Thank You Page Customizer for WooCommerce – Increase Your Sales Security & Risk Analysis

wordpress.org/plugins/woo-thank-you-page-customizer

Craft a stunning thank you page effortlessly with our user-friendly customization tools, offer coupons to customers after purchase.

4K active installs v1.1.9 PHP 7.0+ WP 5.0+ Updated Nov 22, 2025
custom-thank-you-page-for-woocommercewc-custom-thank-youwoocommerce-thank-you-pagewoocommerce-thank-you-page-couponwoocommerce-thank-you-page-customizer
95
A · Safe
CVEs total5
Unpatched0
Last CVEDec 5, 2025
Safety Verdict

Is Thank You Page Customizer for WooCommerce – Increase Your Sales Safe to Use in 2026?

Generally Safe

Score 95/100

Thank You Page Customizer for WooCommerce – Increase Your Sales has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Dec 5, 2025Updated 4mo ago
Risk Assessment

The "woo-thank-you-page-customizer" v1.1.9 plugin exhibits a generally good security posture, with a strong emphasis on secure coding practices like prepared SQL statements and high rates of output escaping. All identified AJAX handlers and REST API routes (if any existed) appear to have authorization checks, which significantly reduces the immediate attack surface. The absence of critical or high-severity vulnerabilities in its history, and the fact that all previously known CVEs are patched, is a positive indicator. However, the plugin's history of 5 medium-severity CVEs, predominantly involving missing authorization and CSRF, warrants continued vigilance. While the static analysis shows no immediate vulnerabilities in the current version, this past pattern suggests a recurring need for thorough security reviews, particularly concerning authorization and CSRF protection in its AJAX endpoints. The presence of two flows with unsanitized paths in the taint analysis, although not flagged as critical or high, represents a potential area for further investigation and mitigation to ensure all paths are handled securely.

Key Concerns

  • Flows with unsanitized paths in taint analysis
  • Bundled Select2 library
  • External HTTP requests (2)
  • History of 5 medium CVEs
Vulnerabilities
5

Thank You Page Customizer for WooCommerce – Increase Your Sales Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
2 CVEs in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
5

5 total CVEs

CVE-2025-66528medium · 4.3Missing Authorization

Thank You Page Customizer for WooCommerce <= 1.1.8 - Missing Authorization

Dec 5, 2025 Patched in 1.1.9 (7d)
CVE-2025-30993medium · 4.3Missing Authorization

Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.7 - Missing Authorization

Aug 11, 2025 Patched in 1.1.8 (36d)
CVE-2024-1686medium · 4.3Missing Authorization

Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Data Export

Feb 26, 2024 Patched in 1.1.3 (242d)
CVE-2024-1687medium · 5.4Missing Authorization

Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution

Feb 26, 2024 Patched in 1.1.3 (1d)
CVE-2022-46812medium · 4.3Cross-Site Request Forgery (CSRF)

Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.0.13 - Cross-Site Request Forgery via send_email

Mar 22, 2023 Patched in 1.0.14 (307d)
Code Analysis
Analyzed Mar 16, 2026

Thank You Page Customizer for WooCommerce – Increase Your Sales Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
1101 escaped
Nonce Checks
18
Capability Checks
11
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

97% escaped1133 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
apply_layout (frontend\frontend.php:269)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Thank You Page Customizer for WooCommerce – Increase Your Sales Attack Surface

