Rescindly for WooCommerce Security & Risk Analysis

wordpress.org/plugins/rescindly-for-woocommerce

Online withdrawal workflow for WooCommerce — connect your store to Rescindly and support Directive (EU) 2023/2673 readiness.

0 active installs v1.4.2 PHP 7.4+ WP 6.0+ Updated Apr 2, 2026
complianceecommercelegalwithdrawalwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rescindly for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Rescindly for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of rescindly-for-woocommerce v1.4.2 reveals a strong security posture in several key areas. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by exclusively using prepared statements for SQL queries and properly escaping all identified output. The lack of file operations, external HTTP requests, and bundled libraries also mitigates common plugin vulnerabilities.

However, the analysis does flag a potential area of concern with the complete absence of nonce checks and capability checks. While the current static analysis indicates zero entry points, the lack of these fundamental security mechanisms means that if any new entry points were to be introduced in future versions or through interactions with other plugins, they would be inherently unprotected. The vulnerability history is also clean, showing no recorded CVEs, which is a positive sign, but it doesn't entirely compensate for the missing checks that are standard security practices.

In conclusion, rescindly-for-woocommerce v1.4.2 appears to be a secure plugin based on the current analysis, particularly concerning its handling of database interactions and output. The developers have implemented robust practices in these areas. The primary weakness lies in the absence of nonce and capability checks, which represents a missed opportunity for fundamental security hardening. While no active vulnerabilities are evident, this omission could pose a risk if the plugin's interaction surface expands.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Rescindly for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Rescindly for WooCommerce Release Timeline

v1.4.3
v1.4.2Current
v1.4.1
Code Analysis
Analyzed Apr 16, 2026

Rescindly for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

Rescindly for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filterwoocommerce_settings_tabs_arrayincludes/class-settings.php:13
actionwoocommerce_settings_tabs_rescindlyincludes/class-settings.php:14
actionwoocommerce_update_options_rescindlyincludes/class-settings.php:15
actionadmin_enqueue_scriptsincludes/class-settings.php:16
actionwp_enqueue_scriptsincludes/class-triggers.php:30
actionwp_footerincludes/class-triggers.php:31
actionwoocommerce_thankyouincludes/class-triggers.php:32
actionwoocommerce_order_details_after_order_tableincludes/class-triggers.php:33
actionwp_enqueue_scriptsincludes/class-widget.php:18
actionadmin_noticesrescindly.php:29
actionplugins_loadedrescindly.php:55
Maintenance & Trust

Rescindly for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 2, 2026
PHP min version7.4
Downloads134

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Rescindly for WooCommerce Developer Profile

rescindly

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Rescindly for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rescindly-for-woocommerce/assets/css/admin.css/wp-content/plugins/rescindly-for-woocommerce/assets/js/admin.js
Version Parameters
rescindly-for-woocommerce/assets/css/admin.css?ver=rescindly-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
rescindly-section-title
Data Attributes
data-rescindly-order
JS Globals
rescindly_admin_toggle
FAQ

Frequently Asked Questions about Rescindly for WooCommerce