
Kiswa COD Fee for WooCommerce Security & Risk Analysis
wordpress.org/plugins/kiswa-cod-fee-for-woocommerceAdd a simple extra fee when customers choose Cash on Delivery (COD) in WooCommerce.
Is Kiswa COD Fee for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Kiswa COD Fee for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "kiswa-cod-fee-for-woocommerce" plugin v1.0.0 reveals a generally strong security posture. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. The code also demonstrates good practices in handling SQL queries, with 100% utilizing prepared statements, and a low number of file operations and external HTTP requests. The presence of one capability check is also a positive sign.
However, a few areas warrant attention. While the overall output escaping is good at 80%, the remaining 20% of unescaped outputs could potentially lead to cross-site scripting (XSS) vulnerabilities if malicious data is introduced through other means. The absence of nonce checks, although not directly tied to any identified entry points in this analysis, is a common security control that is missing and could be a concern if new entry points are introduced in future versions without proper authentication checks. The vulnerability history is clean, with no known CVEs, which is a significant strength and suggests the developers have a good track record.
In conclusion, the plugin appears to be developed with security in mind, especially given its limited attack surface and secure SQL handling. The main weaknesses lie in the unescaped outputs and the missing nonce checks, which, while not exploited in the current analysis, represent potential vulnerabilities. The lack of historical vulnerabilities is a strong positive indicator.
Key Concerns
- Unescaped output detected
- Missing nonce checks
Kiswa COD Fee for WooCommerce Security Vulnerabilities
Kiswa COD Fee for WooCommerce Code Analysis
Output Escaping
Kiswa COD Fee for WooCommerce Attack Surface
WordPress Hooks 9
Maintenance & Trust
Kiswa COD Fee for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Kiswa COD Fee for WooCommerce Alternatives
Smart COD for WooCommerce
wc-smart-cod
All the COD restrictions and extra fees you'll ever need, in a single plugin.
Risk Free Cash On Delivery (COD) – WooCommerce
risk-free-cash-on-delivery-cod-woocommerce
This plugin secures your Cash on delivery orders with an advance Payment option, with an additional feature of Extra fees and Restrictions.
PCOD – Partial COD, Payment Gateway Restrictions & Fees | for WooCommerce
partial-cod-payment-gateway-restrictions-fees
Advanced Partial COD, Payment Method Restrictions, Cart Fees & Cart Discounts for WooCommerce
COD Express Checkout
cod-express-checkout
Add a customizable one-click COD checkout form to product pages. Skip cart, skip checkout, more sales.
PiWeb Disable payment method / Partial payment for WooCommerce
disable-payment-method-for-woocommerce
Disable payment method for WooCommerce, Charge WooCommerce Payment processing FEES, Take Partial payment for Order, Advance COD or Partial payment for …
Kiswa COD Fee for WooCommerce Developer Profile
1 plugin · 30 total installs
How We Detect Kiswa COD Fee for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kiswa-cod-fee-for-woocommerce/assets/js/wccf-checkout.js/wp-content/plugins/kiswa-cod-fee-for-woocommerce/assets/js/wccf-checkout.jskiswa-cod-fee-for-woocommerce/assets/js/wccf-checkout.js?ver=HTML / DOM Fingerprints
data-setting_name="wccf_cod_fee_enabled"data-setting_name="wccf_cod_fee_label"data-setting_name="wccf_cod_fee_type"data-setting_name="wccf_cod_fee_amount"data-setting_name="wccf_cod_fee_min_total"window.wccf_checkout_params