Lexiata Secure COD Security & Risk Analysis

wordpress.org/plugins/lexiata-secure-cod

Secure your Cash on Delivery orders by collecting a deposit/booking fee upfront and collecting the balance amount upon delivery.

0 active installs v1.0.4 PHP 7.2+ WP 5.8+ Updated Unknown
cash-on-deliverycoddepositpartial-paymentwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Lexiata Secure COD Safe to Use in 2026?

Generally Safe

Score 100/100

Lexiata Secure COD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'lexiata-secure-cod' plugin v1.0.4 presents a seemingly strong security posture. The absence of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant positive, indicating that the plugin does not expose easily accessible entry points for attackers. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries that are not prepared, and no file operations or external HTTP requests, all of which are excellent security practices. The vulnerability history being entirely clear of known CVEs further reinforces this positive impression.

However, there are areas of concern. A notable weakness is the lack of any capability checks or nonce checks across all identified entry points, even though there are no entry points identified. This suggests a potential blind spot in the plugin's security implementation. Additionally, while the plugin has few output operations, 40% of them are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the data originates from user input or external sources. The taint analysis reporting zero flows analyzed is also a point of caution; it could mean there are no such flows or that the analysis was not comprehensive enough to detect them.

In conclusion, while the plugin benefits from a minimal attack surface and a clean vulnerability history, the absence of robust authentication and authorization checks (capability and nonce checks) and the presence of unescaped output represent potential risks. The limited taint analysis scope also warrants a degree of caution. The plugin's current version appears to be free of known high-severity vulnerabilities, but these identified weaknesses could be exploited in specific scenarios.

Key Concerns

  • Unescaped output found
  • No capability checks implemented
  • No nonce checks implemented
  • Taint analysis not comprehensive
Vulnerabilities
None known

Lexiata Secure COD Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Lexiata Secure COD Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped5 total outputs
Attack Surface

Lexiata Secure COD Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedlexiata-secure-cod.php:128
filterwoocommerce_payment_gatewayslexiata-secure-cod.php:137
filterwoocommerce_settings_api_form_fields_lexiata_secure_codlexiata-secure-cod.php:142
actionwoocommerce_review_order_before_paymentlexiata-secure-cod.php:171
actionwp_enqueue_scriptslexiata-secure-cod.php:209
actionwoocommerce_checkout_update_order_reviewlexiata-secure-cod.php:285
actionwoocommerce_cart_calculate_feeslexiata-secure-cod.php:299
filterwoocommerce_get_order_item_totalslexiata-secure-cod.php:344
actionwoocommerce_thankyoulexiata-secure-cod.php:370
actionwoocommerce_email_after_order_tablelexiata-secure-cod.php:371
actionadmin_enqueue_scriptslexiata-secure-cod.php:423
Maintenance & Trust

Lexiata Secure COD Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.2
Downloads145

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Lexiata Secure COD Developer Profile

Suresh Lasantha

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lexiata Secure COD

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lexiata-secure-cod/assets/css/lexiata-secure-cod.css/wp-content/plugins/lexiata-secure-cod/assets/js/lexiata-secure-cod.js
Version Parameters
lexiata-secure-cod/assets/css/lexiata-secure-cod.css?ver=lexiata-secure-cod/assets/js/lexiata-secure-cod.js?ver=

HTML / DOM Fingerprints

CSS Classes
lexiata-scod-wrapper
HTML Comments
<!-- Development by <a href="https://lexiata.lk" target="_blank" style="text-decoration:none; color:#0073aa; font-weight:bold;">Lexiata.lk</a> -->
Data Attributes
name="lexiata_scod_checkbox"id="lexiata_scod_checkbox"
JS Globals
window.lexiata_scod_is_activevar lexiata_scod_is_active
FAQ

Frequently Asked Questions about Lexiata Secure COD