
Admin and Customer Messages After Order for WooCommerce: OrderConvo Security & Risk Analysis
wordpress.org/plugins/admin-and-client-message-after-order-for-woocommerceOrderConvo: Enable seamless post-order communication between vendors/admins and customers in WooCommerce.
Is Admin and Customer Messages After Order for WooCommerce: OrderConvo Safe to Use in 2026?
Generally Safe
Score 87/100Admin and Customer Messages After Order for WooCommerce: OrderConvo has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of "admin-and-client-message-after-order-for-woocommerce" v15.0 reveals a seemingly low attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The code also shows a good use of prepared statements for SQL queries (50%) and proper output escaping (76%). Nonce and capability checks are present. However, the plugin has a concerning vulnerability history with 5 known CVEs, including critical and high severity issues like Authorization Bypass, Path Traversal, Unrestricted File Uploads, and Missing Authorization. The fact that all past vulnerabilities are currently unpatched, despite the last one being recent, is a significant red flag. While the current code analysis doesn't expose immediate vulnerabilities, the historical pattern of severe, unpatched flaws strongly suggests that potential issues may still exist or have been overlooked in the static analysis, or that the patching process is unreliable. The plugin's security posture is therefore weakened by its past, with a reliance on the effectiveness of unproven fixes or the hope that no new vulnerabilities have been introduced.
Key Concerns
- History of severe unpatched vulnerabilities
- SQL queries not fully prepared
- Output not fully escaped
Admin and Customer Messages After Order for WooCommerce: OrderConvo Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated Information Disclosure
Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated User Impersonation in Order Messages
Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 13.5 - Unauthenticated Arbitrary File Read
Admin and Customer Messages After Order for WooCommerce <= 13.2 - Authenticated (Subscriber+) Limited File Upload to Cross-Site Scripting
OrderConvo <= 12.4 - Missing Authorization to Arbitrary File Upload
Admin and Customer Messages After Order for WooCommerce: OrderConvo Code Analysis
SQL Query Safety
Output Escaping
Admin and Customer Messages After Order for WooCommerce: OrderConvo Attack Surface
WordPress Hooks 22
Maintenance & Trust
Admin and Customer Messages After Order for WooCommerce: OrderConvo Maintenance & Trust
Maintenance Signals
Community Trust
Admin and Customer Messages After Order for WooCommerce: OrderConvo Alternatives
No alternatives data available yet.
Admin and Customer Messages After Order for WooCommerce: OrderConvo Developer Profile
23 plugins · 5K total installs
How We Detect Admin and Customer Messages After Order for WooCommerce: OrderConvo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-and-client-message-after-order-for-woocommerce/assets/react/front/static/js/main.e0db322b.js/wp-content/plugins/admin-and-client-message-after-order-for-woocommerce/assets/react/front/static/css/main.fa094ed3.css/wp-content/plugins/admin-and-client-message-after-order-for-woocommerce/includes/helper_functions.php/wp-content/plugins/admin-and-client-message-after-order-for-woocommerce/includes/meta.json.php/wp-content/plugins/admin-and-client-message-after-order-for-woocommerce/includes/migration.class.php/wp-content/plugins/admin-and-client-message-after-order-for-woocommerce/includes/order.class.php/wp-content/plugins/admin-and-client-message-after-order-for-woocommerce/includes/wooconvo.class.php/wp-content/plugins/admin-and-client-message-after-order-for-woocommerce/includes/wprest.class.php+2 moreadmin-and-client-message-after-order-for-woocommerce/assets/react/front/static/js/main.e0db322b.js?ver=admin-and-client-message-after-order-for-woocommerce/assets/react/front/static/css/main.fa094ed3.css?ver=HTML / DOM Fingerprints
wooconvo-wp-admin-wrapperWOOCONVO_Data/wooconvo/v1