Stripe Tax – Sales tax automation for WooCommerce Security & Risk Analysis

wordpress.org/plugins/stripe-tax-for-woocommerce

Stripe Tax for WooCommerce allows you to easily calculate and collect sales tax, VAT, and GST on WooCommerce orders.

20K active installs v2.0.0 PHP 7.4+ WP 6.3+ Updated Mar 3, 2026
shippingstripetaxtaxation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Stripe Tax – Sales tax automation for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Stripe Tax – Sales tax automation for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "stripe-tax-for-woocommerce" plugin v2.0.0 exhibits a mixed security posture. On the positive side, it demonstrates strong practices in data handling, with 100% of SQL queries using prepared statements and 99% of output correctly escaped. The absence of known CVEs and a clean vulnerability history suggest a generally well-maintained codebase. However, a significant concern arises from the presence of two AJAX handlers that lack any authentication checks. This creates a considerable attack surface, as these entry points could potentially be exploited by unauthenticated users to trigger unintended actions or access sensitive information if not properly secured within the handler's logic itself.

The code analysis indicates a low immediate risk for issues like SQL injection or cross-site scripting due to the robust prepared statement and escaping practices. The taint analysis reporting zero flows with unsanitized paths further reinforces this. However, the unprotected AJAX endpoints represent the most critical finding. While no specific vulnerabilities are currently documented, the lack of fundamental authentication on these handlers is a clear weakness that could be leveraged in conjunction with other potential flaws or by exploiting the specific functionality they expose. The plugin's strengths lie in its secure data handling, but its weakness is the exposed AJAX endpoints which require immediate attention.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

Stripe Tax – Sales tax automation for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Stripe Tax – Sales tax automation for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
50 prepared
Unescaped Output
5
343 escaped
Nonce Checks
28
Capability Checks
1
File Operations
2
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared50 total queries

Output Escaping

99% escaped348 total outputs
Attack Surface
2 unprotected

Stripe Tax – Sales tax automation for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_stripe_tax_for_woocommerce_test_connectionWordPress\class-hooks.php:206
authwp_ajax_stripe_tax_for_woocommerce_disconnect_from_stripeWordPress\class-hooks.php:215
WordPress Hooks 44
actionrest_dispatch_requestStripe\class-stripecalculationtracker.php:32
actionadmin_initStripe\class-stripecalculationtracker.php:47
actionplugins_loadedstripe-tax-for-woocommerce.php:70
actioninitstripe-tax-for-woocommerce.php:71
actionwoocommerce_after_settings_stripe_tax_for_woocommercetemplates\add-tax-registration.php:443
actionwoocommerce_after_settings_stripe_tax_for_woocommercetemplates\live-mode.php:265
filterwoocommerce_rate_labelWooCommerce\Hook_Handlers\class-order-tax-calculation.php:393
actionadmin_enqueue_scriptsWordPress\class-hooks.php:127
actionadmin_enqueue_scriptsWordPress\class-hooks.php:199
actionwoocommerce_admin_order_items_after_feesWordPress\class-hooks.php:225
actionwoocommerce_product_options_taxWordPress\class-hooks.php:332
actionadd_meta_boxesWordPress\class-hooks.php:347
actionwoocommerce_after_product_object_saveWordPress\class-hooks.php:373
actioninitWordPress\class-hooks.php:382
actionrest_dispatch_requestWordPress\class-hooks.php:383
actionwoocommerce_hydration_dispatch_requestWordPress\class-hooks.php:392
actionwoocommerce_hydration_request_after_callbacksWordPress\class-hooks.php:401
actionrest_request_after_callbacksWordPress\class-hooks.php:410
actionwoocommerce_order_partially_refundedWordPress\class-hooks.php:419
actionwoocommerce_order_fully_refundedWordPress\class-hooks.php:428
actionadmin_noticesWordPress\class-hooks.php:438
actionupdate_option_woocommerce_prices_include_taxWordPress\class-hooks.php:440
actionadmin_footerWordPress\class-hooks.php:454
actionadmin_footer-edit.phpWordPress\class-hooks.php:483
filterwoocommerce_order_type_to_groupWordPress\class-hooks.php:523
filterwoocommerce_get_order_item_classnameWordPress\class-hooks.php:533
filterwoocommerce_cart_hide_zero_taxesWordPress\class-hooks.php:542
filterwoocommerce_find_ratesWordPress\class-hooks.php:550
filterpre_option_wc_connect_taxes_enabledWordPress\class-hooks.php:559
filterwoocommerce_rest_prepare_shop_order_objectWordPress\class-hooks.php:560
filterwoocommerce_order_item_get_formatted_meta_dataWordPress\class-hooks.php:570
filterwoocommerce_get_sections_taxWordPress\class-hooks.php:594
filteroption_woocommerce_tax_based_onWordPress\class-hooks.php:603
filteroption_woocommerce_tax_round_at_subtotalWordPress\class-hooks.php:613
filterwoocommerce_tax_settingsWordPress\class-hooks.php:622
actionadmin_initWordPress\class-hooks.php:813
actionwoocommerce_system_status_reportWordPress\class-hooks.php:814
filterwoocommerce_get_settings_pagesWordPress\class-hooks.php:816
actionadmin_noticesWordPress\class-hooks.php:857
actionshow_user_profileWordPress\class-hooks.php:896
actionedit_user_profileWordPress\class-hooks.php:897
actionpersonal_options_updateWordPress\class-hooks.php:899
actionedit_user_profile_updateWordPress\class-hooks.php:900
actionaction_scheduler_initWordPress\class-stringtaxrateidfixerscheduledaction.php:39
Maintenance & Trust

