Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation Security & Risk Analysis

wordpress.org/plugins/advanced-order-status-for-woocommerce

Create and manage custom WooCommerce order statuses with icons, colors, and bulk actions. Streamline your fulfillment workflow.

10 active installs v1.2.1 PHP 7.2+ WP 5.0+ Updated Mar 15, 2026
custom-order-statuscustom-status-iconsorder-managementorder-workflowwoocommerce-order-status
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation Safe to Use in 2026?

Generally Safe

Score 100/100

Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'advanced-order-status-for-woocommerce' plugin v1.2.1 exhibits a generally strong security posture based on the provided static analysis. The complete absence of dangerous functions, file operations, external HTTP requests, and the perfect implementation of prepared statements for SQL queries and output escaping are significant strengths. The presence of a nonce check is also positive. However, a notable concern arises from the REST API analysis, which reveals one route without proper permission callbacks, creating an unprotected entry point. While taint analysis shows no issues, this unprotected REST API endpoint represents a potential avenue for unauthorized access or manipulation if it handles sensitive data or actions.

The plugin's vulnerability history is entirely clear, with no recorded CVEs. This lack of past vulnerabilities, combined with the strong code hygiene observed in other areas, suggests a diligent development approach. Nevertheless, the single unprotected REST API route is a weakness that cannot be ignored. It indicates a potential oversight in securing all entry points. The bundled Freemius library, while not inherently problematic, is a component to monitor for future security updates, though its version (v1.0) is not explicitly flagged as a current risk in the provided data.

In conclusion, the plugin is well-coded with excellent practices in SQL, output escaping, and avoiding risky functions. The absence of a vulnerability history is a strong indicator of a secure development lifecycle. The primary weakness lies in the one unprotected REST API endpoint. Addressing this would significantly bolster the plugin's security profile. For now, the risk is moderate, leaning towards good, but with a specific, addressable vulnerability.

Key Concerns

  • REST API route without permission callback
  • Bundled library (Freemius v1.0) potentially outdated
Vulnerabilities
None known

Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation Release Timeline

v1.2.1Current
v1.2
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped13 total outputs
Attack Surface
1 unprotected

Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation Attack Surface

Entry Points4
Unprotected1

REST API Routes 4

POST/wp-json/asofw/v1/create-statusincludes\class-aosfw-api.php:15
GET/wp-json/asofw/v1/statusesincludes\class-aosfw-api.php:21
PUT/wp-json/asofw/v1/edit-status/(?P<slug>[a-zA-Z0-9-]+)includes\class-aosfw-api.php:27
DELETE/wp-json/asofw/v1/delete-status/(?P<slug>[a-zA-Z0-9-]+)includes\class-aosfw-api.php:41
WordPress Hooks 14
actionbefore_woocommerce_initadvanced-order-status-for-woocommerce.php:74
filterplugin_row_metaadvanced-order-status-for-woocommerce.php:85
actionadmin_noticesadvanced-order-status-for-woocommerce.php:87
actionrest_api_initincludes\class-aosfw-api.php:8
actioninitincludes\class-aosfw-api.php:9
filterwc_order_statusesincludes\class-aosfw-api.php:10
actionadmin_menuincludes\class-aosfw-register.php:8
actionadmin_enqueue_scriptsincludes\class-aosfw-register.php:9
actioninitincludes\class-aosfw-register.php:10
actionadmin_headincludes\class-aosfw-register.php:11
filterbulk_actions-edit-shop_orderincludes\class-aosfw-register.php:13
filterbulk_actions-woocommerce_page_wc-ordersincludes\class-aosfw-register.php:14
filterhandle_bulk_actions-edit-shop_orderincludes\class-aosfw-register.php:16
filterhandle_bulk_actions-woocommerce_page_wc-ordersincludes\class-aosfw-register.php:17
Maintenance & Trust

Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version7.2
Downloads745

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation Developer Profile

VerseSofts

9 plugins · 130 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-order-status-for-woocommerce/assets/css/admin.css/wp-content/plugins/advanced-order-status-for-woocommerce/assets/js/admin.js
Script Paths
/wp-content/plugins/advanced-order-status-for-woocommerce/freemius/start.php
Version Parameters
advanced-order-status-for-woocommerce/assets/css/admin.css?ver=advanced-order-status-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
order-statusstatus-processingstatus-on-holdstatus-completedstatus-pendingstatus-failedstatus-cancelled
Data Attributes
data-nonce
JS Globals
aosfw_admin_paramsAOSFW_Adminaosfw_freemius_integration
FAQ

Frequently Asked Questions about Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation