WP-xPerts Woocommerce Custom Thank you Page Security & Risk Analysis

wordpress.org/plugins/wp-xperts-woocommerce-custom-thank-you-page

This plugin enables you to create a custom thank you page. Admin will be redirected to custom thank you page after successful checkout

10 active installs v1.2.2 PHP + WP 3.2+ Updated Jul 29, 2017
custom-redirectwoo-custom-thank-you-pagewoo-thank-you-page-redirectwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-xPerts Woocommerce Custom Thank you Page Safe to Use in 2026?

Generally Safe

Score 85/100

WP-xPerts Woocommerce Custom Thank you Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The security posture of the "wp-xperts-woocommerce-custom-thank-you-page" plugin version 1.2.2 appears to be generally good, with no known vulnerabilities or critical code signals indicating immediate threats. The absence of CVEs and a clean vulnerability history suggests a history of secure development or prompt patching. The static analysis reveals a very small attack surface with zero identified entry points, which is a strong indicator of good security practices. Furthermore, the plugin utilizes prepared statements for all SQL queries and demonstrates some output escaping, further contributing to a secure foundation.

However, there are a few areas for concern that temper the overall positive assessment. The presence of the "unserialize" function, even if not directly exploitable due to other security measures, is a known risky function that can lead to deserialization vulnerabilities if input is not strictly controlled. The lack of capability checks is another significant weakness, as it implies that sensitive actions might be accessible to users who should not have access, even if direct entry points are currently limited. While taint analysis shows no current unsanitized flows, the combination of "unserialize" and missing capability checks creates a potential for future vulnerabilities if the plugin evolves without careful attention to input validation and authorization.

In conclusion, the plugin exhibits strengths in its limited attack surface and secure SQL handling. Nevertheless, the presence of "unserialize" and the absence of capability checks represent notable weaknesses that should be addressed to further enhance its security. The clean vulnerability history is a positive sign, but it's crucial to maintain this by mitigating the identified risks.

Key Concerns

  • Dangerous function 'unserialize' present
  • No capability checks found
  • Output escaping not fully implemented
Vulnerabilities
None known

WP-xPerts Woocommerce Custom Thank you Page Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP-xPerts Woocommerce Custom Thank you Page Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$WX_get_cr_options = unserialize($WX_get_cr_options);inc\wx-cr-settings.php:26
unserialize$WX_get_cr_options = unserialize($WX_get_cr_options);woo-custom-thankyou-page.php:80

Output Escaping

67% escaped3 total outputs
Attack Surface

WP-xPerts Woocommerce Custom Thank you Page Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuwoo-custom-thankyou-page.php:25
actionadmin_enqueue_scriptswoo-custom-thankyou-page.php:26
actiontemplate_redirectwoo-custom-thankyou-page.php:74
Maintenance & Trust

WP-xPerts Woocommerce Custom Thank you Page Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedJul 29, 2017
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

WP-xPerts Woocommerce Custom Thank you Page Developer Profile

sajid hussain

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP-xPerts Woocommerce Custom Thank you Page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-xperts-woocommerce-custom-thank-you-page/css/styles-admin.css
Version Parameters
wp-xperts-woocommerce-custom-thank-you-page/css/styles-admin.css?ver=1.2.2

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP-xPerts Woocommerce Custom Thank you Page