
Contribuinte Checkout Security & Risk Analysis
wordpress.org/plugins/contribuinte-checkoutWith this plugin you can add VAT and VIES support to your WooCommerce store. The VAT field will be saved as '_billing_vat'.
Is Contribuinte Checkout Safe to Use in 2026?
Generally Safe
Score 99/100Contribuinte Checkout has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "contribuinte-checkout" v2.0.04 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no raw SQL queries, and no file operations, indicating good practices in these areas. The presence of nonce and capability checks is also a positive sign. However, the taint analysis flags one flow with unsanitized paths, which, although not classified as critical or high, represents a potential risk that could be exploited if an attacker can control the input leading to this path.
The vulnerability history shows a single known CVE, which is thankfully patched. The common vulnerability type being CSRF suggests that in the past, the plugin may have had issues with securing actions against unauthorized requests. While there are no currently unpatched vulnerabilities, this history warrants continued vigilance and regular updates.
Overall, the plugin has some strong security foundations, particularly in its database and file handling. The primary concerns stem from the identified unsanitized path in the taint analysis and the historical pattern of CSRF vulnerabilities, even though currently patched. While the attack surface is reported as zero, which is excellent, the latent risk from the unsanitized path should not be overlooked.
Key Concerns
- Flow with unsanitized path identified in taint analysis
- Historically vulnerable to CSRF (though patched)
- Only 68% of output properly escaped
Contribuinte Checkout Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Contribuinte Checkout <= 2.0.03 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Contribuinte Checkout Code Analysis
Output Escaping
Data Flow Analysis
Contribuinte Checkout Attack Surface
WordPress Hooks 20
Maintenance & Trust
Contribuinte Checkout Maintenance & Trust
Maintenance Signals
Community Trust
Contribuinte Checkout Alternatives
Fraud Prevention For WooCommerce and EDD
woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers
It will Prevent fake orders and Blacklist fraud customers of your store.
Blacklist Manager – WooCommerce Anti-Fraud & Checkout Verification & Spam Prevention
wc-blacklist-manager
Anti-fraud, checkout verification and spam prevention plugin for WooCommerce and WordPress forms.
Export WooCommerce Orders, Products, Customers & Coupons to Google Sheets
wpsyncsheets-woocommerce
Export WooCommerce orders, products, customers, and coupons to Google Sheets automatically in real-time.
RD Order Modifier for WooCommerce
rd-wc-order-modifier
Allows editing order items pricing inclusive of tax or VAT and using unit cost instead of items totals.
All Woocommerce Export
all-woocommerce-export
Export WooCommerce Orders, products and Customers into Excel. Supports all Excel format XLS, XLSX & Mac)
Contribuinte Checkout Developer Profile
2 plugins · 3K total installs
How We Detect Contribuinte Checkout
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contribuinte-checkout/build/index.css/wp-content/plugins/contribuinte-checkout/build/index.js/wp-content/plugins/contribuinte-checkout/build/index.jscontribuinte-checkout/build/index.css?ver=contribuinte-checkout/build/index.js?ver=HTML / DOM Fingerprints
contribuinte-checkout-billing-vatcontribuinte-checkout-shipping-vatbilling_vatshipping_vat<!-- Contribuinte Checkout Settings -->data-vat-field-labelwindow.contribuinteCheckout