
WebToffee Gift Cards for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wt-gift-cards-woocommerceCreate and sell WooCommerce gift cards in your store. Allow your customers to buy, redeem, and share gift vouchers easily.
Is WebToffee Gift Cards for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100WebToffee Gift Cards for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wt-gift-cards-woocommerce" plugin version 1.2.8 exhibits a generally good security posture with several strong protective measures in place. The absence of any recorded CVEs and a clean slate in taint analysis are positive indicators. Furthermore, the plugin demonstrates excellent practices regarding SQL queries, exclusively using prepared statements, and a high percentage of properly escaped output, mitigating common web vulnerabilities. A robust count of nonce and capability checks across its functionalities also suggests a developer conscious of access control.
However, a notable concern arises from the presence of 11 AJAX handlers, three of which lack authentication checks. This creates a direct attack surface for unauthenticated users to interact with potentially sensitive plugin functionalities. While the static analysis did not reveal critical taint flows or dangerous functions, the unprotected AJAX endpoints represent a significant risk that could be exploited if any of those handlers perform actions that can be manipulated by unauthenticated users.
Given the lack of historical vulnerabilities, it's possible these AJAX handlers are benign or protected by other indirect means. Nevertheless, the direct lack of explicit authentication is a clear security gap. The plugin's overall security is strong in many areas, but the unauthenticated AJAX handlers are a weakness that requires immediate attention to ensure a truly secure implementation.
Key Concerns
- Unprotected AJAX handlers found
WebToffee Gift Cards for WooCommerce Security Vulnerabilities
WebToffee Gift Cards for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
WebToffee Gift Cards for WooCommerce Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 128
Maintenance & Trust
WebToffee Gift Cards for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WebToffee Gift Cards for WooCommerce Alternatives
Ultimate Gift Cards for WooCommerce
woo-gift-cards-lite
Create, sell and manage WooCommerce gift cards to attract more sales and multiply your revenue at your online store.
Store credit / Gift cards for woocommerce
store-credit-for-woocommerce
Offer store credit or gift cards to customers that they can use until their credit is finished
Wyseme Gift Cards for WooCommerce by Saara INC – Create Gift card for https://wyse.me/ platform.
wyseme-giftcard-by-saara
This plugin is made for specifically for the merchant those are using https://wyse.me/ platform. This plugin should not be consider as a general giftc …
Gift Up Gift Cards for WordPress and WooCommerce
gift-up
The simplest way to sell gift cards online. Sell your own gift cards, gift certificates and gift vouchers from inside your WordPress website easily wi …
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
gift-voucher
Let your customers buy gift cards/certificates for your services & products directly on your website.
WebToffee Gift Cards for WooCommerce Developer Profile
17 plugins · 377K total installs
How We Detect WebToffee Gift Cards for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wt-gift-cards-woocommerce/assets/css/bootstrap.min.css/wp-content/plugins/wt-gift-cards-woocommerce/assets/css/animate.min.css/wp-content/plugins/wt-gift-cards-woocommerce/assets/css/bootstrap-datetimepicker.css/wp-content/plugins/wt-gift-cards-woocommerce/assets/css/select2.css/wp-content/plugins/wt-gift-cards-woocommerce/assets/css/cropper.min.css/wp-content/plugins/wt-gift-cards-woocommerce/assets/css/bootstrap-slider.css/wp-content/plugins/wt-gift-cards-woocommerce/assets/css/jquery.colorpicker.css/wp-content/plugins/wt-gift-cards-woocommerce/assets/css/admin.css+14 more/wp-content/plugins/wt-gift-cards-woocommerce/assets/js/bootstrap.min.js/wp-content/plugins/wt-gift-cards-woocommerce/assets/js/moment.min.js/wp-content/plugins/wt-gift-cards-woocommerce/assets/js/bootstrap-datetimepicker.min.js/wp-content/plugins/wt-gift-cards-woocommerce/assets/js/select2.full.js/wp-content/plugins/wt-gift-cards-woocommerce/assets/js/cropper.min.js/wp-content/plugins/wt-gift-cards-woocommerce/assets/js/bootstrap-slider.js+7 morewt-gift-cards-woocommerce/wt-gift-cards-woocommerce.php?ver=wt-gift-cards-woocommerce/admin/css/admin.css?ver=wt-gift-cards-woocommerce/admin/js/admin.js?ver=wt-gift-cards-woocommerce/public/css/wcgc_front_style.css?ver=wt-gift-cards-woocommerce/public/js/wcgc_front_script.js?ver=wt-gift-cards-woocommerce/assets/css/bootstrap.min.css?ver=wt-gift-cards-woocommerce/assets/css/animate.min.css?ver=wt-gift-cards-woocommerce/assets/css/bootstrap-datetimepicker.css?ver=wt-gift-cards-woocommerce/assets/css/select2.css?ver=wt-gift-cards-woocommerce/assets/css/cropper.min.css?ver=wt-gift-cards-woocommerce/assets/css/bootstrap-slider.css?ver=wt-gift-cards-woocommerce/assets/css/jquery.colorpicker.css?ver=wt-gift-cards-woocommerce/assets/css/daterangepicker.min.css?ver=wt-gift-cards-woocommerce/assets/js/bootstrap.min.js?ver=wt-gift-cards-woocommerce/assets/js/moment.min.js?ver=wt-gift-cards-woocommerce/assets/js/bootstrap-datetimepicker.min.js?ver=wt-gift-cards-woocommerce/assets/js/select2.full.js?ver=wt-gift-cards-woocommerce/assets/js/cropper.min.js?ver=wt-gift-cards-woocommerce/assets/js/bootstrap-slider.js?ver=wt-gift-cards-woocommerce/assets/js/jquery.colorpicker.js?ver=wt-gift-cards-woocommerce/assets/js/daterangepicker.min.js?ver=wt-gift-cards-woocommerce/assets/js/common.js?ver=wt-gift-cards-woocommerce/assets/js/gapi.js?ver=wt-gift-cards-woocommerce/assets/js/wcgc_admin_script.js?ver=wt-gift-cards-woocommerce/assets/js/wcgc_front_script.js?ver=HTML / DOM Fingerprints
wt_gc_admin_moduleswbte_gc_update_messagewt-gift-cards-woocommerce<!-- Current plugin version. --><!-- Uninstall feedback --><!-- Begins execution of the plugin. --><!-- The admin-specific functionality of the plugin. -->+5 moredata-plugin-namedata-plugin-uridata-versiondata-authordata-author-uridata-license+3 morewt_gc_admin_moduleswt_gc_gift_card_list_objwt_gc_admin_objwt_gc_pro_banner_obj