Risk Assessment

The "bc-woo-custom-thank-you-pages" plugin v1.4.22 exhibits a mixed security posture. While it shows strengths in SQL query handling and output escaping, there are significant concerns regarding its attack surface and past vulnerability history. The presence of one unprotected AJAX handler represents a clear entry point that could be exploited without proper authorization checks. The use of the `unserialize` function is also a red flag, as it can lead to remote code execution if user-supplied data is unserialized without strict validation.

The vulnerability history indicates a past medium-severity vulnerability, specifically related to missing authorization. This pattern, coupled with the current unprotected AJAX handler, suggests a recurring issue with ensuring adequate access controls on plugin entry points. While there are no currently unpatched CVEs, the history and code analysis point to potential weaknesses that require attention. Overall, the plugin has some good security practices in place, but the unprotected AJAX endpoint and the past authorization vulnerability warrant caution and further investigation.

Key Concerns

  • Unprotected AJAX handler
  • Dangerous function 'unserialize' used
  • Past medium vulnerability (Missing Authorization)
Vulnerabilities
1

Custom Thank You Page Customize For WooCommerce by Binary Carpenter Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-32517medium · 4.3Missing Authorization

Custom Thank You Page Customize For WooCommerce by Binary Carpenter <= 1.4.13 - Missing Authorization

Apr 15, 2024 Patched in 1.4.14 (9d)
Code Analysis
Analyzed Mar 16, 2026

Custom Thank You Page Customize For WooCommerce by Binary Carpenter Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
15
57 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserializereturn unserialize(get_post_meta($this->post_id, $key, true));inc\BC_Options.php:142

Output Escaping

79% escaped72 total outputs
Attack Surface
1 unprotected

Custom Thank You Page Customize For WooCommerce by Binary Carpenter Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_bc_tk_activate_licenseInitiator.php:67
WordPress Hooks 9
actioninitinc\BC_Options.php:99
actionadmin_menuInitiator.php:54
actionadmin_enqueue_scriptsInitiator.php:58
actiontemplate_redirectInitiator.php:61
actioninitInitiator.php:65
actionbefore_woocommerce_initInitiator.php:69
filterwoocommerce_is_order_received_pageInitiator.php:75
actionwoocommerce_thankyouInitiator.php:78
actionplugin_loadedInitiator.php:688
Maintenance & Trust

Custom Thank You Page Customize For WooCommerce by Binary Carpenter Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.1.
Last updatedMar 3, 2025
PHP min version5.3
Downloads52K

Community Trust

Rating94/100
Number of ratings13
Active installs2K
Developer Profile

Custom Thank You Page Customize For WooCommerce by Binary Carpenter Developer Profile

BinaryCarpenter

7 plugins · 3K total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect Custom Thank You Page Customize For WooCommerce by Binary Carpenter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bc-woo-custom-thank-you-pages/bundle/css/backend.css/wp-content/plugins/bc-woo-custom-thank-you-pages/bundle/js/backend-bundle.js
Script Paths
bundle/js/backend-bundle.js
Version Parameters
bc-woo-custom-thank-you-pages/bundle/css/backend.css?ver=bc-woo-custom-thank-you-pages/bundle/js/backend-bundle.js?ver=

HTML / DOM Fingerprints

CSS Classes
bctk-options-form-wrapper
HTML Comments
<!-- This is the main wrapper -->
Data Attributes
data-option-namedata-field-id
JS Globals
BC_TK_AJAX_URLBC_TK_NONCE
REST Endpoints
/wp-json/bc-tk/v1/options
Shortcode Output
[bc_tk_thank_you_message][bc_tk_customer_details][bc_tk_order_summary]
FAQ

Frequently Asked Questions about Custom Thank You Page Customize For WooCommerce by Binary Carpenter