Payment On Delivery for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-payment-on-delivery

Receba em dinheiro, cheque, no cartão de crédito, débito, cartão alimentação (voucher) e MultiBanco no ato da entrega.

300 active installs v1.4.0 PHP + WP 3.5.0+ Updated Apr 22, 2023
deliverydelivery-checkoutdelivery-gatewaydelivery-paymentpayment
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment On Delivery for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Payment On Delivery for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin 'woo-payment-on-delivery' v1.4.0 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any reported CVEs, dangerous functions, or SQL queries not using prepared statements is a strong indicator of good development practices. Furthermore, the analysis reveals a limited attack surface with zero identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential entry points for attackers. File operations and external HTTP requests are also not present, further contributing to a secure design.

However, a significant concern arises from the output escaping, where only 44% of outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed on the frontend. The lack of any identified taint flows is reassuring, but the unescaped output remains a notable weakness. The plugin's history of no vulnerabilities is a positive sign, suggesting a proactive approach to security or a lack of past exploitation. Overall, while the plugin demonstrates good security fundamentals in terms of attack surface and data handling, the insufficient output escaping presents a clear risk that needs attention.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Payment On Delivery for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment On Delivery for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

44% escaped18 total outputs
Attack Surface

Payment On Delivery for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedwoo-payment-on-delivery.php:36
actionwoocommerce_card_deliverywoo-payment-on-delivery.php:85
actionplugins_loadedwoo-payment-on-delivery.php:478
filterwoocommerce_payment_gatewayswoo-payment-on-delivery.php:567
actionplugins_loadedwoo-payment-on-delivery.php:569
Maintenance & Trust

Payment On Delivery for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 22, 2023
PHP min version
Downloads25K

Community Trust

Rating90/100
Number of ratings10
Active installs300
Developer Profile

Payment On Delivery for WooCommerce Developer Profile

carlosramosweb

4 plugins · 700 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment On Delivery for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-payment-on-delivery/includes/style.css/wp-content/plugins/woo-payment-on-delivery/includes/js/scripts.js
Script Paths
/wp-content/plugins/woo-payment-on-delivery/includes/js/scripts.js
Version Parameters
woo-payment-on-delivery/includes/style.css?ver=woo-payment-on-delivery/includes/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
payment_box
HTML Comments
<!-- Cash On Delivery Gateway for WooCommerce --><!-- Sair se o arquivo for acessado diretamente --><!-- Inicializar pedido --><!-- Carrega o texto do plugin no site. -->+18 more
Data Attributes
data-plugin-name="Payment On Delivery for WooCommerce"data-plugin-uri="https://wordpress.org/plugins/woo-payment-on-delivery/"data-author="carlosramosweb"data-author-uri="https://www.criacaocriativa.com"data-donate-link="https://donate.criacaocriativa.com"
JS Globals
window.woo_payment_on_delivery_paymenttypes
FAQ

Frequently Asked Questions about Payment On Delivery for WooCommerce