
COD Order Confirmation for India Security & Risk Analysis
wordpress.org/plugins/cod-confirmation-for-indiaUsing this plugin you can ensure that your COD orders are legitimate before you ship them out. This plugin will confirm your COD orders on call or SMS …
Is COD Order Confirmation for India Safe to Use in 2026?
Generally Safe
Score 100/100COD Order Confirmation for India has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cod-confirmation-for-india" plugin v1.2.0 exhibits a mixed security posture. On the positive side, it has no recorded vulnerability history, including CVEs, and the taint analysis found no critical or high severity issues with unsanitized paths. The majority of its SQL queries utilize prepared statements, indicating good practice in database interaction. However, significant concerns arise from its attack surface. With a total of 4 AJAX handlers, 2 of them lack authentication checks, presenting a direct entry point for potential abuse.
Furthermore, the plugin demonstrates poor output escaping practices, with only 12% of outputs being properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected into the page without proper sanitization. While there are no directly identified critical code signals like dangerous functions or raw SQL queries, the combination of unprotected AJAX endpoints and widespread unescaped output creates substantial weaknesses.
The absence of any recorded vulnerabilities in its history is a positive indicator, but it doesn't negate the inherent risks identified in the static analysis. The plugin seems to lack robust capability checks, relying instead on nonce checks for some AJAX handlers. The overall conclusion is that while the plugin avoids known external vulnerabilities, its internal code quality, particularly regarding authentication on AJAX endpoints and output sanitization, introduces significant exploitable weaknesses that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- No capability checks
COD Order Confirmation for India Security Vulnerabilities
COD Order Confirmation for India Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
COD Order Confirmation for India Attack Surface
AJAX Handlers 4
WordPress Hooks 8
Maintenance & Trust
COD Order Confirmation for India Maintenance & Trust
Maintenance Signals
Community Trust
COD Order Confirmation for India Alternatives
Custom Thank You Page for WooCommerce
wc-custom-thank-you
Replace the default WooCommerce Thank You page (order received page) with a custom Thank You page.
Custom Thank You for WooCommerce
custom-thank-you-for-woocommerce
A popular WooCommerce extension that redirects a buyer to a custom WordPress thank you page that includes social share features.
WaMate Confirm – Order Confirmation
wamate-confirm
WaMate Confirm is a powerful plugin designed to streamline your order confirmation process
Custom Thank you for Woo
custom-thank-you-for-woo
The Custom Thank you and order confirmation page plugin display to customers details after order completing with information.
HyperSell – COD Order Form for WooCommerce
hypersell-cod-order-form
If your business is based on Cash On Delivery, you need HyperSell in your store, it will help you increase your conversion by changing the normal WooC …
COD Order Confirmation for India Developer Profile
3 plugins · 230 total installs
How We Detect COD Order Confirmation for India
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cod-confirmation-for-india/css/demo_table.css/wp-content/plugins/cod-confirmation-for-india/css/common.css/wp-content/plugins/cod-confirmation-for-india/js/jquery.dataTables.js/wp-content/plugins/cod-confirmation-for-india/css/jquery-ui.css/wp-content/plugins/cod-confirmation-for-india/js/jquery.dataTables.jscod-confirmation-for-india/css/demo_table.css?ver=cod-confirmation-for-india/css/common.css?ver=cod-confirmation-for-india/js/jquery.dataTables.js?ver=cod-confirmation-for-india/css/jquery-ui.css?ver=HTML / DOM Fingerprints
COD_plugin_object