Boxy WooCommerce Custom Redirect After Checkout Security & Risk Analysis

wordpress.org/plugins/boxy-woocommerce-custom-redirect-after-checkout

Redirect users to a custom URL after successful WooCommerce checkout.

900 active installs v1.0.3 PHP 7.4+ WP 5.8+ Updated Mar 9, 2026
checkoutredirectwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Boxy WooCommerce Custom Redirect After Checkout Safe to Use in 2026?

Generally Safe

Score 100/100

Boxy WooCommerce Custom Redirect After Checkout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 26d ago
Risk Assessment

The plugin "boxy-woocommerce-custom-redirect-after-checkout" version 1.0.4 exhibits a generally strong security posture based on the provided static analysis. The complete absence of identified dangerous functions, raw SQL queries, and file operations is commendable. Furthermore, the high percentage of properly escaped output (89%) suggests a good effort to prevent cross-site scripting vulnerabilities. The plugin also has no known vulnerabilities, which is a positive indicator of its security development lifecycle.

However, a significant concern arises from the complete lack of nonce checks and capability checks across all identified entry points, which are zero. While the attack surface appears minimal with no direct AJAX handlers, REST API routes, shortcodes, or cron events exposed, any future expansion or introduction of such features without proper authentication and authorization mechanisms would pose a substantial risk. The bundled Freemius library, version 1.0, could also be an area for attention if it's outdated and contains known vulnerabilities, though this is not explicitly stated in the provided data.

In conclusion, while the current version of the plugin seems secure due to its limited functionality and code hygiene, the lack of any implemented authorization and nonce checks represents a potential future weakness. This suggests a need for caution and careful review if the plugin's functionality expands or if it's integrated into sensitive environments. The absence of any recorded vulnerabilities is a strength, but it should not lead to complacency, especially concerning the unaddressed authorization mechanisms.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Bundled Freemius v1.0 potentially outdated
Vulnerabilities
None known

Boxy WooCommerce Custom Redirect After Checkout Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Boxy WooCommerce Custom Redirect After Checkout Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
31 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

89% escaped35 total outputs
Attack Surface

Boxy WooCommerce Custom Redirect After Checkout Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuboxy woocommerce custom redirect after checkout .php:75
actionadmin_menuboxy woocommerce custom redirect after checkout .php:123
actionadmin_initboxy woocommerce custom redirect after checkout .php:124
actionadmin_noticesboxy woocommerce custom redirect after checkout .php:125
actionadmin_enqueue_scriptsboxy woocommerce custom redirect after checkout .php:126
actiontemplate_redirectboxy woocommerce custom redirect after checkout .php:712
actionwp_footerboxy woocommerce custom redirect after checkout .php:726
actionplugins_loadedincludes\class-boxy woocommerce custom redirect after checkout .php:139
actionadmin_enqueue_scriptsincludes\class-boxy woocommerce custom redirect after checkout .php:154
actionadmin_enqueue_scriptsincludes\class-boxy woocommerce custom redirect after checkout .php:155
actionwp_enqueue_scriptsincludes\class-boxy woocommerce custom redirect after checkout .php:170
actionwp_enqueue_scriptsincludes\class-boxy woocommerce custom redirect after checkout .php:171
Maintenance & Trust

Boxy WooCommerce Custom Redirect After Checkout Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 9, 2026
PHP min version7.4
Downloads10K

Community Trust

Rating100/100
Number of ratings6
Active installs900
Developer Profile

Boxy WooCommerce Custom Redirect After Checkout Developer Profile

mandeep007

2 plugins · 910 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Boxy WooCommerce Custom Redirect After Checkout

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/boxy-woocommerce-custom-redirect-after-checkout/assets/css/admin.css/wp-content/plugins/boxy-woocommerce-custom-redirect-after-checkout/assets/js/admin.js
Script Paths
/wp-content/plugins/boxy-woocommerce-custom-redirect-after-checkout/assets/js/admin.js
Version Parameters
boxy-woocommerce-custom-redirect-after-checkout/assets/css/admin.css?ver=boxy-woocommerce-custom-redirect-after-checkout/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
boxy-headerboxy-header-leftboxy-header-iconboxy-header-titleboxy-header-versionboxy-upgrade-top-btnboxy-tabsboxy-tab+33 more
HTML Comments
── Header ──── Tabs ──── Layout ──── Cards ──+3 more
Data Attributes
data-tab="general"data-tab="redirects"data-tab="advanced"data-tab="pro"
JS Globals
boxy_redirect_fs
FAQ

Frequently Asked Questions about Boxy WooCommerce Custom Redirect After Checkout