Purchase Redirect for WooCommerce Security & Risk Analysis

wordpress.org/plugins/purchase-redirect-for-woocommerce

A powerful tool that allows you to redirect users after they make a purchase on WooCommerce store and generate temporary links for added functionality

100 active installs v1.0.9 PHP 7.0+ WP 5.1+ Updated Feb 1, 2026
orderpurchaseredirectthank-youwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Purchase Redirect for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Purchase Redirect for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "purchase-redirect-for-woocommerce" plugin v1.0.9 exhibits a generally strong security posture, with several good practices evident in its code. The absence of known vulnerabilities, including CVEs, and the fact that all SQL queries utilize prepared statements are significant strengths. Furthermore, the plugin demonstrates a commitment to security by implementing nonce checks and capability checks on its entry points, and nearly all output is properly escaped. The attack surface, while consisting of two AJAX handlers, is noted as having zero unprotected entry points, which is a positive indicator.

Despite the generally positive findings, a single taint flow with an unsanitized path presents a potential, albeit unexploited, risk. While the severity is not rated as critical or high, any unsanitized path warrants attention as it could theoretically lead to security issues if not handled with extreme care. The plugin's history of no recorded vulnerabilities is a strong positive signal, suggesting a proactive approach to security and a well-maintained codebase. However, the presence of even one unsanitized path, regardless of historical or rated severity, introduces a minor concern that should ideally be addressed to achieve a fully hardened security profile.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

Purchase Redirect for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Purchase Redirect for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
17 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

94% escaped18 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
healomaxprwc_early_redirect_handler (purchase-redirect-for-woocommerce.php:222)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Purchase Redirect for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_healomaxprwc_dismiss_ratingpurchase-redirect-for-woocommerce.php:194
authwp_ajax_healomaxprwc_remind_laterpurchase-redirect-for-woocommerce.php:207
WordPress Hooks 9
actionadmin_menuadmin.php:15
actionadmin_initadmin.php:67
actionwpadmin.php:154
actionbefore_woocommerce_initpurchase-redirect-for-woocommerce.php:18
actionadmin_noticespurchase-redirect-for-woocommerce.php:113
actioninitpurchase-redirect-for-woocommerce.php:221
actionwoocommerce_payment_completepurchase-redirect-for-woocommerce.php:286
actionwoocommerce_thankyoupurchase-redirect-for-woocommerce.php:328
actionwp_enqueue_scriptsscripts\purchase-redirect-for-woocommerce-scripts.php:15
Maintenance & Trust

Purchase Redirect for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 1, 2026
PHP min version7.0
Downloads5K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Purchase Redirect for WooCommerce Developer Profile

healomax

3 plugins · 110 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Purchase Redirect for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/purchase-redirect-for-woocommerce/assets/css/style.css/wp-content/plugins/purchase-redirect-for-woocommerce/assets/js/main.js
Script Paths
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.7.1/jquery.min.js
Version Parameters
purchase-redirect-for-woocommerce/assets/css/style.css?ver=purchase-redirect-for-woocommerce/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
healomaxprwc-rating-noticehealomaxprwc-dismiss-ratinghealomaxprwc-remind-later
Data Attributes
data-nonce
JS Globals
healomaxprwc_dismiss_ratinghealomaxprwc_remind_later
FAQ

Frequently Asked Questions about Purchase Redirect for WooCommerce