SA Hosted Checkout for WooCommerce Security & Risk Analysis

wordpress.org/plugins/sa-hosted-checkout-for-woocommerce

Replace WooCommerce checkout with Stripe Checkout quickly. Let your customers pay with confidence using highly optimized, Stripe hosted checkout.

0 active installs v1.0.4 PHP 5.6+ WP 5.1+ Updated Unknown
express-checkoutsecure-checkoutstripestripe-checkoutwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SA Hosted Checkout for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

SA Hosted Checkout for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "sa-hosted-checkout-for-woocommerce" plugin version 1.0.4 exhibits a strong security posture based on the provided static analysis. The absence of critical or high-severity issues in taint analysis, coupled with the responsible use of prepared statements for all SQL queries and a very high rate of output escaping, indicates a developer who prioritizes secure coding practices. The plugin also demonstrates a good understanding of WordPress security by implementing nonce checks and capability checks on its entry points, which are all protected. The limited attack surface, consisting only of two AJAX handlers, is further mitigated by the lack of unprotected entry points.

While the static analysis reveals an almost flawless implementation, the absence of any recorded vulnerability history might suggest a lack of widespread testing or a relatively new plugin. However, this is not a direct security concern from the code itself. The plugin's strengths lie in its robust input validation and sanitization, as evidenced by the clean taint analysis and well-escaped outputs. There are no immediate red flags or evident vulnerabilities that would suggest a high risk for users.

In conclusion, "sa-hosted-checkout-for-woocommerce" v1.0.4 appears to be a secure plugin. The development team has demonstrated a commitment to secure coding, with excellent performance in crucial areas like SQL querying and output escaping. The minimal attack surface and protected entry points further enhance its security. Without any known vulnerabilities or significant issues identified in the static analysis, the overall risk is assessed as low.

Vulnerabilities
None known

SA Hosted Checkout for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SA Hosted Checkout for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
1
80 escaped
Nonce Checks
3
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

99% escaped81 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
sahcfwc_stripe_checkout_order_callback (includes\classes\class-sahcfwc-post-checkout.php:131)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SA Hosted Checkout for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_sahcfwc_get_stripe_checkout_urlincludes\classes\class-sahcfwc-checkout-button-url-ajax.php:265
noprivwp_ajax_sahcfwc_get_stripe_checkout_urlincludes\classes\class-sahcfwc-checkout-button-url-ajax.php:266
WordPress Hooks 23
actionsahcfwc_plugin_loadedincludes\bootstrap\class-sahcfwc-app.php:47
actioninitincludes\bootstrap\class-sahcfwc-app.php:48
actioninitincludes\bootstrap\class-sahcfwc-app.php:49
actioninitincludes\bootstrap\class-sahcfwc-app.php:50
actioninitincludes\bootstrap\class-sahcfwc-app.php:51
filterwoocommerce_payment_gatewaysincludes\bootstrap\class-sahcfwc-app.php:52
actionwoocommerce_emailincludes\bootstrap\class-sahcfwc-app.php:53
actionwp_enqueue_scriptsincludes\classes\class-sahcfwc-checkout-button-url-ajax.php:264
actionwp_enqueue_scriptsincludes\classes\class-sahcfwc-payment-gateway.php:238
actionset_logged_in_cookieincludes\classes\class-sahcfwc-payment-gateway.php:240
actionwc_ajax_sahcfwc_stripe_checkout_orderincludes\classes\class-sahcfwc-post-checkout.php:81
actionwc_ajax_sahcfwc_stripe_cancel_orderincludes\classes\class-sahcfwc-post-checkout.php:82
filterwoocommerce_coupon_is_validincludes\classes\class-sahcfwc-pre-checkout.php:48
filterwoocommerce_coupon_errorincludes\classes\class-sahcfwc-pre-checkout.php:54
actionadmin_menuincludes\pages\class-sahcfwc-dashboard.php:37
actionadmin_enqueue_scriptsincludes\pages\class-sahcfwc-dashboard.php:38
actionrest_api_initincludes\rest-api\class-sahcfwc-stripe-country-and-key-status.php:50
actionrest_api_initincludes\rest-api\class-sahcfwc-stripe-local-payment-methods.php:51
actionrest_api_initincludes\webhooks\class-sahcfwc-stripe-listener.php:82
actionsahcfwc_charge_succeededincludes\webhooks\class-sahcfwc-stripe-listener.php:83
actionsahcfwc_payment_intent_succeededincludes\webhooks\class-sahcfwc-stripe-listener.php:84
actionplugins_loadedsa-hosted-checkout-for-woocommerce.php:65
filterplugin_row_metasa-hosted-checkout-for-woocommerce.php:82
Maintenance & Trust

SA Hosted Checkout for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version5.6
Downloads759

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SA Hosted Checkout for WooCommerce Developer Profile

Sleek Algo

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SA Hosted Checkout for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sa-hosted-checkout-for-woocommerce/assets/frontend/css/checkout.css/wp-content/plugins/sa-hosted-checkout-for-woocommerce/assets/frontend/js/checkout.js/wp-content/plugins/sa-hosted-checkout-for-woocommerce/assets/frontend/js/payment-gateways.js/wp-content/plugins/sa-hosted-checkout-for-woocommerce/assets/frontend/js/stripe.js
Script Paths
/wp-content/plugins/sa-hosted-checkout-for-woocommerce/assets/frontend/js/checkout.js/wp-content/plugins/sa-hosted-checkout-for-woocommerce/assets/frontend/js/payment-gateways.js/wp-content/plugins/sa-hosted-checkout-for-woocommerce/assets/frontend/js/stripe.js
Version Parameters
sa-hosted-checkout-for-woocommerce/assets/frontend/css/checkout.css?ver=sa-hosted-checkout-for-woocommerce/assets/frontend/js/checkout.js?ver=sa-hosted-checkout-for-woocommerce/assets/frontend/js/payment-gateways.js?ver=sa-hosted-checkout-for-woocommerce/assets/frontend/js/stripe.js?ver=

HTML / DOM Fingerprints

CSS Classes
sahcfwc-checkoutsleekalgo-checkout-container
Data Attributes
data-sahcfwc-checkout-noncedata-sahcfwc-stripe-publishable-keydata-sahcfwc-stripe-locale
JS Globals
SAHCFWC_AJAX_URLSAHCFWC_INIT_PARAMSStripe
REST Endpoints
/wp-json/sahcfwc/v1/create-checkout-session/wp-json/sahcfwc/v1/get-checkout-details
Shortcode Output
[sleek_hosted_checkout]
FAQ

Frequently Asked Questions about SA Hosted Checkout for WooCommerce