
Vietnam Checkout for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-vietnam-checkoutVietnam Checkout for WooCommerce - Thêm Tỉnh/Thành phố, Phường/Xã vào form checkout của Woo và tối giản form checkout cho phù hợp với Việt Nam
Is Vietnam Checkout for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Vietnam Checkout for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "woo-vietnam-checkout" plugin v2.1.6 presents a mixed security posture. While it demonstrates good practices in areas like SQL query sanitization and a lack of critical or high severity taint flows, there are notable areas of concern. The presence of two AJAX handlers without authentication checks creates a significant attack surface, making these endpoints potentially vulnerable to unauthorized access or manipulation. The use of the `unserialize` function, even if not currently part of a known vulnerable flow, is a dangerous function that can lead to remote code execution if improperly handled with untrusted data.
The vulnerability history reveals a pattern of past security issues, with four known CVEs, predominantly medium severity Cross-Site Scripting vulnerabilities. While there are currently no unpatched vulnerabilities, this history suggests a recurring tendency for the plugin to have security flaws that require patching. The recent vulnerability discovered in February 2024 also indicates ongoing security challenges. The plugin's strengths lie in its robust SQL handling and generally good output escaping (74%), but the unprotected AJAX endpoints and the presence of `unserialize` are significant weaknesses that require attention.
Key Concerns
- Unprotected AJAX handlers
- Use of dangerous function (unserialize)
- Past medium severity vulnerabilities (3)
- Recent vulnerability history
Vietnam Checkout for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Woocommerce Vietnam Checkout <= 2.0.7 - Authenticated (Shop manager+) Stored Cross-Site Scripting
Woocommerce Vietnam Checkout <= 2.0.8 - Authenticated (Admin+) Stored Cross-Site Scripting
Woocommerce Vietnam Checkout <= 2.0.5 - Unauthenticated Stored Cross-Site Scripting
Woocommerce Vietnam Checkout <= 2.0.4 - Reflected Cross-Site Scripting
Vietnam Checkout for WooCommerce Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Vietnam Checkout for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 40
Maintenance & Trust
Vietnam Checkout for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Vietnam Checkout for WooCommerce Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Vietnam Checkout for WooCommerce Developer Profile
8 plugins · 44K total installs
How We Detect Vietnam Checkout for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-vietnam-checkout/assets/js/devvn-checkout.js/wp-content/plugins/woo-vietnam-checkout/assets/css/devvn-checkout.css/wp-content/plugins/woo-vietnam-checkout/assets/js/devvn-address.js/wp-content/plugins/woo-vietnam-checkout/assets/js/devvn-checkout.js/wp-content/plugins/woo-vietnam-checkout/assets/js/devvn-address.jswoo-vietnam-checkout/assets/js/devvn-checkout.js?ver=woo-vietnam-checkout/assets/css/devvn-checkout.css?ver=woo-vietnam-checkout/assets/js/devvn-address.js?ver=HTML / DOM Fingerprints
devvn-checkout-wrapperdevvn-select-provincedevvn-select-districtdevvn-select-ward<!-- devvn_checkout_field --><!-- devvn_checkout_shipping_field -->data-provincedata-districtdata-warddevvn_checkout_ajax_object/wp-json/devvn-checkout/v1/locations