Resolve for WooCommerce Security & Risk Analysis

wordpress.org/plugins/resolve-for-woocommerce

Resolve for WooCommerce.

10 active installs v1.0.8 PHP 7.2+ WP 5.0+ Updated Jan 20, 2026
gatewaypaymentresolvewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Resolve for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Resolve for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "resolve-for-woocommerce" plugin v1.0.8 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, coupled with the plugin's adherence to secure coding practices like using prepared statements for SQL, proper output escaping for the vast majority of outputs, and the presence of nonce and capability checks, suggests a development team that is mindful of security.

However, there are a few areas that warrant attention. The presence of external HTTP requests, while only one, could potentially be a vector for various attacks if not handled with extreme care and proper validation on both ends. Additionally, while no taint flows with unsanitized paths were identified, the lack of taint analysis flows analyzed (0 total) means this aspect of the plugin's security hasn't been thoroughly tested. This could indicate either a very simple plugin where taint is unlikely, or a gap in the static analysis process itself.

In conclusion, "resolve-for-woocommerce" v1.0.8 is currently in a strong security state. The development team has implemented several key security measures. The primary concern lies in the potential, albeit unproven by the current analysis, risks associated with the external HTTP request and the limited scope of the taint analysis. Continued vigilance and comprehensive testing, particularly for the external HTTP call, are recommended.

Key Concerns

  • External HTTP requests present potential risk
  • Limited taint analysis performed
Vulnerabilities
None known

Resolve for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Resolve for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
11 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

92% escaped12 total outputs
Attack Surface

Resolve for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_rfw_get_checkout_dataincludes\core\class-rfw-ajax-interface.php:14
noprivwp_ajax_rfw_get_checkout_dataincludes\core\class-rfw-ajax-interface.php:15
WordPress Hooks 14
actionwp_enqueue_scriptsincludes\core\class-rfw-payment-gateway.php:31
filterwoocommerce_available_payment_gatewaysincludes\core\class-rfw-payment-gateway.php:63
actionwoocommerce_order_item_add_action_buttonsincludes\core\class-rfw-payment-gateway.php:65
actionsave_postincludes\core\class-rfw-payment-gateway.php:66
actionadmin_noticesresolve-for-woocommerce.php:53
actionbefore_woocommerce_initresolve-for-woocommerce.php:68
filterwoocommerce_payment_gatewaysresolve-for-woocommerce.php:111
actionadmin_enqueue_scriptsresolve-for-woocommerce.php:114
actionadmin_initresolve-for-woocommerce.php:116
actionadmin_initresolve-for-woocommerce.php:117
actionactivated_pluginresolve-for-woocommerce.php:118
actionwoocommerce_admin_field_payment_gatewaysresolve-for-woocommerce.php:119
actionadmin_noticesresolve-for-woocommerce.php:276
actionplugins_loadedresolve-for-woocommerce.php:380
Maintenance & Trust

Resolve for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 20, 2026
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Resolve for WooCommerce Developer Profile

Resolve

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Resolve for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/resolve-for-woocommerce/assets/dist/js/rfw-admin.js
Script Paths
/wp-content/plugins/resolve-for-woocommerce/assets/dist/js/rfw-admin.js
Version Parameters
resolve-for-woocommerce/assets/dist/js/rfw-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
RFWPaymentGateway
FAQ

Frequently Asked Questions about Resolve for WooCommerce