TT One-Page Checkout for WooCommerce Security & Risk Analysis

wordpress.org/plugins/tt-one-page-checkout-for-woocommerce

A WooCommerce plugin that allow user to combine WooCommmerce cart into the checkout page.

0 active installs v1.0.1 PHP + WP 3.0+ Updated Dec 4, 2022
discountsaleswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TT One-Page Checkout for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

TT One-Page Checkout for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the "tt-one-page-checkout-for-woocommerce" plugin version 1.0.1 exhibits a strong security posture. The code analysis reveals no dangerous functions, no direct SQL queries (all are prepared statements), and a high percentage of properly escaped output. Furthermore, there are no file operations or external HTTP requests, and the plugin implements a nonce check, indicating an effort to protect against common web vulnerabilities.

The lack of any recorded CVEs, both past and present, is a significant positive indicator. This suggests a history of responsible development and proactive security. The absence of critical or high-severity taint flows further reinforces the impression of well-sanitized code.

While the plugin demonstrates good security practices, the primary weakness identified is the absence of capability checks for the entry points. Although the attack surface is currently zero, if new entry points were introduced without proper authorization checks, they could pose a risk. Overall, this plugin appears to be secure for its current version, with a strong foundation of good coding practices and a clean vulnerability record.

Key Concerns

  • No capability checks found for entry points
Vulnerabilities
None known

TT One-Page Checkout for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

TT One-Page Checkout for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
37 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped40 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_page_one_page_checkout (wc-one-page-checkout.php:208)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

TT One-Page Checkout for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionwoocommerce_initwc-one-page-checkout.php:76
actionadmin_menuwc-one-page-checkout.php:85
actionadmin_enqueue_scriptswc-one-page-checkout.php:87
actionwoocommerce_before_checkout_formwc-one-page-checkout.php:92
actionwoocommerce_after_checkout_formwc-one-page-checkout.php:94
filterwoocommerce_loop_add_to_cart_linkwc-one-page-checkout.php:98
filterwoocommerce_product_single_add_to_cart_textwc-one-page-checkout.php:99
filterwoocommerce_order_button_textwc-one-page-checkout.php:103
filterwoocommerce_checkout_fieldswc-one-page-checkout.php:107
filterwoocommerce_add_to_cart_redirectwc-one-page-checkout.php:110
actiontemplate_redirectwc-one-page-checkout.php:112
filterwc_add_to_cart_message_htmlwc-one-page-checkout.php:114
filterwoocommerce_add_to_cart_sold_individually_found_in_cartwc-one-page-checkout.php:116
actionadmin_noticeswc-one-page-checkout.php:517
Maintenance & Trust

TT One-Page Checkout for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 4, 2022
PHP min version
Downloads727

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TT One-Page Checkout for WooCommerce Developer Profile

terrytsang

8 plugins · 1K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TT One-Page Checkout for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tt-one-page-checkout-for-woocommerce/assets/css/admin.css/wp-content/plugins/tt-one-page-checkout-for-woocommerce/assets/js/script.js/wp-content/plugins/tt-one-page-checkout-for-woocommerce/lib/chosen/js/chosen.jquery.js/wp-content/plugins/tt-one-page-checkout-for-woocommerce/assets/css/jquery-ui.css
Script Paths
/wp-content/plugins/tt-one-page-checkout-for-woocommerce/assets/js/script.js/wp-content/plugins/tt-one-page-checkout-for-woocommerce/lib/chosen/js/chosen.jquery.js
Version Parameters
tt-one-page-checkout-for-woocommerce/assets/css/admin.css?ver=tt-one-page-checkout-for-woocommerce/assets/js/script.js?ver=tt-one-page-checkout-for-woocommerce/lib/chosen/js/chosen.jquery.js?ver=tt-one-page-checkout-for-woocommerce/assets/css/jquery-ui.css?ver=

HTML / DOM Fingerprints

HTML Comments
Copyright 2012-2022 Terry Tsang (email: terrytsang811@gmail.com)This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version.This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
JS Globals
wc_one_page_checkout_wc_version_one_page_checkout
Shortcode Output
[woocommerce_cart]
FAQ

Frequently Asked Questions about TT One-Page Checkout for WooCommerce