Buy Now Woocommerce Security & Risk Analysis

wordpress.org/plugins/vmi-direct-checkout

Buy Now woocommerce is a helpful tool to simplify the checkout process. Buy Now woocommerce converts into a one-click process, customer decision to sa …

10 active installs v3.0.3 PHP 7.3+ WP 6.0+ Updated Sep 19, 2023
add-to-cart-removebuy-now-woocommerceeasy-checkoutwoocommercewoocommerce-direct-checkout
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Buy Now Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Buy Now Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of vmi-direct-checkout v3.0.3 indicates a generally strong security posture. The plugin exhibits zero direct entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication. Furthermore, there are no identified dangerous functions, file operations, or external HTTP requests, and all SQL queries are using prepared statements. The presence of nonce checks is also a positive sign. However, a concerning aspect is the low percentage of properly escaped output (33%), which could lead to cross-site scripting vulnerabilities if user-supplied data is not handled carefully. The absence of capability checks on any potential entry points (though there are none identified) is also a point of consideration for future development.

The plugin's vulnerability history is clean, with zero known CVEs. This, combined with the absence of critical or high-severity issues in the static and taint analysis, suggests that this version is likely secure against known threats. The lack of significant findings in taint analysis further supports this. While the clean history is a significant strength, the identified output escaping issue remains a potential weakness that could be exploited if additional, undocumented entry points were discovered or if the plugin's functionality were to expand in the future without adequate security considerations. Overall, vmi-direct-checkout v3.0.3 appears to be a well-coded plugin with a robust security foundation, but a minor weakness in output sanitization warrants attention.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Buy Now Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Buy Now Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
vmi_admin_page_contents (wc-direct-checkout-vmi.php:152)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Buy Now Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_headwc-direct-checkout-vmi.php:18
actionadmin_initwc-direct-checkout-vmi.php:64
actioninitwc-direct-checkout-vmi.php:116
actionwoocommerce_single_product_summarywc-direct-checkout-vmi.php:122
actionadmin_menuwc-direct-checkout-vmi.php:149
Maintenance & Trust

Buy Now Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedSep 19, 2023
PHP min version7.3
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Buy Now Woocommerce Developer Profile

Sharjeel Khan

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Buy Now Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vmi-direct-checkout/assets/css/style.css/wp-content/plugins/vmi-direct-checkout/assets/js/script.js

HTML / DOM Fingerprints

CSS Classes
vmi_single_add_to_cart_buttonvmi_buttonvmi_altvmi_custom-checkout-btnnametext-plugininput-color-containerinput-plugininput-color+3 more
Data Attributes
id="vmiDirectCheckoutBtn"
FAQ

Frequently Asked Questions about Buy Now Woocommerce