
Checkbox Security & Risk Analysis
wordpress.org/plugins/checkboxПлагін інтеграції WooCommerce з Checkbox.ua, сервісом програмної реєстрації розрахункових операцій (пРРО).
Is Checkbox Safe to Use in 2026?
Generally Safe
Score 99/100Checkbox has a strong security track record. Known vulnerabilities have been patched promptly.
The "checkbox" v2.8.14 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and leveraging WordPress's nonce and capability checks in some areas. The absence of critical or high-severity taint flows is also a positive indicator. However, there are notable areas of concern, particularly with the presence of 3 unprotected AJAX handlers, which represent a significant attack surface without proper authorization checks.
The vulnerability history, while showing no currently unpatched CVEs, does reveal a past medium-severity vulnerability, specifically related to missing authorization. This, combined with the identified unprotected AJAX endpoints, suggests a recurring pattern where authorization is not consistently enforced across all entry points. The plugin also has a moderate number of file operations and external HTTP requests, which, while not inherently dangerous, can become points of vulnerability if not handled with extreme care regarding input validation and sanitization.
In conclusion, while the plugin has strengths in its database interaction and some security checks, the presence of unprotected AJAX handlers is a critical weakness that needs immediate attention. The past vulnerability related to missing authorization further reinforces the need for a comprehensive security audit of all entry points to ensure robust protection against potential exploits.
Key Concerns
- Unprotected AJAX handlers
- Past medium severity vulnerability (Missing Authorization)
- Output escaping not fully implemented
- Some capability checks missing on AJAX handlers
Checkbox Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Checkbox <= 2.8.10 - Missing Authorization to Unauthenticated Log Clearing
Checkbox Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Checkbox Attack Surface
AJAX Handlers 9
WordPress Hooks 20
Maintenance & Trust
Checkbox Maintenance & Trust
Maintenance Signals
Community Trust
Checkbox Alternatives
Payment gateway – Robokassa for WooCommerce
wc-robokassa
Integration Robokassa in WooCommerce as payment gateway plugin.
MORKVA Vchasno Kasa Integration
mrkv-vchasno-kasa
Плагін інтеграції WooCommerce з Kasa.vchasno.com.ua, сервісом програмної реєстрації розрахункових операцій (пРРО).
Custom Checkbox Ultimate for WooCommerce
custom-checkbox-ultimate-for-woocommerce
Add customizable checkbox options on WooCommerce product pages for additional services and charges.
Datamap Address for Woocommerce
datamap-address-for-woo
Този модул за WooCommerce добавя интелигентна функционалност за автоматично разпознаване и потвърждение на адреси при финализиране на поръчката.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Checkbox Developer Profile
14 plugins · 3K total installs
How We Detect Checkbox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/checkbox/assets/css/checkbox.css/wp-content/plugins/checkbox/assets/js/checkbox.js/wp-content/plugins/checkbox/assets/js/checkbox-admin.js/wp-content/plugins/checkbox/assets/css/checkbox-admin.csscheckbox/style.css?ver=checkbox/script.js?ver=HTML / DOM Fingerprints
mrkv-checkbox-noticecheckbox-settings-pageStop access .php files through URLVersions numberInclude autoloadInclude checkbox api library+20 moredata-toggle="modal"data-target="#add-new-product-modal"mrkv_checkbox_admin_params/wp-json/checkbox/v1/settings/wp-json/checkbox/v1/save-settings