
Tax Switch for WooCommerce Security & Risk Analysis
wordpress.org/plugins/tax-switch-for-woocommerceLet customers toggle between inclusive and exclusive VAT pricing in your WooCommerce store.
Is Tax Switch for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Tax Switch for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "tax-switch-for-woocommerce" plugin version 1.6.11 demonstrates generally good security practices with a clean static analysis report. The absence of dangerous functions, file operations, and external HTTP requests, along with the use of prepared statements for all SQL queries and a high percentage of properly escaped output, are positive indicators. The presence of a nonce check is also a good sign. However, the lack of capability checks on entry points, while not explicitly flagged as a vulnerability in this analysis, is a potential area for improvement, as it relies solely on nonce checks for authentication. The vulnerability history shows one past CVE, specifically a cross-site scripting vulnerability, which has since been patched. The fact that there are no currently unpatched vulnerabilities is reassuring. The medium severity of the past vulnerability suggests that while the plugin has had issues, they have been addressed. Overall, the plugin appears to be in a decent security state, but ongoing vigilance regarding capability checks and prompt patching of any future vulnerabilities is recommended.
Key Concerns
- No capability checks on entry points
- Past medium severity XSS vulnerability
Tax Switch for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Tax Switch for WooCommerce <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via class-name Parameter
Tax Switch for WooCommerce Code Analysis
Output Escaping
Tax Switch for WooCommerce Attack Surface
Shortcodes 2
WordPress Hooks 39
Maintenance & Trust
Tax Switch for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Tax Switch for WooCommerce Alternatives
WooCommerce Tax (formerly WooCommerce Shipping & Tax)
woocommerce-services
We’re here to help with tax rates: collect accurate sales tax, automatically.
EU VAT Assistant for WooCommerce
woocommerce-eu-vat-assistant
Extends the standard WooCommerce sale process and assists in achieving compliance with the new EU VAT regime starting on the 1st of January 2015.
Tax Exemption for WooCommerce
tax-exemption-woo
Tax Exemption plugin for WooCommerce. Allow customers to declare tax / VAT exemption eligibility, and provide tax exemption details.
RD Order Modifier for WooCommerce
rd-wc-order-modifier
Allows editing order items pricing inclusive of tax or VAT and using unit cost instead of items totals.
Rename VAT to GST for WooCommerce
rename-vat-to-gst-for-woocommerce
Replaces VAT and Tax terminology with GST throughout WooCommerce (emails, cart, checkout, admin, order pages).
Tax Switch for WooCommerce Developer Profile
3 plugins · 1K total installs
How We Detect Tax Switch for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tax-switch-for-woocommerce/admin/js/wdevs-tax-switch-woocommerce.js/wp-content/plugins/tax-switch-for-woocommerce/includes/assets/css/wdevs-tax-switch-shared.css/wp-content/plugins/tax-switch-for-woocommerce/admin/js/wdevs-tax-switch-woocommerce.jstax-switch-for-woocommerce/admin/js/wdevs-tax-switch-woocommerce.js?ver=tax-switch-for-woocommerce/includes/assets/css/wdevs-tax-switch-shared.css?ver=HTML / DOM Fingerprints
wdevs-tax-switch-container<!-- Plugin Name: Tax Switch for WooCommerce -->data-original-tax-displaydata-check-price-elementswtsEditorObjectwtsAjaxObject[wdevs_tax_switch]