Clicklease Buttons Security & Risk Analysis

wordpress.org/plugins/clicklease-buttons

Increase your sales by adding a "finance with Clicklease button".

10 active installs v2.0.4 PHP 7.4+ WP 5.2+ Updated Jul 4, 2022
clickleasefinanceleasingsaleswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Clicklease Buttons Safe to Use in 2026?

Generally Safe

Score 85/100

Clicklease Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "clicklease-buttons" v2.0.4 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions, exclusively using prepared statements for SQL queries, and achieving a high percentage of properly escaped output. The absence of known CVEs and a clean vulnerability history further contribute to its positive security profile. However, there are significant areas of concern. The plugin lacks any nonce checks or capability checks, which is a major oversight, especially concerning file operations and external HTTP requests. With 88 output operations, even a 90% escape rate leaves a small percentage potentially vulnerable to cross-site scripting (XSS). The presence of file operations and four external HTTP requests without any authentication or authorization checks presents a substantial risk, as these could be exploited by unauthenticated users. The plugin's strength lies in its clean code regarding SQL and its lack of past vulnerabilities, but the absence of fundamental security checks like nonces and capability checks on critical operations is a significant weakness that could lead to serious security incidents.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Potential for unescaped output (10% of 88)
  • File operations without auth checks
  • External HTTP requests without auth checks
Vulnerabilities
None known

Clicklease Buttons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Clicklease Buttons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
79 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
4
Bundled Libraries
0

Output Escaping

90% escaped88 total outputs
Attack Surface

Clicklease Buttons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actionwoocommerce_before_main_contentClickleaseButtons.php:61
actionwoocommerce_before_cart_tableClickleaseButtons.php:67
actionwoocommerce_before_shop_loopClickleaseButtons.php:72
actionwoocommerce_before_checkout_formClickleaseButtons.php:79
actionwoocommerce_checkout_update_order_reviewClickleaseButtons.php:80
actionwp_enqueue_scriptsincludes\CLSWP_BtnsScripts.php:45
actionadmin_enqueue_scriptsincludes\CLSWP_BtnsScripts.php:46
actionadmin_footerincludes\CLSWP_BtnsScripts.php:48
actionadmin_menuincludes\views\admin\CLSWP_MainSettignsPage.php:17
actionadmin_initincludes\views\admin\CLSWP_MainSettignsPage.php:18
actionwoocommerce_after_shop_loop_itemincludes\views\CLSWP_CategoryPage.php:107
actionwoocommerce_after_shop_loopincludes\views\CLSWP_CategoryPage.php:108
actionwp_footerincludes\views\CLSWP_CategoryPage.php:110
actionwoocommerce_review_order_before_submitincludes\views\CLSWP_CheckoutPage.php:28
actionwp_footerincludes\views\CLSWP_CheckoutPage.php:30
actionwoocommerce_single_product_summaryincludes\views\CLSWP_ProductPage.php:34
actionwoocommerce_before_add_to_cart_quantityincludes\views\CLSWP_ProductPage.php:36
actionwoocommerce_after_add_to_cart_buttonincludes\views\CLSWP_ProductPage.php:40
actionwoocommerce_after_single_productincludes\views\CLSWP_ProductPage.php:44
actionwp_footerincludes\views\CLSWP_ProductPage.php:65
actionwoocommerce_after_cartincludes\views\CLSWP_ShoppingCart.php:108
actionwp_footerincludes\views\CLSWP_ShoppingCart.php:129
Maintenance & Trust

Clicklease Buttons Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.0
Last updatedJul 4, 2022
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Clicklease Buttons Developer Profile

Fran Jimenez

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Clicklease Buttons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clicklease-buttons/dist/public.bundle.js/wp-content/plugins/clicklease-buttons/dist/admin.bundle.js
Script Paths
/wp-content/plugins/clicklease-buttons/dist/public.bundle.js/wp-content/plugins/clicklease-buttons/dist/admin.bundle.js

HTML / DOM Fingerprints

JS Globals
CLS_PLUGIN_URLCL_SVGS_URL
FAQ

Frequently Asked Questions about Clicklease Buttons