Entry Points11
Unprotected0

AJAX Handlers 11

authwp_ajax_woo_thank_you_page_get_available_shortcodesadmin\design.php:56
authwp_ajax_wtyp_search_couponadmin\settings.php:30
authwp_ajax_wtyp_search_productadmin\settings.php:31
authwp_ajax_wtyp_search_product_parentadmin\settings.php:32
authwp_ajax_wtyp_search_cateadmin\settings.php:33
authwp_ajax_wtypc_preview_emailsadmin\settings.php:37
authwp_ajax_woo_thank_you_page_layoutfrontend\frontend.php:74
authwp_ajax_woo_thank_you_page_select_orderfrontend\frontend.php:75
authwp_ajax_woo_thank_you_page_get_text_editor_contentfrontend\frontend.php:76
authwp_ajax_woocommerce_thank_you_page_customizer_send_emailfrontend\frontend.php:80
noprivwp_ajax_woocommerce_thank_you_page_customizer_send_emailfrontend\frontend.php:81
WordPress Hooks 42
actionadmin_noticesadmin\admin.php:19
actioninitadmin\admin.php:20
actioncustomize_registeradmin\design.php:51
actionwp_print_stylesadmin\design.php:52
actioncustomize_preview_initadmin\design.php:53
actioncustomize_controls_print_scriptsadmin\design.php:54
actioncustomize_controls_enqueue_scriptsadmin\design.php:55
filterplugin_action_links_woo-thank-you-page-customizer/woo-thank-you-page-customizer.phpadmin\settings.php:20
actionadmin_menuadmin\settings.php:26
actionadmin_enqueue_scriptsadmin\settings.php:27
actionadmin_initadmin\settings.php:28
actionmedia_buttonsadmin\settings.php:36
actionadmin_footeradmin\settings.php:38
filterwoocommerce_account_orders_columnsfrontend\account.php:18
actionwoocommerce_my_account_my_orders_column_wtypc_couponfrontend\account.php:19
actionwp_enqueue_scriptsfrontend\frontend.php:71
actionwp_print_scriptsfrontend\frontend.php:72
filterthe_contentfrontend\frontend.php:73
actionmedia_buttonsfrontend\frontend.php:77
actionwp_footerfrontend\frontend.php:78
actionwp_footerfrontend\frontend.php:79
filterpage_template_hierarchyfrontend\frontend.php:86
filterwc_get_templatefrontend\frontend.php:87
filterwoocommerce_valid_order_statuses_for_order_againfrontend\frontend.php:88
filterwoocommerce_email_stylesfrontend\frontend.php:231
filterviwec_disable_woocommerce_email_inline_stylefrontend\frontend.php:236
filterwoocommerce_email_stylesincludes\class-wtypc-functions.php:60
filterviwec_disable_woocommerce_email_inline_styleincludes\class-wtypc-functions.php:65
actionadmin_enqueue_scriptsincludes\support.php:33
actionadmin_noticesincludes\support.php:34
actionadmin_initincludes\support.php:35
actionadmin_menuincludes\support.php:36
filterplugin_row_metaincludes\support.php:38
actionadmin_initincludes\support.php:40
actionadmin_bar_menuincludes\support.php:42
actionadmin_noticesincludes\support.php:55
actionwp_dashboard_setupincludes\support.php:57
actionadmin_footerincludes\support.php:697
actionadmin_bar_menuincludes\support.php:831
actionadmin_noticesincludes\support.php:978
actionbefore_woocommerce_initwoo-thank-you-page-customizer.php:36
actionplugins_loadedwoo-thank-you-page-customizer.php:44
Maintenance & Trust

Thank You Page Customizer for WooCommerce – Increase Your Sales Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 22, 2025
PHP min version7.0
Downloads102K

Community Trust

Rating90/100
Number of ratings37
Active installs4K
Developer Profile

Thank You Page Customizer for WooCommerce – Increase Your Sales Developer Profile

VillaTheme

58 plugins · 167K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
217 days
View full developer profile
Detection Fingerprints

How We Detect Thank You Page Customizer for WooCommerce – Increase Your Sales

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-thank-you-page-customizer/assets/css/customizer.css/wp-content/plugins/woo-thank-you-page-customizer/assets/js/customizer.js/wp-content/plugins/woo-thank-you-page-customizer/assets/js/welcome-page.js/wp-content/plugins/woo-thank-you-page-customizer/assets/css/welcome-page.css
Script Paths
/wp-content/plugins/woo-thank-you-page-customizer/assets/js/customizer.js/wp-content/plugins/woo-thank-you-page-customizer/assets/js/welcome-page.js
Version Parameters
woo-thank-you-page-customizer/assets/css/customizer.css?ver=woo-thank-you-page-customizer/assets/js/customizer.js?ver=woo-thank-you-page-customizer/assets/js/welcome-page.js?ver=woo-thank-you-page-customizer/assets/css/welcome-page.css?ver=

HTML / DOM Fingerprints

CSS Classes
vi-woo-thank-you-page-customizer-welcome-pagevi-woo-thank-you-page-content-wrap
HTML Comments
Copyright 2018 villatheme.com. All rights reserved.Author: Andy Ha (support@villatheme.com)
Data Attributes
data-vi-woo-thank-you-page-nonce
JS Globals
vi_woo_thank_you_page_customizer_params
REST Endpoints
/wp-json/woo-thank-you-page-customizer/v1/get-settings/wp-json/woo-thank-you-page-customizer/v1/save-settings
FAQ

Frequently Asked Questions about Thank You Page Customizer for WooCommerce – Increase Your Sales