CoffeeCode – Checkout Stripe Pix for WooCommerce Security & Risk Analysis

wordpress.org/plugins/coffeecode-stripe-pix-for-woocommerce

CoffeeCode - Checkout Stripe Pix for WooCommerce

0 active installs v1.2 PHP 7.4+ WP 6.1+ Updated Nov 17, 2025
checkoutpaymentspixstripewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CoffeeCode – Checkout Stripe Pix for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

CoffeeCode – Checkout Stripe Pix for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of coffeecode-stripe-pix-for-woocommerce v1.2 reveals a generally strong security posture with several good practices in place. The absence of direct SQL injection vulnerabilities due to the use of prepared statements for all queries is a significant positive. The high percentage of properly escaped output also minimizes the risk of cross-site scripting (XSS) vulnerabilities. Furthermore, the lack of known CVEs and a clean vulnerability history suggest a history of secure development or prompt patching of issues.

However, there are notable areas of concern. The complete absence of nonce checks and capability checks across all entry points is a critical oversight. This means that any function that could potentially be triggered externally, even those not immediately apparent as direct entry points in this analysis, could be exploited by an unauthenticated or low-privileged user. The presence of file operations and external HTTP requests without explicit authentication checks could also be a vector for abuse, depending on their implementation. The lack of taint analysis data, while potentially indicating no issues were found, also means that complex, indirect data manipulation vulnerabilities might not have been detected.

In conclusion, while the plugin demonstrates good fundamental security practices in areas like SQL and output handling, the complete lack of nonce and capability checks represents a significant security weakness. This oversight, combined with the potential for misuse of file operations and external requests, warrants careful consideration. The clean vulnerability history is a strength, but it does not negate the immediate risks identified in the static analysis, particularly the absence of crucial authentication checks.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
  • File operations without clear auth checks
  • External HTTP requests without clear auth checks
  • Low percentage of output escaped (1% unescaped)
Vulnerabilities
None known

CoffeeCode – Checkout Stripe Pix for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CoffeeCode – Checkout Stripe Pix for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
30 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

97% escaped31 total outputs
Attack Surface

CoffeeCode – Checkout Stripe Pix for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
filterwoocommerce_checkout_fieldssrc\Services\CheckoutBlocksService.php:27
actionwoocommerce_checkout_update_order_metasrc\Services\CheckoutBlocksService.php:29
actionwoocommerce_store_api_checkout_update_order_from_requestsrc\Services\CheckoutBlocksService.php:31
filterwoocommerce_rest_prepare_shop_ordersrc\Services\CheckoutBlocksService.php:33
actionwoocommerce_store_api_checkout_update_order_from_requestsrc\WooCommerce\GateWays\Pix\PaymentGatewayPixBlocks.php:37
actionwoocommerce_rest_checkout_process_payment_with_contextsrc\WooCommerce\GateWays\Pix\PaymentGatewayPixBlocks.php:38
filterwoocommerce_payment_gatewayssrc\WooCommerce\GateWaysServiceProvider.php:15
actionwoocommerce_blocks_loadedsrc\WooCommerce\GateWaysServiceProvider.php:16
actionbefore_woocommerce_initsrc\WooCommerce\GateWaysServiceProvider.php:17
actionwoocommerce_blocks_payment_method_type_registrationsrc\WooCommerce\GateWaysServiceProvider.php:52
actionwp_enqueue_scriptssrc\WordPress\AssetsProvider.php:13
actionadmin_enqueue_scriptssrc\WordPress\AssetsProvider.php:14
actionadmin_noticessrc\WordPress\PluginProvider.php:45
Maintenance & Trust

CoffeeCode – Checkout Stripe Pix for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 17, 2025
PHP min version7.4
Downloads207

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CoffeeCode – Checkout Stripe Pix for WooCommerce Developer Profile

Coffee Code Tech

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CoffeeCode – Checkout Stripe Pix for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coffeecode-stripe-pix-for-woocommerce/dist/front-style.css/wp-content/plugins/coffeecode-stripe-pix-for-woocommerce/dist/front.js/wp-content/plugins/coffeecode-stripe-pix-for-woocommerce/dist/admin-style.css/wp-content/plugins/coffeecode-stripe-pix-for-woocommerce/dist/admin.js/wp-content/plugins/coffeecode-stripe-pix-for-woocommerce/dist/login-style.css/wp-content/plugins/coffeecode-stripe-pix-for-woocommerce/dist/login.js
Script Paths
/wp-content/plugins/coffeecode-stripe-pix-for-woocommerce/dist/front.js/wp-content/plugins/coffeecode-stripe-pix-for-woocommerce/dist/admin.js/wp-content/plugins/coffeecode-stripe-pix-for-woocommerce/dist/login.js
Version Parameters
coffeecode-stripe-pix-for-woocommerce/dist/front-style.css?ver=coffeecode-stripe-pix-for-woocommerce/dist/front.js?ver=coffeecode-stripe-pix-for-woocommerce/dist/admin-style.css?ver=coffeecode-stripe-pix-for-woocommerce/dist/admin.js?ver=coffeecode-stripe-pix-for-woocommerce/dist/login-style.css?ver=coffeecode-stripe-pix-for-woocommerce/dist/login.js?ver=

HTML / DOM Fingerprints

CSS Classes
coffeecode-stripe-pix-for-woocommerce
JS Globals
coffeePixParamswooStripePixAdminParams
FAQ

Frequently Asked Questions about CoffeeCode – Checkout Stripe Pix for WooCommerce