Gift Wrapping for WooCommerce Security & Risk Analysis

wordpress.org/plugins/gift-wrapping-for-woocommerce

Allow customers to select a gift wrapper for their orders.

1K active installs v1.2.4 PHP 5.6+ WP 5.3+ Updated Mar 1, 2025
gift-boxgift-wrappergift-wrappingwoocommercewrapping
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Gift Wrapping for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Gift Wrapping for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "gift-wrapping-for-woocommerce" plugin v1.2.4 exhibits a strong security posture based on the provided static analysis. There are no identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) that are directly exposed to attack, and critically, none of these potential entry points lack authentication or permission checks if they were to exist. The code also avoids dangerous functions, performs SQL queries exclusively with prepared statements, and does not engage in file operations or external HTTP requests. While the output escaping is not perfect (80% properly escaped), this is a relatively minor concern given the lack of other critical vulnerabilities.

The vulnerability history is completely clean, with no recorded CVEs of any severity. This suggests a history of diligent security practices or a lack of historical targeting, either of which is a positive indicator. The taint analysis also yielded no critical or high severity flows, further reinforcing the impression of a secure codebase. The plugin's strengths lie in its avoidance of common attack vectors and its robust SQL handling. The only minor area for improvement is the slight gap in output escaping, but overall, this plugin appears to be well-secured.

Key Concerns

  • Output escaping not fully implemented
Vulnerabilities
None known

Gift Wrapping for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gift Wrapping for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped5 total outputs
Attack Surface

Gift Wrapping for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedincludes\class-gift-wrapping-for-woocommerce.php:124
filterwoocommerce_get_settings_pagesincludes\class-gift-wrapping-for-woocommerce.php:143
actionmanage_shop_order_posts_custom_columnincludes\class-gift-wrapping-for-woocommerce.php:148
actionmanage_woocommerce_page_wc-orders_custom_columnincludes\class-gift-wrapping-for-woocommerce.php:150
filterplugin_action_linksincludes\class-gift-wrapping-for-woocommerce.php:153
actionbefore_woocommerce_initincludes\class-gift-wrapping-for-woocommerce.php:161
actionwoocommerce_cart_calculate_feesincludes\class-gift-wrapping-for-woocommerce.php:203
actionwoocommerce_checkout_create_orderincludes\class-gift-wrapping-for-woocommerce.php:204
actionwoocommerce_order_get_itemsincludes\class-gift-wrapping-for-woocommerce.php:210
filterwp_kses_allowed_htmlpublic\class-gift-wrapping-for-woocommerce-public.php:131
filterwoocommerce_get_order_item_totals_excl_free_feespublic\class-gift-wrapping-for-woocommerce-public.php:223
Maintenance & Trust

Gift Wrapping for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 1, 2025
PHP min version5.6
Downloads12K

Community Trust

Rating100/100
Number of ratings7
Active installs1K
Developer Profile

Gift Wrapping for WooCommerce Developer Profile

Gift Wrapping for WooCommerce

1 plugin · 1K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gift Wrapping for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gift-wrapping-for-woocommerce/admin/css/gift-wrapping-for-woocommerce-admin.css/wp-content/plugins/gift-wrapping-for-woocommerce/admin/js/gift-wrapping-for-woocommerce-admin.js/wp-content/plugins/gift-wrapping-for-woocommerce/public/css/gift-wrapping-for-woocommerce-public.css/wp-content/plugins/gift-wrapping-for-woocommerce/public/js/gift-wrapping-for-woocommerce-public.js
Version Parameters
gift-wrapping-for-woocommerce/admin/css/gift-wrapping-for-woocommerce-admin.css?ver=gift-wrapping-for-woocommerce/admin/js/gift-wrapping-for-woocommerce-admin.js?ver=gift-wrapping-for-woocommerce/public/css/gift-wrapping-for-woocommerce-public.css?ver=gift-wrapping-for-woocommerce/public/js/gift-wrapping-for-woocommerce-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
tgpc-order-list-gift-wrapper--label_icon
Data Attributes
data-tgpc_gift_wrapper_value
JS Globals
tgpc_wc_gift_wrap_admin
FAQ

Frequently Asked Questions about Gift Wrapping for WooCommerce