
Livees Checkout Security & Risk Analysis
wordpress.org/plugins/livees-checkoutLivees Checkout® Más que una pasarela de pagos: el puente definitivo entre tu negocio y todos los medios electrónicos regulados por ASFI.
Is Livees Checkout Safe to Use in 2026?
Generally Safe
Score 100/100Livees Checkout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The livees-checkout plugin v6.8.4 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query sanitization and output escaping, there are significant concerns regarding its entry points. The plugin exposes two AJAX handlers without any authentication or capability checks, creating a substantial attack surface. This lack of protection on these handlers is a critical weakness, as it allows any unauthenticated user to potentially trigger plugin functionality, leading to unexpected behavior or exploitation.
The static analysis also reveals a complete absence of nonce checks and capability checks across all identified entry points, which further exacerbates the risk associated with the unprotected AJAX handlers. The taint analysis shows no identified vulnerabilities, which is a positive sign. Furthermore, the plugin has no recorded history of known vulnerabilities (CVEs), suggesting a generally stable code base in terms of past exploits. However, this lack of historical issues does not mitigate the present risks identified in the current code analysis.
In conclusion, the plugin's strong adherence to prepared statements for SQL and high percentage of properly escaped output are commendable. Nevertheless, the unprotected AJAX handlers represent a significant security flaw that requires immediate attention. The absence of nonce and capability checks on these critical entry points makes the plugin susceptible to various attacks. This oversight overshadows the otherwise positive aspects of the plugin's security implementation.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Missing capability checks
Livees Checkout Security Vulnerabilities
Livees Checkout Release Timeline
Livees Checkout Code Analysis
Output Escaping
Livees Checkout Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Livees Checkout Maintenance & Trust
Maintenance Signals
Community Trust
Livees Checkout Alternatives
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
MONEI Payments for WooCommerce
monei
Accept Card, Apple Pay, Google Pay, Bizum, PayPal and many more payment methods in your WooCommerce store using MONEI payment gateway.
Paystation Payment Gateway for woocommerce
paystation-woocommerce-payment-gateway
Take credit card payments on your store via Paystation.
Ecart Pay
ecart-pay
Ecart Pay allows online merchants to quickly and securely accept payments through WooCommerce. With multiple payment options, this plugin is easy to s …
Paypercut Payments for WooCommerce
paypercut-payments-for-woocommerce
Paypercut Payments enables WooCommerce merchants to accept online payments using Paypercut's checkout experience.
Livees Checkout Developer Profile
1 plugin · 100 total installs
How We Detect Livees Checkout
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/livees-checkout/build/index.js/wp-content/plugins/livees-checkout/build/index.jslivees-checkout/build/index.js?ver=HTML / DOM Fingerprints
<!-- Este plugin se encuentra protegido por derechos de autor. Cualquier similitud, copia o parecido con el mismo --><!-- � ser� considerado plagio y estar� sujeto a las leyes de protecci�n de derechos de autor en Bolivia. --><!-- Propiedad de la empresa Livees. Bolivia. --><!-- Livees Gateway -->+10 moredata-livees-settingsliveesSettings[wc_iframe_gateway_view]