
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Security & Risk Analysis
wordpress.org/plugins/gift-voucherLet your customers buy gift cards/certificates for your services & products directly on your website.
Is Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Safe to Use in 2026?
Generally Safe
Score 91/100Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) has a strong security track record. Known vulnerabilities have been patched promptly.
The "gift-voucher" plugin v4.6.4 exhibits a mixed security posture. While it demonstrates some good practices, such as a high percentage of prepared statements for SQL queries and proper output escaping, significant concerns remain. The presence of 15 unprotected AJAX handlers out of a total of 29 entry points is a major red flag, indicating a large attack surface that could be exploited without proper authorization. Furthermore, the taint analysis revealed 6 high-severity flows with unsanitized paths, suggesting potential vulnerabilities that could be triggered by malicious input.
The plugin's vulnerability history is particularly troubling, with 6 known CVEs, including 2 critical ones. The common vulnerability types like Missing Authorization, Cross-site Scripting (XSS), CSRF, and SQL Injection, coupled with the recent critical vulnerabilities, point to a pattern of insecure coding practices. Although there are currently no unpatched CVEs, the historical prevalence of critical and medium vulnerabilities suggests that the plugin may have underlying architectural weaknesses or that its development team struggles with consistently implementing secure coding standards.
In conclusion, while the plugin shows some strengths in areas like SQL preparedness and output escaping, the high number of unprotected entry points, critical taint flows, and a history of significant vulnerabilities necessitate a cautious approach. The potential for authorization bypasses, XSS, CSRF, and SQL injection, especially through the unprotected AJAX handlers and unsanitized taint flows, presents a substantial risk. Users should be aware of these risks and consider alternatives or ensure robust security measures are in place.
Key Concerns
- 15 unprotected AJAX handlers
- 6 high severity taint flows
- 2 critical known CVEs
- 4 medium known CVEs
- History of SQL Injection
- History of XSS
- History of Missing Authorization
- History of CSRF
- Bundled Stripe PHP library
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.9 - Missing Authorization to Unauthenticated Price, Date, and Note Updates
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Gift Vouchers <= 4.4.0 - Cross-Site Request Forgery
Gift Cards (Gift Vouchers and Packages) <= 4.3.5 - Cross-Site Request Forgery in new_voucher_template.php
Gift Cards (Gift Vouchers and Packages) <= 4.3.2 - Unauthenticated SQL Injection
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) < 4.1.8 - SQL Injection
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Attack Surface
AJAX Handlers 29
Shortcodes 7
WordPress Hooks 110
Scheduled Events 3
Maintenance & Trust
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Maintenance & Trust
Maintenance Signals
Community Trust
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Alternatives
Ultimate Gift Cards for WooCommerce
woo-gift-cards-lite
Create, sell and manage WooCommerce gift cards to attract more sales and multiply your revenue at your online store.
Gift Up Gift Cards for WordPress and WooCommerce
gift-up
The simplest way to sell gift cards online. Sell your own gift cards, gift certificates and gift vouchers from inside your WordPress website easily wi …
WebToffee Gift Cards for WooCommerce
wt-gift-cards-woocommerce
Create and sell WooCommerce gift cards in your store. Allow your customers to buy, redeem, and share gift vouchers easily.
Store credit / Gift cards for woocommerce
store-credit-for-woocommerce
Offer store credit or gift cards to customers that they can use until their credit is finished
VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce
vaocher-app
Sell your own gift cards, gift vouchers and gift certificates from your WordPress website (WooCommerce compatible) easily in just a few minutes
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Developer Profile
3 plugins · 1K total installs
How We Detect Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gift-voucher/css/wpgv-frontend.css/wp-content/plugins/gift-voucher/css/wpgv-frontend-gift-form.css/wp-content/plugins/gift-voucher/css/wpgv-frontend-voucher-style.css/wp-content/plugins/gift-voucher/js/wpgv-frontend.js/wp-content/plugins/gift-voucher/js/wpgv-frontend-gift-form.js/wp-content/plugins/gift-voucher/js/wpgv-frontend-voucher-style.js/wp-content/plugins/gift-voucher/js/wpgv-frontend.js/wp-content/plugins/gift-voucher/js/wpgv-frontend-gift-form.js/wp-content/plugins/gift-voucher/js/wpgv-frontend-voucher-style.jsgift-voucher/css/wpgv-frontend.css?ver=gift-voucher/css/wpgv-frontend-gift-form.css?ver=gift-voucher/css/wpgv-frontend-voucher-style.css?ver=gift-voucher/js/wpgv-frontend.js?ver=gift-voucher/js/wpgv-frontend-gift-form.js?ver=gift-voucher/js/wpgv-frontend-voucher-style.js?ver=HTML / DOM Fingerprints
wpgv-voucher-formwpgv-voucher-itemwpgv-gift-voucher-sectionwpgv-gift-voucher-wrapperwpgv-voucher-input-groupwpgv-voucher-buttonwpgv-voucher-codewpgv-voucher-amount+6 more<!-- Frontend Voucher Form --><!-- Gift Voucher Style Section -->data-wpgv-amountdata-wpgv-codedata-wpgv-currency-symbolWPGVFrontendwpgv_frontend_params/wp-json/gift-voucher/v1/save-voucher-data/wp-json/gift-voucher/v1/get-voucher-data[gift-voucher-form][gift-voucher-display]