
VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce Security & Risk Analysis
wordpress.org/plugins/vaocher-appSell your own gift cards, gift vouchers and gift certificates from your WordPress website (WooCommerce compatible) easily in just a few minutes
Is VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "vaocher-app" v1.1.0 plugin exhibits a mixed security posture. On one hand, the plugin demonstrates good practices by having no recorded vulnerabilities in its history and a seemingly limited attack surface with zero identified AJAX handlers, REST API routes, or shortcodes that lack authentication checks. All SQL queries are also performed using prepared statements, which is a significant strength.
However, there are notable concerns. The static analysis reveals that only 21% of outputs are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis identified two flows with unsanitized paths, which, while not classified as critical or high severity in this specific analysis, represent potential injection vectors that could be exploited if coupled with insufficient input validation or improper handling. The absence of nonce checks across any entry points is also a significant security gap, as it allows for Cross-Site Request Forgery (CSRF) attacks.
Given the lack of historical vulnerabilities, it might suggest diligent patching or a lower likelihood of past exploits. However, the current static analysis flags potential weaknesses, particularly in output escaping and unsanitized path flows, which could be exploited by attackers. The absence of nonce checks is a fundamental security flaw that should be addressed.
Key Concerns
- Low output escaping (21%)
- Unsanitized paths in taint flows (2)
- No nonce checks on entry points
- File operations detected
- External HTTP requests detected
VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce Security Vulnerabilities
VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce Attack Surface
WordPress Hooks 16
Maintenance & Trust
VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce Alternatives
Ultimate Gift Cards for WooCommerce
woo-gift-cards-lite
Create, sell and manage WooCommerce gift cards to attract more sales and multiply your revenue at your online store.
Gift Up Gift Cards for WordPress and WooCommerce
gift-up
The simplest way to sell gift cards online. Sell your own gift cards, gift certificates and gift vouchers from inside your WordPress website easily wi …
Store credit / Gift cards for woocommerce
store-credit-for-woocommerce
Offer store credit or gift cards to customers that they can use until their credit is finished
Wyseme Gift Cards for WooCommerce by Saara INC – Create Gift card for https://wyse.me/ platform.
wyseme-giftcard-by-saara
This plugin is made for specifically for the merchant those are using https://wyse.me/ platform. This plugin should not be consider as a general giftc …
PW WooCommerce Gift Cards
pw-woocommerce-gift-cards
Sell gift cards to your WooCommerce store, in just a few minutes!
VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce Developer Profile
1 plugin · 40 total installs
How We Detect VaocherApp – Gift cards/vouchers system for WordPress & WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vaocher-app/assets/js/main.js/wp-content/plugins/vaocher-app/assets/css/main.cssassets/js/main.jsvaocher-app/assets/js/main.js?ver=vaocher-app/assets/css/main.css?ver=HTML / DOM Fingerprints
data-vaocherappVaocherApp/wp-json/vaocher-app[vaocher_app_buy_button][vaocher_app_redeem_form]