
Custom Thank You for WooCommerce Security & Risk Analysis
wordpress.org/plugins/custom-thank-you-for-woocommerceA popular WooCommerce extension that redirects a buyer to a custom WordPress thank you page that includes social share features.
Is Custom Thank You for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Custom Thank You for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-thank-you-for-woocommerce" plugin v1.1.6 exhibits a generally positive security posture, adhering to several best practices. The absence of known CVEs and any recorded critical or high severity vulnerabilities in its history is a significant strength. Furthermore, the plugin demonstrates good security by implementing nonce and capability checks on its entry points, and the static analysis indicates that all AJAX handlers and REST API routes (if any existed) are protected. The lack of file operations and external HTTP requests also reduces the potential attack surface.
However, there are areas for improvement that introduce potential risks. The most notable concern is the complete lack of prepared statements for its SQL queries, with 100% of queries being potentially vulnerable to SQL injection. Additionally, the output escaping is also a concern, with only 27% of outputs being properly escaped, leaving 73% of them vulnerable to cross-site scripting (XSS) attacks. While taint analysis showed no flows, this is likely due to the limited scope of the analysis or the absence of complex data manipulation that would trigger taint detection. The limited attack surface is a positive, but the unprotected nature of the identified SQL queries and outputs represent significant weaknesses.
In conclusion, while the plugin benefits from a clean vulnerability history and proper authentication on entry points, the unescaped outputs and raw SQL queries represent clear and present dangers. These issues, if exploited, could lead to serious security breaches. Addressing these specific code-level concerns should be a priority to bolster the plugin's overall security.
Key Concerns
- SQL queries without prepared statements
- Low percentage of properly escaped output
Custom Thank You for WooCommerce Security Vulnerabilities
Custom Thank You for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Custom Thank You for WooCommerce Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 16
Maintenance & Trust
Custom Thank You for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Custom Thank You for WooCommerce Alternatives
Custom Thank You Page for WooCommerce
wc-custom-thank-you
Replace the default WooCommerce Thank You page (order received page) with a custom Thank You page.
Custom Thank You Page for WooCommerce
custom-thank-you-page
Custom Thank You Page for WooCommerce plugin allows you to customize the final thank you page of a WooCommerce order.
Custom Thank You Message for WooCommerce
custom-thank-you-message-for-woocommerce
Add a custom thank-you message to WooCommerce order pages with dynamic placeholders like [customer_name] and [order_id].
RedFox Thank You Page for WooCommerce
redfox-thank-you
Create beautiful, customizable WooCommerce thank you pages with powerful Gutenberg blocks and responsive controls.
Successful Redirection for Contact Form
cf7-redirection
A simple add-on for Forms that adds a redirect option after form sent successfully.
Custom Thank You for WooCommerce Developer Profile
8 plugins · 5K total installs
How We Detect Custom Thank You for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-thank-you-for-woocommerce/assets/js/ctyw_admin.js/wp-content/plugins/custom-thank-you-for-woocommerce/assets/css/ctyw_admin.csswp-content/plugins/custom-thank-you-for-woocommerce/assets/js/ctyw_admin.jswp-content/plugins/custom-thank-you-for-woocommerce/assets/css/ctyw_admin.csscustom-thank-you-for-woocommerce/assets/js/ctyw_admin.js?ver=custom-thank-you-for-woocommerce/assets/css/ctyw_admin.css?ver=HTML / DOM Fingerprints
ctyw-settings-wrapctyw-section-headingctyw-admin-form-wrapctyw-settings-groupctyw-form-field-wrapper<!-- Main WC custom free init class --><!-- Set things up. --><!-- Add plugin description link --><!-- Add custom link for the plugin beside activate/deactivate links -->+7 moredata-ctyw-settings-toggledata-ctyw-field-idCTYW_AJAX_URLctyw_admin_object