Stripe Tax – Sales tax automation for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 3, 2026
PHP min version7.4
Downloads172K

Community Trust

Rating20/100
Number of ratings2
Active installs20K
Developer Profile

Stripe Tax – Sales tax automation for WooCommerce Developer Profile

Stripe Tax

1 plugin · 20K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Stripe Tax – Sales tax automation for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stripe-tax-for-woocommerce/assets/css/stripe_tax_for_woocommerce_admin.css
Script Paths
/wp-content/plugins/stripe-tax-for-woocommerce/assets/js/stripe_tax_for_woocommerce_checkout.js/wp-content/plugins/stripe-tax-for-woocommerce/assets/js/stripe_tax_for_woocommerce_admin.js
Version Parameters
stripe_tax_for_woocommerce/assets/css/stripe_tax_for_woocommerce_admin.css?ver=stripe_tax_for_woocommerce/assets/js/stripe_tax_for_woocommerce_checkout.js?ver=stripe_tax_for_woocommerce/assets/js/stripe_tax_for_woocommerce_admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
stripe-tax-for-woocommerce-admin-wrapstripe_tax_for_woocommerce_checkout_wrapper
Data Attributes
data-stripe_tax_for_woocommerce_checkout
JS Globals
StripeTaxForWooCommerce
REST Endpoints
/wp-json/stripe-tax-for-woocommerce/v1/save-stripe-account-settings/wp-json/stripe-tax-for-woocommerce/v1/get-stripe-account-settings/wp-json/stripe-tax-for-woocommerce/v1/delete-stripe-account-settings/wp-json/stripe-tax-for-woocommerce/v1/get-stripe-tax-settings/wp-json/stripe-tax-for-woocommerce/v1/update-stripe-tax-settings/wp-json/stripe-tax-for-woocommerce/v1/get-stripe-tax-tax-codes/wp-json/stripe-tax-for-woocommerce/v1/get-stripe-tax-tax-rates/wp-json/stripe-tax-for-woocommerce/v1/get-stripe-tax-registered-countries/wp-json/stripe-tax-for-woocommerce/v1/register-stripe-tax-country/wp-json/stripe-tax-for-woocommerce/v1/get-stripe-tax-product-taxability/wp-json/stripe-tax-for-woocommerce/v1/update-stripe-tax-product-taxability/wp-json/stripe-tax-for-woocommerce/v1/get-stripe-tax-exemptions/wp-json/stripe-tax-for-woocommerce/v1/update-stripe-tax-exemptions/wp-json/stripe-tax-for-woocommerce/v1/calculate-stripe-tax-checkout/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-save-checkout-calculation/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-get-checkout-calculation/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-delete-checkout-calculation/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-create-invoice/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-create-credit-memo/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-get-order-tax-details/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-get-order-tax-calculation-details/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-get-order-tax-calculation-reversal-details/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-get-tax-calculations/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-sync-product/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-sync-products/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-delete-product/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-create-tax-rate/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-delete-tax-rate/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-get-plugin-app-info/wp-json/stripe-tax-for-woocommerce/v1/stripe-tax-save-plugin-settings
FAQ

Frequently Asked Questions about Stripe Tax – Sales tax automation for WooCommerce