
ClimateClick: Climate Action for all Security & Risk Analysis
wordpress.org/plugins/co2ok-for-woocommerceEmpower your customers to make their order climate neutral
Is ClimateClick: Climate Action for all Safe to Use in 2026?
Mostly Safe
Score 84/100ClimateClick: Climate Action for all is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The "co2ok-for-woocommerce" plugin v2.0.9 exhibits a mixed security posture, with some positive indicators but significant concerns arising from its attack surface and output handling. While the plugin demonstrates good practices by using prepared statements for all SQL queries and making no direct file operations, the absence of nonces and capability checks on its two AJAX entry points presents a clear risk. Furthermore, a concerning 100% of its output is not properly escaped, suggesting a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, which aligns with its historical vulnerability types.
The plugin's vulnerability history, with two known CVEs including a high and a medium severity vulnerability related to XSS and missing authorization, further exacerbates these concerns. The fact that a vulnerability was last identified in May 2022 and there are currently no unpatched vulnerabilities is a positive sign regarding maintenance, but the nature of past vulnerabilities points to recurring issues in handling user input and authorization.
In conclusion, while the use of prepared statements is commendable, the plugin's significant attack surface with unprotected AJAX endpoints and widespread unescaped output, coupled with a history of XSS and authorization flaws, indicates a moderate to high-risk profile. Remediation efforts should prioritize securing AJAX handlers and implementing proper output escaping.
Key Concerns
- AJAX handlers without auth checks
- Unescaped output
- Missing nonce checks
- High severity vulnerability history
- Medium severity vulnerability history
- Vulnerability history includes XSS
- Vulnerability history includes missing authorization
ClimateClick: Climate Action for all Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
CO2ok: carbon offsetting for e-commerce <= 1.0.9.21 - Cross-Site Scripting
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
ClimateClick: Climate Action for all Code Analysis
Output Escaping
ClimateClick: Climate Action for all Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
ClimateClick: Climate Action for all Maintenance & Trust
Maintenance Signals
Community Trust
ClimateClick: Climate Action for all Alternatives
Carbon Balance: Carbon calculation and offsetting for WooCommerce
carbonbalance-for-woocommerce
Empower your customers to make their order more climate Friendly
HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce
hurrytimer
Create unlimited urgency and scarcity countdown timers for WordPress and WooCommerce to boost conversions and sales instantly.
Evergreen Countdown Timer
intelly-countdown
Evergreen Countdown is a plugin built for marketers that need a reliable solution to use scarcity on their websites and landing pages.
WP Old Post Date Remover
wp-old-post-date-remover
Removes the date stamp from older posts (you choose how old), while leaving the date stamp on newer posts. Ideal for blogs with evergreen content.
Morning for WooCommerce
wc-gateway-greeninvoice
Morning (Green Invoice) add-on for WooCommerce enables an easy and convenient connection between your morning account to your online store.
ClimateClick: Climate Action for all Developer Profile
1 plugin · 10 total installs
How We Detect ClimateClick: Climate Action for all
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/co2ok-for-woocommerce/admin/css/south-pole-climate-click-admin.csssouth-pole-climate-click-admin.css?ver=HTML / DOM Fingerprints
id="wc_climate_click_settings_tabs_api"id="wc_climate_click_settings_tabs_checkbox"id="wc_climate_click_settings_tabs_page_selection"id="wc_climate_click_settings_tabs_section_end"id="wc_climate_click_settings_tabs_section_title"