wcs-renewal-scheduler
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalyprogrammatic-renewal.md
LOWAnomalyLOW
programmatic-renewal.md
The code is a readable WooCommerce renewal skeleton with no apparent malware, credential theft, exfiltration, obfuscated payload, or destructive behavior. It performs sensitive renewal and payment-related operations, so deploying it without authentication, authorization, nonce and replay protection, atomic durable locking, audit logging, idempotency, and recent-order checks would create a meaningful security and billing risk. Raw exception propagation should also be restricted or sanitized.
Confidence: 97%Severity: 55%
Audit Metadata