Kiswa COD Fee for WooCommerce Security & Risk Analysis

wordpress.org/plugins/kiswa-cod-fee-for-woocommerce

Add a simple extra fee when customers choose Cash on Delivery (COD) in WooCommerce.

30 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Dec 19, 2025
cash-on-deliverycheckoutcodextra-feewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kiswa COD Fee for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Kiswa COD Fee for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The static analysis of the "kiswa-cod-fee-for-woocommerce" plugin v1.0.0 reveals a generally strong security posture. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. The code also demonstrates good practices in handling SQL queries, with 100% utilizing prepared statements, and a low number of file operations and external HTTP requests. The presence of one capability check is also a positive sign.

However, a few areas warrant attention. While the overall output escaping is good at 80%, the remaining 20% of unescaped outputs could potentially lead to cross-site scripting (XSS) vulnerabilities if malicious data is introduced through other means. The absence of nonce checks, although not directly tied to any identified entry points in this analysis, is a common security control that is missing and could be a concern if new entry points are introduced in future versions without proper authentication checks. The vulnerability history is clean, with no known CVEs, which is a significant strength and suggests the developers have a good track record.

In conclusion, the plugin appears to be developed with security in mind, especially given its limited attack surface and secure SQL handling. The main weaknesses lie in the unescaped outputs and the missing nonce checks, which, while not exploited in the current analysis, represent potential vulnerabilities. The lack of historical vulnerabilities is a strong positive indicator.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
Vulnerabilities
None known

Kiswa COD Fee for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kiswa COD Fee for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped5 total outputs
Attack Surface

Kiswa COD Fee for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_noticeskiswa-cod-fee-for-woocommerce.php:40
filterwoocommerce_settings_tabs_arraykiswa-cod-fee-for-woocommerce.php:45
actionwoocommerce_settings_tabs_wccf_cod_feekiswa-cod-fee-for-woocommerce.php:46
actionwoocommerce_update_options_wccf_cod_feekiswa-cod-fee-for-woocommerce.php:47
actionwoocommerce_cart_calculate_feeskiswa-cod-fee-for-woocommerce.php:50
actionplugins_loadedkiswa-cod-fee-for-woocommerce.php:52
actionwp_enqueue_scriptskiswa-cod-fee-for-woocommerce.php:68
actionwoocommerce_cart_calculate_feeskiswa-cod-fee-for-woocommerce.php:296
actionwoocommerce_review_order_before_paymentkiswa-cod-fee-for-woocommerce.php:308
Maintenance & Trust

Kiswa COD Fee for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 19, 2025
PHP min version7.4
Downloads180

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Kiswa COD Fee for WooCommerce Developer Profile

kiswasolutions

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kiswa COD Fee for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kiswa-cod-fee-for-woocommerce/assets/js/wccf-checkout.js
Script Paths
/wp-content/plugins/kiswa-cod-fee-for-woocommerce/assets/js/wccf-checkout.js
Version Parameters
kiswa-cod-fee-for-woocommerce/assets/js/wccf-checkout.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-setting_name="wccf_cod_fee_enabled"data-setting_name="wccf_cod_fee_label"data-setting_name="wccf_cod_fee_type"data-setting_name="wccf_cod_fee_amount"data-setting_name="wccf_cod_fee_min_total"
JS Globals
window.wccf_checkout_params
FAQ

Frequently Asked Questions about Kiswa COD Fee for WooCommerce