Complimentary greetings card for WooCommerce Security & Risk Analysis

wordpress.org/plugins/byconsole-greetingcard

Let you customers choose a complimentary greetings card on checkout page.

10 active installs v1.0.2 PHP 5.2.4+ WP 3.5+ Updated Aug 26, 2019
byconsolegreeting-cardwoocommercewoocommerce-greetings-card
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Complimentary greetings card for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Complimentary greetings card for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The byconsole-greetingcard plugin v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate a positive approach to secure coding, with all SQL queries utilizing prepared statements and no dangerous functions, file operations, or external HTTP requests being detected. The plugin also shows an absence of bundled libraries, which can often be a source of vulnerabilities if not managed properly.

However, a significant concern arises from the very low percentage of properly escaped output (19%). This suggests that a substantial amount of user-supplied or dynamically generated data is being outputted without sufficient sanitization, leaving the plugin vulnerable to Cross-Site Scripting (XSS) attacks. While taint analysis shows no flows with unsanitized paths, the high proportion of unescaped output is a direct indicator of potential XSS vulnerabilities that may not have been captured by the current taint analysis scope or might be context-dependent. The lack of any recorded vulnerability history is a positive indicator, but it's important to note that this could also be due to the plugin's limited scope and attack surface, or simply a lack of past diligent security auditing.

In conclusion, the plugin's strength lies in its minimal attack surface and robust handling of database operations. The primary weakness and area of significant risk is the widespread lack of output escaping, which presents a clear XSS vulnerability. The absence of vulnerability history is encouraging but should not be solely relied upon given the identified output escaping issue. Developers should prioritize addressing the output escaping deficiencies to mitigate the risk of XSS.

Key Concerns

  • Poor output escaping
Vulnerabilities
None known

Complimentary greetings card for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Complimentary greetings card for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

19% escaped21 total outputs
Attack Surface

Complimentary greetings card for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionwp_enqueue_scriptsByconsoleCusGreetingCard.php:65
actionwp_enqueue_scriptsByconsoleCusGreetingCard.php:87
actionwoocommerce_after_order_notesByconsoleCusGreetingCard.php:91
actionwoocommerce_checkout_update_order_metaByconsoleCusGreetingCard.php:321
actionwoocommerce_admin_order_data_after_shipping_addressByconsoleCusGreetingCard.php:347
actionwoocommerce_order_details_after_order_table_itemsByconsoleCusGreetingCard.php:379
actionwoocommerce_email_after_order_tableByconsoleCusGreetingCard.php:411
actionadmin_menuinc\admin.php:5
actionadmin_initinc\admin.php:299
Maintenance & Trust

Complimentary greetings card for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedAug 26, 2019
PHP min version5.2.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Complimentary greetings card for WooCommerce Developer Profile

mdalabar

5 plugins · 560 total installs

71
trust score
Avg Security Score
76/100
Avg Patch Time
71 days
View full developer profile
Detection Fingerprints

How We Detect Complimentary greetings card for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/byconsole-greetingcard/css/style.css/wp-content/plugins/byconsole-greetingcard/js/card-preview.js
Script Paths
/wp-content/plugins/byconsole-greetingcard/js/card-preview.js
Version Parameters
byconsole-greetingcard/css/style.css?ver=byconsole-greetingcard/js/card-preview.js?ver=

HTML / DOM Fingerprints

CSS Classes
select_demo_card_sectionbyconsolecusgreetcard_radio_boxbyconsole_card_crossbyconsole_cusgcard_iframebyconsole_cusgcard_contenierbyconsole_cusgcard_trigger
Data Attributes
byconsolecusgreetcard_radio_box
Shortcode Output
<div class="select_demo_card_section"> <h3>Select your card</h3>
FAQ

Frequently Asked Questions about Complimentary greetings card for WooCommerce