
ArchiveMaster – Auto Archive and Export Old Orders for WooCommerce Security & Risk Analysis
wordpress.org/plugins/archive-masterArchive old WooCommerce orders to speed up your site and keep your database lean. Move historical orders to local DB, cloud, or even Google Drive.
Is ArchiveMaster – Auto Archive and Export Old Orders for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100ArchiveMaster – Auto Archive and Export Old Orders for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The archive-master plugin v1.12.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in several areas, with a high percentage of SQL queries using prepared statements and a substantial majority of output being properly escaped. The plugin also has no known historical vulnerabilities, which suggests a generally stable and well-maintained codebase over time. However, significant concerns arise from its attack surface. A substantial portion of its AJAX handlers (8 out of 11) lack authentication checks, presenting a considerable entry point for potential unauthorized actions or information disclosure. While taint analysis did not reveal critical or high-severity issues, the presence of one flow with unsanitized paths warrants attention, even if it did not escalate to a critical finding in this analysis. The limited number of entry points in other areas like REST API and shortcodes is a strength, but the unprotected AJAX handlers overshadow these positives.
In conclusion, while the plugin's use of prepared statements and output escaping is commendable, the high number of unprotected AJAX handlers represents a clear and actionable security risk. The absence of historical vulnerabilities is a good sign, but it does not mitigate the immediate risks presented by the current code. The plugin would benefit from implementing proper authentication and authorization checks on all its AJAX endpoints to significantly improve its security. The single unsanitized path flow, though not rated critical, should also be investigated and remediated.
Key Concerns
- High number of AJAX handlers without auth checks
- Flows with unsanitized paths
ArchiveMaster – Auto Archive and Export Old Orders for WooCommerce Security Vulnerabilities
ArchiveMaster – Auto Archive and Export Old Orders for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ArchiveMaster – Auto Archive and Export Old Orders for WooCommerce Attack Surface
AJAX Handlers 11
WordPress Hooks 67
Scheduled Events 1
Maintenance & Trust
ArchiveMaster – Auto Archive and Export Old Orders for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ArchiveMaster – Auto Archive and Export Old Orders for WooCommerce Alternatives
Disable Author Archives
disable-author-archives
Disable Author Archives completely removes author archives and makes the web server return status code 404 ('Not Found') instead.
Simple Yearly Archive
simple-yearly-archive
Simple Yearly Archive is a rather neat and simple Wordpress plugin that allows you to display your archives in a year-based list.
Advanced Posts/Page
advanced-posts-per-page
Fine grained control of how many of your posts appear on each of the various WordPress archive pages.
Collapsing Archives
collapsing-archives
This plugin uses Javascript to dynamically expand or collapse the set of months for each year and posts for each month in the archive listing of your …
Sitekit
sitekit
Widgets: search, archives and categories. Shortcodes: archives, bloginfo, iframe and categories.
ArchiveMaster – Auto Archive and Export Old Orders for WooCommerce Developer Profile
16 plugins · 32K total installs
How We Detect ArchiveMaster – Auto Archive and Export Old Orders for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/archive-master/build/style.css/wp-content/plugins/archive-master/build/app.js/wp-content/plugins/archive-master/build/vendor.js/wp-content/plugins/archive-master/build/app.js/wp-content/plugins/archive-master/build/vendor.js/wp-content/plugins/archive-master/build/style.css?ver=/wp-content/plugins/archive-master/build/app.js?ver=/wp-content/plugins/archive-master/build/vendor.js?ver=HTML / DOM Fingerprints
archm-ordersarchm-archive-btnarchm-unarchive-btnarchm-order-actionsarchm-bulk-archive-formarchm-bulk-actionsarchm-date-pickerdata-wp-edit-postdata-archm-noncedata-archm-post-idwindow.archmSettingswindow.archmAjaxUrlwindow.archmNonce/wp-json/archive-master/v1/bulk-archive/wp-json/archive-master/v1/settings[archive_master_orders][archive_master_dashboard]