Multistep Checkout for Woocommerce Security & Risk Analysis

wordpress.org/plugins/multistep-checkout-for-woocommerce-by-codeixer

With this plugin the Buyers of your website will get a new step by step User Interface for checkout page.Not only that,This plugin will improve your c …

10 active installs v1.0 PHP + WP 4.0+ Updated Dec 15, 2018
multistep-checkoutmultistep-checkout-for-woocommercewoocommerce-multistep-checkout
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multistep Checkout for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Multistep Checkout for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin "multistep-checkout-for-woocommerce-by-codeixer" v1.0 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and a clean taint analysis are significant strengths. The plugin also demonstrates good practices by utilizing prepared statements for its SQL queries and performing capability checks for access control, although the specific check isn't detailed. The total lack of known vulnerabilities and CVEs further supports a positive security assessment.

However, there are areas of concern that prevent a perfect score. The most notable is the significantly low percentage of properly escaped output (65%). This indicates a substantial risk of cross-site scripting (XSS) vulnerabilities, where user-supplied data might be injected and executed in the browser. Furthermore, the complete absence of any identified entry points (AJAX, REST API, shortcodes, cron) is unusual and could either indicate a very simple plugin or a limitation in the analysis itself. If the plugin *does* have functionality that is not being detected as an entry point, it represents a blind spot. The lack of nonce checks, while not directly tied to an entry point without auth, is a generally recommended security practice for many WordPress interactions.

In conclusion, the plugin shows promising security foundations with its careful handling of sensitive operations. The low rate of properly escaped output is the primary vulnerability to address. Addressing this output escaping issue and ensuring all active functionalities are properly accounted for in the attack surface would significantly bolster its security.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks identified
Vulnerabilities
None known

Multistep Checkout for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Multistep Checkout for Woocommerce Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Multistep Checkout for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
31 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

65% escaped48 total outputs
Attack Surface

Multistep Checkout for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptsinc/class.settings-api.php:30
actionadmin_initinc/options.php:16
actionadmin_menuinc/options.php:17
actionadmin_noticeswoocommerce-multistep-checkout.php:22
actionwp_enqueue_scriptswoocommerce-multistep-checkout.php:129
actionplugins_loadedwoocommerce-multistep-checkout.php:133
actionci_multistep_checkout_paymentwoocommerce-multistep-checkout.php:138
filterwc_get_templatewoocommerce-multistep-checkout.php:146
Maintenance & Trust

Multistep Checkout for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 15, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Multistep Checkout for Woocommerce Developer Profile

Niloy - Codeixer

8 plugins · 29K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
856 days
View full developer profile
Detection Fingerprints

How We Detect Multistep Checkout for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multistep-checkout-for-woocommerce-by-codeixer/assets/css/ttabs.css/wp-content/plugins/multistep-checkout-for-woocommerce-by-codeixer/assets/css/multistep-checkout.css/wp-content/plugins/multistep-checkout-for-woocommerce-by-codeixer/assets/js/ttabs.js/wp-content/plugins/multistep-checkout-for-woocommerce-by-codeixer/assets/js/scripts.js
Script Paths
https://maxcdn.bootstrapcdn.com/bootstrap/3.3.6/css/bootstrap.min.css
Version Parameters
/multistep-checkout-for-woocommerce-by-codeixer/assets/css/ttabs.css?ver=/multistep-checkout-for-woocommerce-by-codeixer/assets/css/multistep-checkout.css?ver=/multistep-checkout-for-woocommerce-by-codeixer/assets/js/ttabs.js?ver=/multistep-checkout-for-woocommerce-by-codeixer/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
ci_multistepmultistep-nav-tabssw-theme-defaultstep-anchor
JS Globals
ci_multistep
FAQ

Frequently Asked Questions about Multistep Checkout for Woocommerce