WooBooster Partial COD for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wb-partial-cod-for-woocommerce

Best Wordpress plugin to Allows you to take partial payment via Cash on Delivery (COD) in WooCommerce.

400 active installs v2.2 PHP + WP + Updated Sep 3, 2025
partial-cash-on-deliverypartial-codwoobooster-partial-codwoocommerce-partial-codwp-partial-cod
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WooBooster Partial COD for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

WooBooster Partial COD for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The plugin "wb-partial-cod-for-woocommerce" v2.2 exhibits a generally positive security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are significant strengths, suggesting a developer mindful of security best practices. The code doesn't utilize dangerous functions or perform file operations, and all SQL queries are properly prepared, mitigating common web application vulnerabilities. The limited attack surface, with only two AJAX handlers and no REST API routes or shortcodes, is also a positive sign. However, there are areas for concern. The plugin performs external HTTP requests, which could be a vector for issues if not handled securely. Furthermore, while there's a nonce check on one AJAX handler, capability checks are entirely absent, meaning that the AJAX endpoints are potentially accessible to users without the necessary permissions to perform their intended actions. The output escaping, while at 75%, still leaves a quarter of outputs unescaped, which could lead to cross-site scripting (XSS) vulnerabilities if sensitive data is handled without proper sanitization.

While the plugin demonstrates good practices in areas like SQL sanitization and limited attack surface, the lack of capability checks on AJAX endpoints and the unescaped outputs present notable risks. The external HTTP requests, though not inherently a vulnerability, warrant careful scrutiny for how they are implemented and what data they handle. The strong historical record of no vulnerabilities is reassuring, but it does not negate the potential for issues in the current version. Overall, the plugin is in a reasonably secure state, but these specific areas require attention to further harden its security.

Key Concerns

  • AJAX handlers without capability checks
  • Unescaped output (25% of total outputs)
  • External HTTP requests
Vulnerabilities
None known

WooBooster Partial COD for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WooBooster Partial COD for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
55 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

75% escaped73 total outputs
Attack Surface

WooBooster Partial COD for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_update_partial_paymentwoobooster-partial-cod.php:706
noprivwp_ajax_update_partial_paymentwoobooster-partial-cod.php:707
WordPress Hooks 25
filterwoocommerce_order_shipping_to_display_shipped_viatemplates\emails\email-order-details.php:30
actionadmin_enqueue_scriptswoobooster-partial-cod.php:99
actionwp_enqueue_scriptswoobooster-partial-cod.php:111
filterwoocommerce_register_shop_order_post_statuseswoobooster-partial-cod.php:130
filterwc_order_statuseswoobooster-partial-cod.php:131
actionwoocommerce_coupon_options_usage_restrictionwoobooster-partial-cod.php:157
actionwoocommerce_coupon_options_savewoobooster-partial-cod.php:180
filterwoocommerce_coupon_is_validwoobooster-partial-cod.php:188
filterwoocommerce_settings_tabs_arraywoobooster-partial-cod.php:231
actionwoocommerce_settings_tabs_partial_codwoobooster-partial-cod.php:237
actionwoocommerce_update_options_partial_codwoobooster-partial-cod.php:242
actionwoocommerce_review_order_before_paymentwoobooster-partial-cod.php:350
filterwoocommerce_available_payment_gatewayswoobooster-partial-cod.php:376
actionwoocommerce_checkout_create_orderwoobooster-partial-cod.php:389
actionwoocommerce_checkout_order_processedwoobooster-partial-cod.php:427
actionwoocommerce_cart_calculate_feeswoobooster-partial-cod.php:465
actionwoocommerce_order_details_after_order_tablewoobooster-partial-cod.php:513
actionwoocommerce_review_order_after_order_totalwoobooster-partial-cod.php:551
filterwoocommerce_order_get_totalwoobooster-partial-cod.php:635
actionwoocommerce_email_after_order_tablewoobooster-partial-cod.php:649
filterwoocommerce_order_needs_shipping_addresswoobooster-partial-cod.php:664
actionwoocommerce_admin_order_totals_after_totalwoobooster-partial-cod.php:675
actionwoocommerce_thankyouwoobooster-partial-cod.php:721
filterwoocommerce_locate_templatewoobooster-partial-cod.php:755
actionadmin_menuwoobooster-partial-cod.php:767
Maintenance & Trust

WooBooster Partial COD for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 3, 2025
PHP min version
Downloads5K

Community Trust

Rating94/100
Number of ratings6
Active installs400
Developer Profile

WooBooster Partial COD for WooCommerce Developer Profile

WooBooster

2 plugins · 420 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WooBooster Partial COD for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wb-partial-cod-for-woocommerce/css/woobooster_partial_cod_style.css/wp-content/plugins/wb-partial-cod-for-woocommerce/js/partial-cod.js
Script Paths
/wp-content/plugins/wb-partial-cod-for-woocommerce/js/partial-cod.js
Version Parameters
wb-partial-cod-for-woocommerce/css/woobooster_partial_cod_style.css?ver=wb-partial-cod-for-woocommerce/js/partial-cod.js?ver=

HTML / DOM Fingerprints

Data Attributes
restrict_partial_codonly_partial_cod
JS Globals
partial_cod_params
FAQ

Frequently Asked Questions about WooBooster Partial COD for WooCommerce