
Tips & Donations at WooCommerce Checkout Security & Risk Analysis
wordpress.org/plugins/tips-donations-at-checkoutThe plugin simply adds "Tips" field to your website's WooCommerce Checkout Form.
Is Tips & Donations at WooCommerce Checkout Safe to Use in 2026?
Generally Safe
Score 92/100Tips & Donations at WooCommerce Checkout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tips-donations-at-checkout" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The code demonstrates excellent security practices, including the exclusive use of prepared statements for SQL queries and proper output escaping for all identified outputs. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its safety. Furthermore, the plugin correctly implements a nonce check, a fundamental security mechanism for preventing CSRF attacks. The vulnerability history is also clean, with no recorded CVEs, indicating a history of secure development or timely patching.
While the static analysis reveals no immediate critical or high-severity vulnerabilities, a slight concern arises from the complete absence of capability checks. This means that while nonces might be present, the plugin doesn't explicitly verify if the logged-in user has the necessary permissions to execute its functionalities. This could potentially lead to authorization bypass issues if not handled implicitly by WordPress core or other plugins. However, given the other robust security measures in place and the limited attack surface (one shortcode), the overall risk is assessed as low. The strengths in SQL handling, output sanitization, and lack of known vulnerabilities far outweigh this single, potential weakness, especially for a plugin likely used in a controlled checkout environment.
Key Concerns
- Missing capability checks
Tips & Donations at WooCommerce Checkout Security Vulnerabilities
Tips & Donations at WooCommerce Checkout Code Analysis
Output Escaping
Data Flow Analysis
Tips & Donations at WooCommerce Checkout Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Tips & Donations at WooCommerce Checkout Maintenance & Trust
Maintenance Signals
Community Trust
Tips & Donations at WooCommerce Checkout Alternatives
Donation or Tip For WooCommerce
donation-or-tip-for-woocommerce
Add a customizable donation or tip field to your WooCommerce cart and checkout page. Support fixed amounts, percentage tips, and custom input — no cod …
Simple checkout page donations/tips for WooCommerce
simple-checkout-page-donationstips-for-woocommerce
This plugin lets you add custom tips for display in the checkout page. These tips are optional for the customer to add to the cart fee.
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
charitable
The best WordPress donation plugin. Create fundraising donation forms, accept recurring donations, easy donor management, add crowdfunding, and more.
Accept Donations with PayPal & Stripe
easy-paypal-donation
Add a PayPal or Stripe Donation Button to your website and start collecting donations today. No Coding Required. Official PayPal & Stripe Partner.
Tips & Donations at WooCommerce Checkout Developer Profile
5 plugins · 700 total installs
How We Detect Tips & Donations at WooCommerce Checkout
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tips-donations-at-checkout/wtd_front.phpHTML / DOM Fingerprints
gwtd_notice_butsselected="selected"<button class="gwtd_notice_buts" id="gwtd_notice_buts_