Ledyer Checkout for WooCommerce Security & Risk Analysis

wordpress.org/plugins/ledyer-checkout-for-woocommerce

Ledyer Checkout payment gateway for WooCommerce.

10 active installs v1.12.2 PHP 7.4+ WP 5.0+ Updated Jan 28, 2026
checkoute-commerceecommerceledyerwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ledyer Checkout for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Ledyer Checkout for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of 'ledyer-checkout-for-woocommerce' v1.12.2 reveals a generally strong security posture based on the provided metrics. The plugin exhibits excellent practices in several key areas: all SQL queries utilize prepared statements, 100% of output is properly escaped, and there are no observed dangerous functions or file operations. Furthermore, the absence of known CVEs and the lack of any recorded vulnerabilities in its history suggest a mature and well-maintained codebase.

However, there are a few areas that warrant attention. The plugin makes one external HTTP request, which introduces a potential dependency on external services and could be a vector for supply chain attacks if the external service is compromised. While the taint analysis shows no unsanitized paths, the limited scope of the analysis (0 flows analyzed) means this metric should be interpreted with caution. More importantly, the absence of capability checks on any entry points is a significant concern, as it implies that potentially sensitive actions could be performed by unauthenticated or unauthorized users, despite the presence of some nonce checks.

In conclusion, while the plugin demonstrates commendable adherence to secure coding principles like prepared statements and output escaping, the lack of capability checks on its entry points is a notable weakness. The single external HTTP request also presents a minor risk. The clean vulnerability history is a positive indicator, but the potential for privilege escalation due to missing capability checks should be addressed to ensure a more robust security profile.

Key Concerns

  • No capability checks on entry points
  • External HTTP request made
Vulnerabilities
None known

Ledyer Checkout for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ledyer Checkout for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
98 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped98 total outputs
Attack Surface

Ledyer Checkout for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadd_meta_boxesclasses\admin\class-ledyer-meta-box.php:26
actionrest_api_initclasses\class-ledyer-callback.php:54
actionschedule_process_notificationclasses\class-ledyer-callback.php:55
actionwoocommerce_after_calculate_totalsclasses\class-ledyer-checkout.php:25
actioninitclasses\class-ledyer-confirmation.php:27
actionwoocommerce_checkout_fieldsclasses\class-ledyer-main.php:67
filterwoocommerce_payment_gatewaysclasses\class-ledyer-main.php:105
actionlco_wc_after_order_reviewclasses\class-ledyer-templates.php:53
actionlco_wc_before_snippetclasses\class-ledyer-templates.php:54
actionbefore_woocommerce_initledyer-checkout-for-woocommerce.php:50
Maintenance & Trust

Ledyer Checkout for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Ledyer Checkout for WooCommerce Developer Profile

simonledyer

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ledyer Checkout for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ledyer-checkout-for-woocommerce/build/ledyer-checkout-for-woocommerce.css
Script Paths
https://checkout.live.ledyer.com/bootstrap.jshttp://localhost:1337/bootstrap.iife.jshttps://checkout.dev.ledyer.com/bootstrap.jshttps://checkout.sandbox.ledyer.com/bootstrap.js/wp-content/plugins/ledyer-checkout-for-woocommerce/assets/js/ledyer-checkout-for-woocommerce.js
Version Parameters
ledyer-checkout-for-woocommerce/build/ledyer-checkout-for-woocommerce.css?ver=ledyer-checkout-for-woocommerce.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-lco-payment-gateway
JS Globals
window.LedyerCheckoutwindow.Ledyerwindow.LCO_WC_VERSION
FAQ

Frequently Asked Questions about Ledyer Checkout for WooCommerce