
Checkout Add-on for Woo OnePage – Lite Security & Risk Analysis
wordpress.org/plugins/checkout-add-on-woo-onepageCheckout Add-on for Woo OnePage - Lite is a Instant/Quick/OnPage/Floating Checkout Add-on for Woo OnePage Checkout Shop.
Is Checkout Add-on for Woo OnePage – Lite Safe to Use in 2026?
Generally Safe
Score 85/100Checkout Add-on for Woo OnePage – Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "checkout-add-on-woo-onepage" plugin v0.9 exhibits a concerning security posture, primarily due to its unprotected entry points. While the plugin demonstrates good practices like using prepared statements for all SQL queries and a high percentage of properly escaped outputs, the presence of four AJAX handlers without any authentication or capability checks creates a significant attack surface. This means any user, including unauthenticated ones, could potentially interact with these AJAX endpoints and trigger unintended actions or reveal sensitive information. The absence of nonce checks on these AJAX handlers further exacerbates this risk, as it opens the door to Cross-Site Request Forgery (CSRF) attacks. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign. However, the current static analysis findings strongly suggest that the lack of security controls on its entry points is a major oversight that needs immediate attention to mitigate potential exploitation. The plugin's strengths lie in its careful handling of database queries and output, but these are overshadowed by the critical flaw of unprotected AJAX endpoints.
Key Concerns
- AJAX handlers without auth checks
- Missing nonce checks on AJAX
- High percentage of unprotected entry points
Checkout Add-on for Woo OnePage – Lite Security Vulnerabilities
Checkout Add-on for Woo OnePage – Lite Code Analysis
Output Escaping
Checkout Add-on for Woo OnePage – Lite Attack Surface
AJAX Handlers 4
WordPress Hooks 8
Maintenance & Trust
Checkout Add-on for Woo OnePage – Lite Maintenance & Trust
Maintenance Signals
Community Trust
Checkout Add-on for Woo OnePage – Lite Alternatives
Add to Cart Redirect for WooCommerce
add-to-cart-direct-checkout-for-woocommerce
Features offered: Add to cart redirect, Quick purchase button, Buy now button, Quick View product, option to change quantity on checkout page.
Popup For WooCommerce Checkout (FREE)
woo-checkout-on-popup-free
This plugin enables instant woocommerce checkout through popup. Seamlessly integrate into product details page with full admin control settings.
Checkout Add-on for Woo OnePage – Lite Developer Profile
3 plugins · 30 total installs
How We Detect Checkout Add-on for Woo OnePage – Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/checkout-add-on-woo-onepage/assets/css/frontend.css/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/country-select-min.js/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/front-checkout-min.js/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/frontend.js/wp-content/plugins/checkout-add-on-woo-onepage/assets/css/admin.css/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/admin.js/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/country-select-min.js/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/front-checkout-min.js/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/frontend.js/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/admin.js/wp-content/plugins/checkout-add-on-woo-onepage/assets/css/frontend.css?ver=1.0.0/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/country-select-min.js?ver=1.0.0/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/front-checkout-min.js?ver=1.0.0/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/frontend.js?ver=1.0.0/wp-content/plugins/checkout-add-on-woo-onepage/assets/css/admin.css?ver=1.0.0/wp-content/plugins/checkout-add-on-woo-onepage/assets/js/admin.js?ver=1.0.0HTML / DOM Fingerprints
acl-wooc-frontenddata-acl-wooc-pluginops_country_select_paramswoosc_checkout_datawooc_ajax_objectwooc_admin_object