Risk Free Cash On Delivery (COD) – WooCommerce Security & Risk Analysis

wordpress.org/plugins/risk-free-cash-on-delivery-cod-woocommerce

This plugin secures your Cash on delivery orders with an advance Payment option, with an additional feature of Extra fees and Restrictions.

500 active installs v1.0.4 PHP 5.2.4+ WP 3.0.1+ Updated Jun 27, 2019
advance-amountcash-on-deliverycodextra-feewoocommerce
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEAug 20, 2025
Safety Verdict

Is Risk Free Cash On Delivery (COD) – WooCommerce Safe to Use in 2026?

Use With Caution

Score 63/100

Risk Free Cash On Delivery (COD) – WooCommerce has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Aug 20, 2025Updated 6yr ago
Risk Assessment

The plugin 'risk-free-cash-on-delivery-cod-woocommerce' v1.0.4 exhibits a mixed security posture. While the static analysis reveals a commendable lack of dangerous functions and 100% of SQL queries utilizing prepared statements, there are significant areas of concern. Notably, 51% of output escaping is not properly handled, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. The presence of one flow with unsanitized paths in the taint analysis, although not categorized as critical or high severity, warrants attention as it could lead to unexpected behavior or potential exploits.

The plugin's vulnerability history is a major red flag. With one known medium-severity CVE that is currently unpatched and identified as Cross-Site Scripting, this strongly suggests a recurring weakness in input sanitization and output escaping. The fact that the last vulnerability was recent (2025-08-20) implies that the development team may not be consistently addressing security issues or that new vulnerabilities are being introduced.

In conclusion, while the plugin demonstrates good practices in some areas like SQL usage and a contained attack surface, the persistent XSS issue and the concerning taint flow highlight critical weaknesses. The unpatched medium severity CVE is the most significant risk, demanding immediate attention. The overall security is compromised by the history of vulnerabilities and the insufficient output escaping.

Key Concerns

  • Unpatched CVE (Medium Severity XSS)
  • Taint flow with unsanitized paths
  • Insufficient output escaping (51%)
Vulnerabilities
1

Risk Free Cash On Delivery (COD) – WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48358medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Risk Free Cash On Delivery (COD) - WooCommerce <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Aug 20, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Risk Free Cash On Delivery (COD) – WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
21 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

51% escaped41 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<risk_free_advanced_cod> (risk_free_advanced_cod.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Risk Free Cash On Delivery (COD) – WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
filterwoocommerce_available_payment_gatewaysincludes\sb_main_filter_class.php:7
actionwoocommerce_review_order_before_paymentincludes\sb_main_filter_class.php:35
filtergettextincludes\sb_main_filter_class.php:37
actionwoocommerce_cart_calculate_feesincludes\sb_main_filter_class.php:121
filterwoocommerce_form_field_hiddenincludes\sb_main_filter_class.php:190
filterwoocommerce_checkout_fieldsincludes\sb_main_filter_class.php:198
actioninitrisk_free_advanced_cod.php:31
actionadmin_menurisk_free_advanced_cod.php:33
actionadmin_enqueue_scriptsrisk_free_advanced_cod.php:34
actioninitrisk_free_advanced_cod.php:128
Maintenance & Trust

Risk Free Cash On Delivery (COD) – WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 27, 2019
PHP min version5.2.4
Downloads13K

Community Trust

Rating100/100
Number of ratings2
Active installs500
Developer Profile

Risk Free Cash On Delivery (COD) – WooCommerce Developer Profile

everythingwp

1 plugin · 500 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Risk Free Cash On Delivery (COD) – WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/risk-free-cash-on-delivery-cod-woocommerce/includes/sb_main_filter_class.php

HTML / DOM Fingerprints

CSS Classes
sb_boxessb_servicestable-boxtable-box-main
HTML Comments
to check wether accessed directly
Data Attributes
id="available_offers_section"style="margin-top: 0px; border: 1px solid #ccc;border-top: unset !important;padding: 5px;"
FAQ

Frequently Asked Questions about Risk Free Cash On Delivery (COD) – WooCommerce