Country Based Bank Accounts for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-country-based-bank-accounts

Select which BACS gateway bank accounts will be available in certain country/countries

200 active installs v2.0.2 PHP + WP 4.2+ Updated Aug 31, 2025
bacsbank-accountcountriescountrywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Country Based Bank Accounts for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Country Based Bank Accounts for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'woo-country-based-bank-accounts' plugin v2.0.2 exhibits a generally strong security posture. The absence of any identified CVEs, coupled with a clean taint analysis and lack of dangerous functions, indicates diligent security practices in its development or a low profile for exploit attempts. The plugin also demonstrates good practices by using prepared statements for all SQL queries and having no file operations or external HTTP requests, further reducing common attack vectors.

However, the analysis does reveal some concerning areas. The complete lack of output escaping is a significant weakness. Every output point is a potential vector for cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before display. Additionally, the absence of any nonce or capability checks across all identified entry points is a critical oversight. This means that any functionality exposed through AJAX, REST API, or shortcodes (though none are listed) could be triggered by unauthenticated users or users with insufficient privileges, leading to potential unauthorized actions or information disclosure. While the attack surface appears to be zero currently, any future additions without proper security checks will inherit these risks.

In conclusion, while the plugin has a clean vulnerability history and uses secure methods for database interaction and external communication, the critical flaws in output escaping and the complete lack of authentication/authorization checks on entry points present substantial risks. These issues, if exploited, could lead to severe security compromises. The current lack of identified issues might be due to the plugin's limited attack surface or its obscurity, rather than inherent security.

Key Concerns

  • No output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Country Based Bank Accounts for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Country Based Bank Accounts for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Country Based Bank Accounts for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterwoocommerce_settings_tabs_arrayclass-wc-country-based-bank-accounts-settings.php:18
actionbefore_woocommerce_initwoo-country-based-bank-accounts.php:50
actionwoocommerce_loadedwoo-country-based-bank-accounts.php:57
actionupdate_option_woocommerce_bacs_accountswoo-country-based-bank-accounts.php:58
actionwoocommerce_thankyou_bacswoo-country-based-bank-accounts.php:61
actionwoocommerce_email_before_order_tablewoo-country-based-bank-accounts.php:62
filterwoocommerce_bacs_accountswoo-country-based-bank-accounts.php:63
filterwoocommerce_available_payment_gatewayswoo-country-based-bank-accounts.php:64
Maintenance & Trust

Country Based Bank Accounts for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 31, 2025
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Country Based Bank Accounts for WooCommerce Developer Profile

Marian Kadanka

3 plugins · 8K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Country Based Bank Accounts for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Country Based Bank Accounts for WooCommerce