
WooDPD Security & Risk Analysis
wordpress.org/plugins/woodpdWordpress plugin for WooCommerce and DPD, with cart button widget.
Is WooDPD Safe to Use in 2026?
Generally Safe
Score 85/100WooDPD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'woodpd' v1.0.0 plugin exhibits a mixed security posture. On one hand, the lack of any recorded vulnerabilities, CVEs, or identified critical/high severity taint flows is a positive indicator. The plugin also demonstrates good practices in handling SQL queries by exclusively using prepared statements and avoiding external HTTP requests and file operations, which are common attack vectors. However, the static analysis reveals significant concerns. The presence of a `create_function` call is a known dangerous function that can lead to arbitrary code execution if not handled with extreme caution and proper sanitization, which is not evident from the provided data. Furthermore, a very low percentage (16%) of output escaping is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of any nonce checks or capability checks, combined with zero unprotected entry points, initially appears positive but could also mean the plugin has an extremely limited attack surface or that these checks are simply missing, leaving any potential future entry points vulnerable. The vulnerability history being clean is good, but the current code analysis points to potential weaknesses that could lead to future vulnerabilities.
Key Concerns
- Dangerous function create_function used
- Low output escaping (16%)
- Missing nonce checks
- Missing capability checks
WooDPD Security Vulnerabilities
WooDPD Code Analysis
Dangerous Functions Found
Output Escaping
WooDPD Attack Surface
WordPress Hooks 14
Maintenance & Trust
WooDPD Maintenance & Trust
Maintenance Signals
Community Trust
WooDPD Alternatives
2C2P Redirect API for WooCommerce
2c2p-redirect-api-for-woocommerce
Accept Payment (Credit/Debit Cards, Alipay, Alternative/Cash Payments) on your WooCommerce webstore.
WooCommerce PayPal Here Payment Gateway
woocommerce-paypal-here-gateway
Accept payment in-person using PayPal Here as a point-of-sale system.
Interface for Geniki Taxydromiki API v2 and Woo
interface-for-geniki-taxydromiki-and-woo
Interface for Geniki Taxydromiki API v2 and Woocommerce.
Awesome for WC
awesome-wc
Customize every aspect of your WooCommerce store.
Extended Setup for WooCommerce – Customize your eCommerce
extended-setup-for-woocommerce
WooCommerce Extended Setup is a powerful customizer for WooCommerce that helps you customize with no code.
WooDPD Developer Profile
1 plugin · 10 total installs
How We Detect WooDPD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woodpd/woodpd.php/wp-content/plugins/woodpd/woodpd-template.php