Qvickly Checkout for WooCommerce Security & Risk Analysis

wordpress.org/plugins/billmate-checkout-for-woocommerce

Qvickly Checkout is an embedded checkout solution and includes all popular payment methods, Debit & Credicard, Swish, Invoice, Installment and dir …

100 active installs v1.8.0 PHP 7.4+ WP 5.0+ Updated Feb 20, 2025
billmatecheckoute-commerceecommercewoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Qvickly Checkout for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Qvickly Checkout for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "billmate-checkout-for-woocommerce" v1.8.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points suggests a well-defined and secured attack surface. The code analysis further reinforces this, showing no dangerous functions, all SQL queries using prepared statements, and a high percentage of properly escaped output. The presence of nonce and capability checks, alongside a clean taint analysis with no critical or high severity flows, indicates robust defensive coding practices.

While the plugin demonstrates excellent internal security controls, the primary area for potential concern, albeit minor, lies in the file operations and external HTTP requests. These are standard functionalities for many plugins, but they represent potential vectors if not meticulously handled or if external services are compromised. The lack of any recorded vulnerabilities in its history is a significant positive indicator, suggesting a history of stable and secure development. Overall, this plugin appears to be very secure, with the main areas of vigilance being the external interactions it performs.

Key Concerns

  • No capability checks detected
  • External HTTP requests present
  • File operations present
Vulnerabilities
None known

Qvickly Checkout for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Qvickly Checkout for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
72 escaped
Nonce Checks
5
Capability Checks
0
File Operations
4
External Requests
6
Bundled Libraries
0

Output Escaping

95% escaped76 total outputs
Attack Surface

Qvickly Checkout for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
actionplugins_loadedbillmate-checkout-for-woocommerce.php:82
actionadmin_noticesbillmate-checkout-for-woocommerce.php:247
actionwoocommerce_api_bco_wc_pushclasses\class-bco-api-callbacks.php:42
actionbco_process_push_callbackclasses\class-bco-api-callbacks.php:43
actiontemplate_redirectclasses\class-bco-confirmation.php:38
actiontemplate_redirectclasses\class-bco-display-monthly-cost.php:50
actionwoocommerce_thankyouclasses\class-bco-gateway.php:63
actionwoocommerce_checkout_order_processedclasses\class-bco-gateway.php:64
actionwoocommerce_gateway_titleclasses\class-bco-gateway.php:67
actionwp_enqueue_scriptsclasses\class-bco-gateway.php:70
filterwoocommerce_payment_gatewaysclasses\class-bco-gateway.php:301
filterwc_get_templateclasses\class-bco-templates.php:51
filterwc_get_templateclasses\class-bco-templates.php:54
actionbco_wc_after_wrapperclasses\class-bco-templates.php:58
actionbco_wc_after_order_reviewclasses\class-bco-templates.php:59
actionbco_wc_before_checkout_formclasses\class-bco-templates.php:60
actionbco_wc_before_checkout_formclasses\class-bco-templates.php:61
actionbco_wc_after_order_reviewclasses\class-bco-templates.php:62
actiontemplate_redirectclasses\class-bco-templates.php:65
filterbody_classclasses\class-bco-templates.php:68
filterwoocommerce_enable_order_notes_fieldclasses\class-bco-templates.php:239
filterwoocommerce_enable_order_notes_fieldclasses\class-bco-templates.php:244
actionadd_meta_boxesdependencies\krokedil\woocommerce\src\OrderMetabox.php:59
actionadmin_initdependencies\krokedil\woocommerce\src\OrderMetabox.php:60
Maintenance & Trust

Qvickly Checkout for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 20, 2025
PHP min version7.4
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Qvickly Checkout for WooCommerce Developer Profile

Billmate

2 plugins · 200 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Qvickly Checkout for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/billmate-checkout-for-woocommerce/assets/css/billmate-checkout-gateway.css/wp-content/plugins/billmate-checkout-for-woocommerce/assets/css/billmate-checkout-gateway-admin.css/wp-content/plugins/billmate-checkout-for-woocommerce/assets/js/billmate-checkout-gateway.js
Script Paths
/wp-content/plugins/billmate-checkout-for-woocommerce/assets/js/billmate-checkout-gateway.js
Version Parameters
billmate-checkout-for-woocommerce/assets/css/billmate-checkout-gateway.css?ver=billmate-checkout-for-woocommerce/assets/css/billmate-checkout-gateway-admin.css?ver=billmate-checkout-for-woocommerce/assets/js/billmate-checkout-gateway.js?ver=

HTML / DOM Fingerprints

CSS Classes
billmate-checkout-gateway-wrapperbillmate-checkout-gateway-formbillmate-checkout-monthly-cost
HTML Comments
<!-- Start Billmate Checkout Gateway --><!-- End Billmate Checkout Gateway --><!-- Placeholder for monthly cost calculator -->
Data Attributes
data-bco-containerdata-bco-payment-method
JS Globals
BillmateCheckoutGateway
FAQ

Frequently Asked Questions about Qvickly Checkout for WooCommerce