Checkout with Cash App on WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-cashapp

The #1 finance app in the App Store now available on WordPress. Receive Cash App payments on your website with WooCommerce + Cash App

2K active installs v6.1.1 PHP 5.0+ WP 5.0+ Updated Jan 28, 2026
cash-appcashapppaymentssquarewoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 22, 2024
Safety Verdict

Is Checkout with Cash App on WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Checkout with Cash App on WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 22, 2024Updated 2mo ago
Risk Assessment

The wc-cashapp plugin version 6.1.1 presents a mixed security profile. On the positive side, it demonstrates good practices in handling SQL queries, utilizing prepared statements for all identified queries, and a high percentage of properly escaped output. The plugin also incorporates nonce checks and capability checks, which are essential for secure WordPress development. The attack surface appears limited, with no immediately obvious unprotected entry points like unauthenticated AJAX handlers or REST API routes.

However, there are areas of concern. The presence of one unsanitized path in the taint analysis is a significant risk, even if no critical or high severity issues were reported. This could potentially lead to vulnerabilities if the path is user-controlled. Furthermore, the plugin relies on a bundled library, Freemius v1.0, which may be outdated and could introduce its own security risks if not kept up-to-date. The history of a medium severity Cross-Site Scripting vulnerability, though recently patched, indicates a past weakness in input neutralization that warrants continued vigilance.

Overall, while the plugin shows strengths in core security implementation like prepared statements and output escaping, the unsanitized taint flow and the potential for issues with bundled libraries are notable weaknesses. The past XSS vulnerability also suggests that the developers should maintain a rigorous approach to security testing and patching.

Key Concerns

  • Flows with unsanitized paths
  • Bundled Freemius v1.0 library
  • Past medium severity XSS vulnerability
Vulnerabilities
1

Checkout with Cash App on WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-9635medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Checkout with Cash App on WooCommerce <= 6.0.2 - Reflected Cross-Site Scripting

Nov 22, 2024 Patched in 6.0.3 (1d)
Code Analysis
Analyzed Mar 16, 2026

Checkout with Cash App on WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
22
189 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
11
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared2 total queries

Output Escaping

90% escaped211 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
<square-redirect> (includes\admin\square-redirect.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Checkout with Cash App on WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 32
filterconnect_urlcashapp.php:95
filterafter_skip_urlcashapp.php:96
filterafter_connect_urlcashapp.php:97
filterafter_pending_connect_urlcashapp.php:98
actionadmin_enqueue_scriptscashapp.php:112
filterwoocommerce_payment_gatewayscashapp.php:127
actionbefore_woocommerce_initcashapp.php:134
actionplugins_loadedcashapp.php:141
actioninitcashapp.php:143
actionadmin_menuincludes\admin\dashboard.php:127
actionadmin_menuincludes\admin\dashboard.php:270
actionwp_enqueue_scriptsincludes\class-wc_cashapp_gateway.php:295
actionwoocommerce_checkout_order_processedincludes\class-wc_cashapp_gateway.php:298
actionwoocommerce_email_order_detailsincludes\class-wc_cashapp_gateway.php:305
actionwoocommerce_blocks_loadedincludes\class-wc_cashapp_gateway.php:312
actionwoocommerce_cancel_unpaid_ordersincludes\class-wc_cashapp_gateway.php:314
actionwoocommerce_blocks_payment_method_type_registrationincludes\class-wc_cashapp_gateway.php:320
actionadmin_post_save_live_square_envincludes\class-wc_cashapp_square.php:7
actionadmin_post_revoke_square_tokenincludes\class-wc_cashapp_square.php:8
actionadmin_post_refresh_square_tokenincludes\class-wc_cashapp_square.php:9
actionwc_cashapp_square_renewal_token_cron_hookincludes\class-wc_cashapp_square.php:10
actioninitincludes\class-wc_cashapp_update_order.php:7
actionrest_api_initincludes\class-wc_cashapp_update_order.php:29
actionwp_enqueue_scriptsincludes\class-wc_cash_app_pay_gateway.php:196
actionwoocommerce_checkout_order_processedincludes\class-wc_cash_app_pay_gateway.php:199
actionadmin_post_wc_cash_app_pay_connectincludes\class-wc_cash_app_pay_gateway.php:205
actionwoocommerce_email_order_detailsincludes\class-wc_cash_app_pay_gateway.php:206
actionadmin_noticesincludes\notifications\notices.php:3
actionadmin_noticesincludes\notifications\notices.php:13
actionadmin_noticesincludes\notifications\notices.php:22
actionadmin_noticesincludes\notifications\sms.php:8
actionadmin_noticesincludes\notifications\woocommerce.php:3

Scheduled Events 5

wc_cashapp_square_renewal_token_cron_hook
wc_cashapp_square_renewal_token_cron_hook
wc_cashapp_square_renewal_token_cron_hook
wc_cashapp_square_renewal_token_cron_hook
wc_cashapp_square_renewal_token_cron_hook
Maintenance & Trust

Checkout with Cash App on WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version5.0
Downloads66K

Community Trust

Rating88/100
Number of ratings5
Active installs2K
Developer Profile

Checkout with Cash App on WooCommerce Developer Profile

The African Boss

6 plugins · 8K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
66 days
View full developer profile
Detection Fingerprints

How We Detect Checkout with Cash App on WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-cashapp/assets/css/bootstrap.min.css
Version Parameters
wc-cashapp/assets/css/bootstrap.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
wc_cashapp_gateway_form
HTML Comments
<!-- DO NOT REMOVE THIS IF, IT IS ESSENTIAL FOR THE `function_exists` CALL ABOVE TO PROPERLY WORK. -->
Data Attributes
data-plugin-name="Checkout with Cash App on WooCommerce"
FAQ

Frequently Asked Questions about Checkout with Cash App on WooCommerce