
TaxDo Security & Risk Analysis
wordpress.org/plugins/taxdoA unique solution for managing sales tax calculation & tax exemption certificates.
Is TaxDo Safe to Use in 2026?
Generally Safe
Score 100/100TaxDo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The taxdo plugin v2.3.10 exhibits a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling by exclusively using prepared statements and largely implements proper output escaping, with 96% of identified outputs being sanitized. The absence of known CVEs and a clean vulnerability history suggests a degree of diligence in addressing past security issues. However, significant concerns arise from the static analysis. The plugin exposes two REST API routes that lack any permission callbacks, creating a direct attack surface for unauthorized actions or information disclosure. This, combined with zero capability checks, indicates a lack of robust authorization mechanisms for critical entry points.
While the taint analysis shows no flows with unsanitized paths, the presence of unprotected REST API routes is a critical oversight. The absence of capability checks on these routes means any unauthenticated user could potentially interact with them, leading to unintended consequences. The plugin also performs external HTTP requests, which, while not inherently insecure, can become a vector if the target endpoints are compromised or if the data sent is not properly validated. The limited number of entry points is a strength, but the unprotected nature of these points negates much of that advantage.
In conclusion, the taxdo plugin's strengths lie in its SQL hygiene and output sanitization. Nevertheless, the presence of unprotected REST API routes represents a significant security weakness that requires immediate attention. The absence of capability checks on these endpoints is a critical concern, potentially exposing the site to unauthorized access and manipulation. Until these entry points are properly secured, the plugin carries a notable risk.
Key Concerns
- REST API routes without permission callbacks
- No capability checks
- External HTTP requests (potential risk)
- Minor unescaped output (4% of total)
TaxDo Security Vulnerabilities
TaxDo Code Analysis
SQL Query Safety
Output Escaping
TaxDo Attack Surface
REST API Routes 2
WordPress Hooks 3
Maintenance & Trust
TaxDo Maintenance & Trust
Maintenance Signals
Community Trust
TaxDo Alternatives
TaxJar – Sales Tax Automation for WooCommerce
taxjar-simplified-taxes-for-woocommerce
Trusted by more than 20,000 businesses, TaxJar’s award-winning solution makes it easy to automate sales tax reporting and filing, and determine econom …
SutTax
avior-sales-tax-automation-for-woocommerce
Avior SutTax offers sales tax determination web service to retailers. With SutTax WooCommerce Plugin, retailers are able to add accurate sales tax to …
Sales Tax Reports For WooCommerce
sales-tax-reports-for-woocommerce
The Sales Tax Reports For WooCommerce Plugin
TaxCloud for WooCommerce
simple-sales-tax
Simplify sales tax calculations, reporting, and filing by connecting your WooCommerce store to TaxCloud.
CereTax
ceretax
Simplify sales tax complexity with CereTax for WooCommerce.
TaxDo Developer Profile
1 plugin · 0 total installs
How We Detect TaxDo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/taxdo/build/apply-certificate/frontend.js/wp-content/plugins/taxdo/build/apply-certificate/index.js/wp-content/plugins/taxdo/build/apply-certificate/style-index.css/wp-content/plugins/taxdo/build/index.js/wp-content/plugins/taxdo/build/show-sub-tax-class/frontend.js/wp-content/plugins/taxdo/build/show-sub-tax-class/index.js/wp-content/plugins/taxdo/build/show-sub-tax-class/style-index.css/wp-content/plugins/taxdo/build/apply-certificate/frontend.js/wp-content/plugins/taxdo/build/apply-certificate/index.js/wp-content/plugins/taxdo/build/index.js/wp-content/plugins/taxdo/build/show-sub-tax-class/frontend.js/wp-content/plugins/taxdo/build/show-sub-tax-class/index.jstaxdo/build/apply-certificate/frontend.js?ver=taxdo/build/apply-certificate/index.js?ver=taxdo/build/apply-certificate/style-index.css?ver=taxdo/build/index.js?ver=taxdo/build/show-sub-tax-class/frontend.js?ver=taxdo/build/show-sub-tax-class/index.js?ver=taxdo/build/show-sub-tax-class/style-index.css?ver=HTML / DOM Fingerprints
taxdo-apply-certificatetaxdo-show-sub-tax-classwindow.wc_taxdo_apply_certificate_paramswindow.wc_taxdo_show_sub_tax_class_params