Tips & Donations at WooCommerce Checkout Security & Risk Analysis

wordpress.org/plugins/tips-donations-at-checkout

The plugin simply adds "Tips" field to your website's WooCommerce Checkout Form.

10 active installs v1.0.0 PHP + WP 5.0.0+ Updated Dec 3, 2024
checkout-fielddonatedonationtipwoocommerce-tip
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tips & Donations at WooCommerce Checkout Safe to Use in 2026?

Generally Safe

Score 92/100

Tips & Donations at WooCommerce Checkout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "tips-donations-at-checkout" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The code demonstrates excellent security practices, including the exclusive use of prepared statements for SQL queries and proper output escaping for all identified outputs. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its safety. Furthermore, the plugin correctly implements a nonce check, a fundamental security mechanism for preventing CSRF attacks. The vulnerability history is also clean, with no recorded CVEs, indicating a history of secure development or timely patching.

While the static analysis reveals no immediate critical or high-severity vulnerabilities, a slight concern arises from the complete absence of capability checks. This means that while nonces might be present, the plugin doesn't explicitly verify if the logged-in user has the necessary permissions to execute its functionalities. This could potentially lead to authorization bypass issues if not handled implicitly by WordPress core or other plugins. However, given the other robust security measures in place and the limited attack surface (one shortcode), the overall risk is assessed as low. The strengths in SQL handling, output sanitization, and lack of known vulnerabilities far outweigh this single, potential weakness, especially for a plugin likely used in a controlled checkout environment.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

Tips & Donations at WooCommerce Checkout Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Tips & Donations at WooCommerce Checkout Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
34 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped34 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<wtd_admin> (wtd_admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Tips & Donations at WooCommerce Checkout Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[gdym_didyoumean] tips-donations-at-checkout.php:19
WordPress Hooks 4
actionadmin_menutips-donations-at-checkout.php:20
actionwoocommerce_cart_calculate_feestips-donations-at-checkout.php:23
actionwp_footertips-donations-at-checkout.php:65
actionwoocommerce_before_checkout_formtips-donations-at-checkout.php:94
Maintenance & Trust

Tips & Donations at WooCommerce Checkout Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 3, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Tips & Donations at WooCommerce Checkout Developer Profile

Guaven Labs

5 plugins · 700 total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
329 days
View full developer profile
Detection Fingerprints

How We Detect Tips & Donations at WooCommerce Checkout

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tips-donations-at-checkout/wtd_front.php

HTML / DOM Fingerprints

CSS Classes
gwtd_notice_buts
Data Attributes
selected="selected"
Shortcode Output
<button class="gwtd_notice_buts" id="gwtd_notice_buts_
FAQ

Frequently Asked Questions about Tips & Donations at WooCommerce Checkout