VAT / UST ID Checker – Validator EU for WooCommerce Security & Risk Analysis

wordpress.org/plugins/vat-ust-id-checker-validator-eu-for-woocommerce

Just a small plugin that allows you to apply reverse charge (Europe) in WooCommerce.

10 active installs v1.0.0 PHP 5.2.4+ WP 4.0+ Updated Oct 7, 2020
reverse-chargeustidvalidatorvatwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is VAT / UST ID Checker – Validator EU for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

VAT / UST ID Checker – Validator EU for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "vat-ust-id-checker-validator-eu-for-woocommerce" plugin, at version 1.0.0, exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerability history, significant concerns arise from its attack surface and lack of authorization checks. The presence of two AJAX handlers, both entirely unprotected by authentication, presents a direct avenue for attackers to interact with the plugin's functionality without prior validation. This lack of access control on entry points is a critical weakness.

Despite the absence of taint analysis findings and a clean vulnerability history, the unprotected AJAX handlers represent a substantial risk. The plugin's static analysis reveals that 50% of its output is not properly escaped, which, when combined with unprotected entry points, could lead to cross-site scripting (XSS) vulnerabilities if attacker-controlled data is reflected in the output without proper sanitization. The plugin's total lack of nonce checks further exacerbates this risk, as it provides no mechanism to verify the legitimacy of incoming requests to these AJAX endpoints.

In conclusion, while the plugin's foundational code appears robust in areas like SQL handling and the absence of known vulnerabilities, the unprotected AJAX handlers and insufficient output escaping create a clear and present danger. The plugin has the potential for serious security flaws that could be exploited by unauthenticated users. Addressing the unprotected entry points and ensuring proper output escaping are paramount for improving its security.

Key Concerns

  • AJAX handlers without auth checks
  • Unescaped output (50% of 14)
  • No nonce checks on AJAX
Vulnerabilities
None known

VAT / UST ID Checker – Validator EU for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

VAT / UST ID Checker – Validator EU for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped14 total outputs
Attack Surface
2 unprotected

VAT / UST ID Checker – Validator EU for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_ctviwoo_update_sessioncheck-tax-vat-id-woo.php:122
noprivwp_ajax_ctviwoo_update_sessioncheck-tax-vat-id-woo.php:123
WordPress Hooks 10
actionwpi_after_formatted_billing_addresscheck-tax-vat-id-woo.php:47
actionwoocommerce_admin_order_data_after_billing_addresscheck-tax-vat-id-woo.php:49
actionwoocommerce_after_order_notescheck-tax-vat-id-woo.php:115
actionwoocommerce_checkout_update_order_reviewcheck-tax-vat-id-woo.php:116
actionwp_enqueue_scriptscheck-tax-vat-id-woo.php:117
actionwoocommerce_thankyoucheck-tax-vat-id-woo.php:118
actionwoocommerce_checkout_update_user_metacheck-tax-vat-id-woo.php:119
actionwoocommerce_checkout_update_order_metacheck-tax-vat-id-woo.php:120
actionwp_footercheck-tax-vat-id-woo.php:121
actionwoocommerce_before_checkout_billing_formcheck-tax-vat-id-woo.php:124
Maintenance & Trust

VAT / UST ID Checker – Validator EU for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 7, 2020
PHP min version5.2.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

VAT / UST ID Checker – Validator EU for WooCommerce Developer Profile

mlfactory

7 plugins · 21K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
318 days
View full developer profile
Detection Fingerprints

How We Detect VAT / UST ID Checker – Validator EU for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vat-ust-id-checker-validator-eu-for-woocommerce/assets/css/custom.css/wp-content/plugins/vat-ust-id-checker-validator-eu-for-woocommerce/assets/js/custom.js
Script Paths
/wp-content/plugins/vat-ust-id-checker-validator-eu-for-woocommerce/assets/js/custom.js
Version Parameters
/wp-content/plugins/vat-ust-id-checker-validator-eu-for-woocommerce/assets/css/custom.css?ver=/wp-content/plugins/vat-ust-id-checker-validator-eu-for-woocommerce/assets/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
ctvidwoo_private_companyctviwoo_checkout_fieldsctviwoo_ust_wrapper
Data Attributes
name="ctviwoo_corp"name="ctviwoo_ust_input"
JS Globals
ctviwoo_update_session
FAQ

Frequently Asked Questions about VAT / UST ID Checker – Validator EU for WooCommerce