
Payment On Delivery for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-payment-on-deliveryReceba em dinheiro, cheque, no cartão de crédito, débito, cartão alimentação (voucher) e MultiBanco no ato da entrega.
Is Payment On Delivery for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Payment On Delivery for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'woo-payment-on-delivery' v1.4.0 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any reported CVEs, dangerous functions, or SQL queries not using prepared statements is a strong indicator of good development practices. Furthermore, the analysis reveals a limited attack surface with zero identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential entry points for attackers. File operations and external HTTP requests are also not present, further contributing to a secure design.
However, a significant concern arises from the output escaping, where only 44% of outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed on the frontend. The lack of any identified taint flows is reassuring, but the unescaped output remains a notable weakness. The plugin's history of no vulnerabilities is a positive sign, suggesting a proactive approach to security or a lack of past exploitation. Overall, while the plugin demonstrates good security fundamentals in terms of attack surface and data handling, the insufficient output escaping presents a clear risk that needs attention.
Key Concerns
- Insufficient output escaping
Payment On Delivery for WooCommerce Security Vulnerabilities
Payment On Delivery for WooCommerce Code Analysis
Output Escaping
Payment On Delivery for WooCommerce Attack Surface
WordPress Hooks 5
Maintenance & Trust
Payment On Delivery for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Payment On Delivery for WooCommerce Alternatives
PiWeb Disable payment method / Partial payment for WooCommerce
disable-payment-method-for-woocommerce
Disable payment method for WooCommerce, Charge WooCommerce Payment processing FEES, Take Partial payment for Order, Advance COD or Partial payment for …
Advanced Conditional COD Payment System
advanced-conditional-cod-payment-system
Advanced Conditional COD Payment System allows you to add a conditional advance payment for Cash on Delivery orders in WooCommerce.
Lexiata Secure COD
lexiata-secure-cod
Secure your Cash on Delivery orders by collecting a deposit/booking fee upfront and collecting the balance amount upon delivery.
R2B Partial COD Lite for WooCommerce
r2b-partial-cod-lite
Collect a small advance online and the rest via Cash on Delivery — increase trust and reduce RTO for WooCommerce stores.
TheForge Smart COD Control & Fraud Blocker for WooCommerce
theforge-smart-cod-control-fraud-blocker-for-woocommerce
Stop COD fraud with intelligent controls - reduce fake orders, prevent fraud, and save money on failed deliveries with advanced risk assessment.
Payment On Delivery for WooCommerce Developer Profile
4 plugins · 700 total installs
How We Detect Payment On Delivery for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-payment-on-delivery/includes/style.css/wp-content/plugins/woo-payment-on-delivery/includes/js/scripts.js/wp-content/plugins/woo-payment-on-delivery/includes/js/scripts.jswoo-payment-on-delivery/includes/style.css?ver=woo-payment-on-delivery/includes/js/scripts.js?ver=HTML / DOM Fingerprints
payment_box<!-- Cash On Delivery Gateway for WooCommerce --><!-- Sair se o arquivo for acessado diretamente --><!-- Inicializar pedido --><!-- Carrega o texto do plugin no site. -->+18 moredata-plugin-name="Payment On Delivery for WooCommerce"data-plugin-uri="https://wordpress.org/plugins/woo-payment-on-delivery/"data-author="carlosramosweb"data-author-uri="https://www.criacaocriativa.com"data-donate-link="https://donate.criacaocriativa.com"window.woo_payment_on_delivery_paymenttypes