Custom Thank You Woo Security & Risk Analysis

wordpress.org/plugins/custom-thank-you-woo

This free Woocommerce extension allows you to define a specific and custom Thank You page for your customers.

0 active installs v1.1 PHP + WP 6.5+ Updated Apr 23, 2025
custom-thank-you-page-redirectthank-you-pagewoocommercewoocommerce-thank-you
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Thank You Woo Safe to Use in 2026?

Generally Safe

Score 100/100

Custom Thank You Woo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "custom-thank-you-woo" plugin version 1.1 presents a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the consistent use of prepared statements for SQL queries, and the proper escaping of all output are significant strengths. Furthermore, the plugin has no recorded vulnerabilities, including critical or high severity ones, and no history of unpatched CVEs, suggesting a history of responsible development and maintenance.

However, the analysis does reveal some areas for concern. The complete lack of nonce checks and capability checks across all entry points is a notable weakness. While the static analysis indicates a zero attack surface in terms of AJAX, REST API, shortcodes, and cron events, this could be misleading if the plugin relies on external mechanisms or if these entry points are implicitly created elsewhere. The absence of these essential security mechanisms leaves the plugin vulnerable to potential attacks if any of its functionalities were ever to be exposed or if an attack vector is discovered that bypasses the static analysis.

In conclusion, "custom-thank-you-woo" v1.1 demonstrates good practices in data handling and output sanitization. The lack of known vulnerabilities is a positive indicator. Nevertheless, the critical oversight in implementing nonce and capability checks across its codebase represents a significant, albeit currently theoretical, risk. Future development should prioritize addressing these checks to solidify its security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Custom Thank You Woo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Custom Thank You Woo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

Custom Thank You Woo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actiontemplate_redirectcustom-thank-you-woo.php:33
filterthe_contentcustom-thank-you-woo.php:41
filterwoocommerce_is_order_received_pagecustom-thank-you-woo.php:49
filterwoocommerce_settings_pagescustom-thank-you-woo.php:57
actionwoocommerce_initcustom-thank-you-woo.php:60
actionbefore_woocommerce_initcustom-thank-you-woo.php:63
Maintenance & Trust

Custom Thank You Woo Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 23, 2025
PHP min version
Downloads428

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Custom Thank You Woo Developer Profile

Galaxy Weblinks

40 plugins · 25K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
310 days
View full developer profile
Detection Fingerprints

How We Detect Custom Thank You Woo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
woocommerce-notice--successwoocommerce-thankyou-order-received
Data Attributes
id="custom_thankyou_options"id="custom_thank_you_woo_page_id"
FAQ

Frequently Asked Questions about Custom Thank You Woo