
Risk Free Cash On Delivery (COD) – WooCommerce Security & Risk Analysis
wordpress.org/plugins/risk-free-cash-on-delivery-cod-woocommerceThis plugin secures your Cash on delivery orders with an advance Payment option, with an additional feature of Extra fees and Restrictions.
Is Risk Free Cash On Delivery (COD) – WooCommerce Safe to Use in 2026?
Use With Caution
Score 63/100Risk Free Cash On Delivery (COD) – WooCommerce has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin 'risk-free-cash-on-delivery-cod-woocommerce' v1.0.4 exhibits a mixed security posture. While the static analysis reveals a commendable lack of dangerous functions and 100% of SQL queries utilizing prepared statements, there are significant areas of concern. Notably, 51% of output escaping is not properly handled, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. The presence of one flow with unsanitized paths in the taint analysis, although not categorized as critical or high severity, warrants attention as it could lead to unexpected behavior or potential exploits.
The plugin's vulnerability history is a major red flag. With one known medium-severity CVE that is currently unpatched and identified as Cross-Site Scripting, this strongly suggests a recurring weakness in input sanitization and output escaping. The fact that the last vulnerability was recent (2025-08-20) implies that the development team may not be consistently addressing security issues or that new vulnerabilities are being introduced.
In conclusion, while the plugin demonstrates good practices in some areas like SQL usage and a contained attack surface, the persistent XSS issue and the concerning taint flow highlight critical weaknesses. The unpatched medium severity CVE is the most significant risk, demanding immediate attention. The overall security is compromised by the history of vulnerabilities and the insufficient output escaping.
Key Concerns
- Unpatched CVE (Medium Severity XSS)
- Taint flow with unsanitized paths
- Insufficient output escaping (51%)
Risk Free Cash On Delivery (COD) – WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Risk Free Cash On Delivery (COD) - WooCommerce <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Risk Free Cash On Delivery (COD) – WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Risk Free Cash On Delivery (COD) – WooCommerce Attack Surface
WordPress Hooks 10
Maintenance & Trust
Risk Free Cash On Delivery (COD) – WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Risk Free Cash On Delivery (COD) – WooCommerce Alternatives
Smart COD for WooCommerce
wc-smart-cod
All the COD restrictions and extra fees you'll ever need, in a single plugin.
PCOD – Partial COD, Payment Gateway Restrictions & Fees | for WooCommerce
partial-cod-payment-gateway-restrictions-fees
Advanced Partial COD, Payment Method Restrictions, Cart Fees & Cart Discounts for WooCommerce
Kiswa COD Fee for WooCommerce
kiswa-cod-fee-for-woocommerce
Add a simple extra fee when customers choose Cash on Delivery (COD) in WooCommerce.
PiWeb Disable payment method / Partial payment for WooCommerce
disable-payment-method-for-woocommerce
Disable payment method for WooCommerce, Charge WooCommerce Payment processing FEES, Take Partial payment for Order, Advance COD or Partial payment for …
WooBooster Partial COD for WooCommerce
wb-partial-cod-for-woocommerce
Best Wordpress plugin to Allows you to take partial payment via Cash on Delivery (COD) in WooCommerce.
Risk Free Cash On Delivery (COD) – WooCommerce Developer Profile
1 plugin · 500 total installs
How We Detect Risk Free Cash On Delivery (COD) – WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/risk-free-cash-on-delivery-cod-woocommerce/includes/sb_main_filter_class.phpHTML / DOM Fingerprints
sb_boxessb_servicestable-boxtable-box-main to check wether accessed directlyid="available_offers_section"style="margin-top: 0px;
border: 1px solid #ccc;border-top: unset !important;padding: 5px;"