Gift Pack for Woocommerce Security & Risk Analysis

wordpress.org/plugins/gift-pack-for-woocommerce

Let customers add gift packing/wrapping to individual products from product pages. choose your own Gift Pack design directly from the product page wit …

300 active installs v2.1.1 PHP 7.4+ WP 6.0+ Updated Dec 10, 2025
gift-packgift-wrapgift-wrapperwoocommmercewordpress-gift-pack
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gift Pack for Woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Gift Pack for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "gift-pack-for-woocommerce" v2.1.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries, utilizing prepared statements exclusively, and has a very high rate of properly escaped outputs. The absence of file operations, external HTTP requests, and known vulnerabilities in its history are also strong indicators of a secure development approach. However, significant concerns arise from the attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a direct entry point for unauthenticated attackers to interact with potentially sensitive functionality. Furthermore, the taint analysis revealed one flow with an unsanitized path, which, while not categorized as critical or high severity in the provided data, still represents a potential risk that needs careful review. The lack of nonce checks on these unprotected AJAX endpoints further exacerbates the risk, making it easier for attackers to forge requests.

Key Concerns

  • AJAX handlers without authentication
  • Taint flow with unsanitized path
  • AJAX handlers without nonce checks
Vulnerabilities
None known

Gift Pack for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gift Pack for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
262 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped265 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
gpfw_update_settings (admin\class-gift-pack-for-woocommerce-admin.php:209)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Gift Pack for Woocommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_gpfw_check_gift_wrapincludes\class-gift-pack-for-woocommerce.php:178
authwp_ajax_gpfw_check_gift_wrapincludes\class-gift-pack-for-woocommerce.php:179
WordPress Hooks 19
actionplugins_loadedincludes\class-gift-pack-for-woocommerce.php:136
actionadmin_noticesincludes\class-gift-pack-for-woocommerce.php:148
actionadmin_enqueue_scriptsincludes\class-gift-pack-for-woocommerce.php:149
actionadmin_enqueue_scriptsincludes\class-gift-pack-for-woocommerce.php:150
actionadmin_menuincludes\class-gift-pack-for-woocommerce.php:151
actionadd_meta_boxesincludes\class-gift-pack-for-woocommerce.php:152
actionadmin_post_save_gpfw_update_settingsincludes\class-gift-pack-for-woocommerce.php:153
actionwoocommerce_product_options_general_product_dataincludes\class-gift-pack-for-woocommerce.php:155
actionwoocommerce_admin_process_product_objectincludes\class-gift-pack-for-woocommerce.php:156
actionwp_enqueue_scriptsincludes\class-gift-pack-for-woocommerce.php:168
actionwp_enqueue_scriptsincludes\class-gift-pack-for-woocommerce.php:169
actionwp_headincludes\class-gift-pack-for-woocommerce.php:171
actionwoocommerce_single_product_summaryincludes\class-gift-pack-for-woocommerce.php:172
actionwoocommerce_before_add_to_cart_buttonincludes\class-gift-pack-for-woocommerce.php:173
filterwoocommerce_add_cart_item_dataincludes\class-gift-pack-for-woocommerce.php:174
actionwoocommerce_before_calculate_totalsincludes\class-gift-pack-for-woocommerce.php:175
filterwoocommerce_get_item_dataincludes\class-gift-pack-for-woocommerce.php:176
actionwoocommerce_checkout_create_order_line_itemincludes\class-gift-pack-for-woocommerce.php:177
filterwoocommerce_post_classincludes\class-gift-pack-for-woocommerce.php:180
Maintenance & Trust

Gift Pack for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version7.4
Downloads13K

Community Trust

Rating92/100
Number of ratings5
Active installs300
Developer Profile

Gift Pack for Woocommerce Developer Profile

IT Path Solutions

10 plugins · 11K total installs

84
trust score
Avg Security Score
94/100
Avg Patch Time
77 days
View full developer profile
Detection Fingerprints

How We Detect Gift Pack for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gift-pack-for-woocommerce/admin/css/gift-pack-for-woocommerce-admin.css/wp-content/plugins/gift-pack-for-woocommerce/admin/js/gift-pack-for-woocommerce-admin.js/wp-content/plugins/gift-pack-for-woocommerce/admin/js/admin.js
Script Paths
/wp-content/plugins/gift-pack-for-woocommerce/admin/js/gift-pack-for-woocommerce-admin.js/wp-content/plugins/gift-pack-for-woocommerce/admin/js/admin.js
Version Parameters
gift-pack-for-woocommerce/admin/css/gift-pack-for-woocommerce-admin.css?ver=gift-pack-for-woocommerce/admin/js/gift-pack-for-woocommerce-admin.js?ver=gift-pack-for-woocommerce/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
gpfw_checkbox_price
Data Attributes
gift_pack_wrapper_price
JS Globals
gift_pack_for_woocommerce
FAQ

Frequently Asked Questions about Gift Pack for Woocommerce