Livees Checkout Security & Risk Analysis

wordpress.org/plugins/livees-checkout

Livees Checkout® Más que una pasarela de pagos: el puente definitivo entre tu negocio y todos los medios electrónicos regulados por ASFI.

100 active installs v6.8.4 PHP + WP 6.0+ Updated Sep 15, 2025
boliviaecommercegatewaylivees-checkoutpayments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Livees Checkout Safe to Use in 2026?

Generally Safe

Score 100/100

Livees Checkout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The livees-checkout plugin v6.8.4 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query sanitization and output escaping, there are significant concerns regarding its entry points. The plugin exposes two AJAX handlers without any authentication or capability checks, creating a substantial attack surface. This lack of protection on these handlers is a critical weakness, as it allows any unauthenticated user to potentially trigger plugin functionality, leading to unexpected behavior or exploitation.

The static analysis also reveals a complete absence of nonce checks and capability checks across all identified entry points, which further exacerbates the risk associated with the unprotected AJAX handlers. The taint analysis shows no identified vulnerabilities, which is a positive sign. Furthermore, the plugin has no recorded history of known vulnerabilities (CVEs), suggesting a generally stable code base in terms of past exploits. However, this lack of historical issues does not mitigate the present risks identified in the current code analysis.

In conclusion, the plugin's strong adherence to prepared statements for SQL and high percentage of properly escaped output are commendable. Nevertheless, the unprotected AJAX handlers represent a significant security flaw that requires immediate attention. The absence of nonce and capability checks on these critical entry points makes the plugin susceptible to various attacks. This oversight overshadows the otherwise positive aspects of the plugin's security implementation.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • Missing capability checks
Vulnerabilities
None known

Livees Checkout Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Livees Checkout Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Livees Checkout Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

94% escaped35 total outputs
Attack Surface
2 unprotected

Livees Checkout Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_wc_iframe_complete_orderlivees-checkout.php:209
noprivwp_ajax_wc_iframe_complete_orderlivees-checkout.php:210

Shortcodes 1

[wc_iframe_gateway_view] includes\shortcodes.php:7
WordPress Hooks 9
filterwoocommerce_admin_settings_sanitize_optionincludes\class-wc-iframe-gateway.php:197
actionplugins_loadedlivees-checkout.php:93
filterwoocommerce_payment_gatewayslivees-checkout.php:106
actionwoocommerce_blocks_payment_method_type_registrationlivees-checkout.php:115
actionenqueue_block_editor_assetslivees-checkout.php:187
actionwp_enqueue_scriptslivees-checkout.php:188
filterwoocommerce_get_return_urllivees-checkout.php:190
actiontemplate_redirectlivees-checkout.php:243
actionwoocommerce_before_thankyoulivees-checkout.php:383
Maintenance & Trust

Livees Checkout Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 15, 2025
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Livees Checkout Developer Profile

Livees

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Livees Checkout

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/livees-checkout/build/index.js
Script Paths
/wp-content/plugins/livees-checkout/build/index.js
Version Parameters
livees-checkout/build/index.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Este plugin se encuentra protegido por derechos de autor. Cualquier similitud, copia o parecido con el mismo --><!-- � ser� considerado plagio y estar� sujeto a las leyes de protecci�n de derechos de autor en Bolivia. --><!-- Propiedad de la empresa Livees. Bolivia. --><!-- Livees Gateway -->+10 more
Data Attributes
data-livees-settings
JS Globals
liveesSettings
Shortcode Output
[wc_iframe_gateway_view]
FAQ

Frequently Asked Questions about Livees Checkout