
WooBooster Partial COD for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wb-partial-cod-for-woocommerceBest Wordpress plugin to Allows you to take partial payment via Cash on Delivery (COD) in WooCommerce.
Is WooBooster Partial COD for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100WooBooster Partial COD for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wb-partial-cod-for-woocommerce" v2.2 exhibits a generally positive security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are significant strengths, suggesting a developer mindful of security best practices. The code doesn't utilize dangerous functions or perform file operations, and all SQL queries are properly prepared, mitigating common web application vulnerabilities. The limited attack surface, with only two AJAX handlers and no REST API routes or shortcodes, is also a positive sign. However, there are areas for concern. The plugin performs external HTTP requests, which could be a vector for issues if not handled securely. Furthermore, while there's a nonce check on one AJAX handler, capability checks are entirely absent, meaning that the AJAX endpoints are potentially accessible to users without the necessary permissions to perform their intended actions. The output escaping, while at 75%, still leaves a quarter of outputs unescaped, which could lead to cross-site scripting (XSS) vulnerabilities if sensitive data is handled without proper sanitization.
While the plugin demonstrates good practices in areas like SQL sanitization and limited attack surface, the lack of capability checks on AJAX endpoints and the unescaped outputs present notable risks. The external HTTP requests, though not inherently a vulnerability, warrant careful scrutiny for how they are implemented and what data they handle. The strong historical record of no vulnerabilities is reassuring, but it does not negate the potential for issues in the current version. Overall, the plugin is in a reasonably secure state, but these specific areas require attention to further harden its security.
Key Concerns
- AJAX handlers without capability checks
- Unescaped output (25% of total outputs)
- External HTTP requests
WooBooster Partial COD for WooCommerce Security Vulnerabilities
WooBooster Partial COD for WooCommerce Code Analysis
Output Escaping
WooBooster Partial COD for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 25
Maintenance & Trust
WooBooster Partial COD for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WooBooster Partial COD for WooCommerce Alternatives
WooBooster Partial COD for WooCommerce Developer Profile
2 plugins · 420 total installs
How We Detect WooBooster Partial COD for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wb-partial-cod-for-woocommerce/css/woobooster_partial_cod_style.css/wp-content/plugins/wb-partial-cod-for-woocommerce/js/partial-cod.js/wp-content/plugins/wb-partial-cod-for-woocommerce/js/partial-cod.jswb-partial-cod-for-woocommerce/css/woobooster_partial_cod_style.css?ver=wb-partial-cod-for-woocommerce/js/partial-cod.js?ver=HTML / DOM Fingerprints
restrict_partial_codonly_partial_codpartial_cod_params