Bootstrap one page woocommerce checkout Security & Risk Analysis

wordpress.org/plugins/bootstrap-one-page-woocommerce-checkout

Bootstrap one page woocommerce checkout, that show chekout and card in one page.

200 active installs v1.1.1 PHP + WP 1.0.1+ Updated Jul 6, 2015
one-page-checkoutproductsshopwoocommercewoocommerce-checkout
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bootstrap one page woocommerce checkout Safe to Use in 2026?

Generally Safe

Score 85/100

Bootstrap one page woocommerce checkout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin "bootstrap-one-page-woocommerce-checkout" v1.1.1 exhibits a mixed security posture. On the positive side, there are no known CVEs, dangerous functions are absent, and all SQL queries are properly prepared. The absence of file operations and external HTTP requests also contributes to a lower risk profile. However, significant concerns arise from the static analysis.

The plugin has a very limited attack surface with only one shortcode, and notably, zero entry points require authentication. The primary area of concern is the complete lack of output escaping, meaning any data displayed to users, even if originating from trusted sources, is not protected against injection attacks. Additionally, the taint analysis revealed two flows with unsanitized paths, indicating a potential for path traversal or related vulnerabilities, although the severity was not classified as critical or high.

The plugin's history of zero known vulnerabilities is a strong positive indicator of good development practices over time. However, this history, combined with the current code analysis findings, suggests that while past development may have been secure, the current version has critical flaws in output handling and potentially path sanitization. The lack of capability checks and nonce checks on its single entry point further exacerbates these risks, as an unauthenticated user could potentially leverage these flaws.

Key Concerns

  • Unescaped output detected
  • Flows with unsanitized paths found
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Bootstrap one page woocommerce checkout Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bootstrap one page woocommerce checkout Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
bd_setting_checkout_page (includes\setting.php:7)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bootstrap one page woocommerce checkout Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bd_woocommerce_one_page_checkout] includes\functions.php:10
WordPress Hooks 4
filteradd_to_cart_redirectincludes\functions.php:2
actionwp_headincludes\functions.php:29
actionadmin_headincludes\functions.php:55
actionadmin_menuincludes\setting.php:2
Maintenance & Trust

Bootstrap one page woocommerce checkout Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJul 6, 2015
PHP min version
Downloads17K

Community Trust

Rating100/100
Number of ratings6
Active installs200
Developer Profile

Bootstrap one page woocommerce checkout Developer Profile

Mahabub Hasan

4 plugins · 380 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bootstrap one page woocommerce checkout

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bootstrap-one-page-woocommerce-checkout/assets/css/style.css/wp-content/plugins/bootstrap-one-page-woocommerce-checkout/assets/js/custom.js
Script Paths
/wp-content/plugins/bootstrap-one-page-woocommerce-checkout/assets/js/custom.js
Version Parameters
bootstrap-one-page-woocommerce-checkout/assets/css/style.css?ver=bootstrap-one-page-woocommerce-checkout/assets/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
bd_woocommerce_one_page_checkoutcol-md-6col-md-12
Shortcode Output
[bd_woocommerce_one_page_checkout]
FAQ

Frequently Asked Questions about Bootstrap one page woocommerce checkout