Cash On Pickup for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-cash-on-pickup

Have your customers pay with cash on pickup

8K active installs v1.7.1 PHP + WP 3.5+ Updated Nov 10, 2025
cashgatewaypaymentpickupwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cash On Pickup for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Cash On Pickup for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "wc-cash-on-pickup" v1.7.1 plugin exhibits a strong security posture. The analysis reveals no identified attack surface points that are unprotected, and all code signals indicate adherence to secure coding practices. Specifically, there are no dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations and external HTTP requests further minimizes potential vulnerabilities. Taint analysis shows no issues with unsanitized paths, reinforcing the lack of critical or high-severity vulnerabilities in the code itself.

The plugin's vulnerability history is equally clean, with zero known CVEs recorded. This indicates a proactive approach to security or a lack of past exploitation, which is a positive sign. The complete absence of any recorded vulnerabilities, regardless of severity, suggests that the plugin has either been very well-maintained or has not presented an attractive target for attackers.

In conclusion, "wc-cash-on-pickup" v1.7.1 appears to be a secure plugin. Its strengths lie in its minimal attack surface, adherence to secure coding standards for SQL and output handling, and a clean vulnerability history. There are no immediate or apparent weaknesses identified in the provided data. However, it is important to remember that security is an ongoing process, and even secure plugins can benefit from regular updates and monitoring.

Vulnerabilities
None known

Cash On Pickup for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cash On Pickup for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

Cash On Pickup for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwoocommerce_email_before_order_tableclasses\class.wc-cop.php:101
filterwoocommerce_available_payment_gatewaysclasses\class.wc-cop.php:107
actionplugins_loadedwc-cash-on-pickup.php:53
filterwoocommerce_payment_gatewayswc-cash-on-pickup.php:64
filterplugin_action_linkswc-cash-on-pickup.php:83
actionbefore_woocommerce_initwc-cash-on-pickup.php:88
Maintenance & Trust

Cash On Pickup for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 10, 2025
PHP min version
Downloads72K

Community Trust

Rating100/100
Number of ratings19
Active installs8K
Developer Profile

Cash On Pickup for WooCommerce Developer Profile

Marian Kadanka

3 plugins · 8K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cash On Pickup for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-cash-on-pickup/assets/css/style.css/wp-content/plugins/wc-cash-on-pickup/assets/js/script.js
Script Paths
/wp-content/plugins/wc-cash-on-pickup/assets/js/script.js
Version Parameters
wc-cash-on-pickup/assets/css/style.css?ver=wc-cash-on-pickup/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wc-cop-checkout-field
HTML Comments
<!-- Cash On Pickup for WooCommerce --><!-- Payment method is Cash on Pickup -->
Data Attributes
data-cop-message
JS Globals
wc_cop_params
FAQ

Frequently Asked Questions about Cash On Pickup for WooCommerce