
Lexiata Secure COD Security & Risk Analysis
wordpress.org/plugins/lexiata-secure-codSecure your Cash on Delivery orders by collecting a deposit/booking fee upfront and collecting the balance amount upon delivery.
Is Lexiata Secure COD Safe to Use in 2026?
Generally Safe
Score 100/100Lexiata Secure COD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the 'lexiata-secure-cod' plugin v1.0.4 presents a seemingly strong security posture. The absence of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant positive, indicating that the plugin does not expose easily accessible entry points for attackers. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries that are not prepared, and no file operations or external HTTP requests, all of which are excellent security practices. The vulnerability history being entirely clear of known CVEs further reinforces this positive impression.
However, there are areas of concern. A notable weakness is the lack of any capability checks or nonce checks across all identified entry points, even though there are no entry points identified. This suggests a potential blind spot in the plugin's security implementation. Additionally, while the plugin has few output operations, 40% of them are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the data originates from user input or external sources. The taint analysis reporting zero flows analyzed is also a point of caution; it could mean there are no such flows or that the analysis was not comprehensive enough to detect them.
In conclusion, while the plugin benefits from a minimal attack surface and a clean vulnerability history, the absence of robust authentication and authorization checks (capability and nonce checks) and the presence of unescaped output represent potential risks. The limited taint analysis scope also warrants a degree of caution. The plugin's current version appears to be free of known high-severity vulnerabilities, but these identified weaknesses could be exploited in specific scenarios.
Key Concerns
- Unescaped output found
- No capability checks implemented
- No nonce checks implemented
- Taint analysis not comprehensive
Lexiata Secure COD Security Vulnerabilities
Lexiata Secure COD Code Analysis
Output Escaping
Lexiata Secure COD Attack Surface
WordPress Hooks 11
Maintenance & Trust
Lexiata Secure COD Maintenance & Trust
Maintenance Signals
Community Trust
Lexiata Secure COD Alternatives
PiWeb Disable payment method / Partial payment for WooCommerce
disable-payment-method-for-woocommerce
Disable payment method for WooCommerce, Charge WooCommerce Payment processing FEES, Take Partial payment for Order, Advance COD or Partial payment for …
Smart COD for WooCommerce
wc-smart-cod
All the COD restrictions and extra fees you'll ever need, in a single plugin.
Deposits & Partial Payments for WooCommerce
deposits-for-woocommerce
Deposits for WooCommerce is allowing customers to pay for WooCommerce products using a partial payment.💰
Risk Free Cash On Delivery (COD) – WooCommerce
risk-free-cash-on-delivery-cod-woocommerce
This plugin secures your Cash on delivery orders with an advance Payment option, with an additional feature of Extra fees and Restrictions.
WooBooster Partial COD for WooCommerce
wb-partial-cod-for-woocommerce
Best Wordpress plugin to Allows you to take partial payment via Cash on Delivery (COD) in WooCommerce.
Lexiata Secure COD Developer Profile
2 plugins · 0 total installs
How We Detect Lexiata Secure COD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lexiata-secure-cod/assets/css/lexiata-secure-cod.css/wp-content/plugins/lexiata-secure-cod/assets/js/lexiata-secure-cod.jslexiata-secure-cod/assets/css/lexiata-secure-cod.css?ver=lexiata-secure-cod/assets/js/lexiata-secure-cod.js?ver=HTML / DOM Fingerprints
lexiata-scod-wrapper<!-- Development by <a href="https://lexiata.lk" target="_blank" style="text-decoration:none; color:#0073aa; font-weight:bold;">Lexiata.lk</a> -->name="lexiata_scod_checkbox"id="lexiata_scod_checkbox"window.lexiata_scod_is_activevar lexiata_scod_is_active