Bulk Orders Remover for WooCommerce Security & Risk Analysis

wordpress.org/plugins/bulk-orders-remover-for-woocommerce

Bulk Orders Remover for WooCommerce

10 active installs v1.0 PHP 5.6+ WP 4.7+ Updated Nov 21, 2019
bulk-removecleanoptimize-databaseorderswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Bulk Orders Remover for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Bulk Orders Remover for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "bulk-orders-remover-for-woocommerce" plugin version 1.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unsanitized taint flows, or direct SQL queries without prepared statements is a significant positive. Furthermore, the plugin demonstrates good practices by consistently using prepared statements for its SQL queries and a high percentage of properly escaped output. The limited attack surface, with no exposed AJAX handlers, REST API routes, or shortcodes without proper checks, further contributes to its secure design.

While the code analysis indicates a clean slate, the plugin's vulnerability history is completely empty, suggesting either a very well-written plugin or a lack of historical auditing. The presence of capability checks, even if only one is identified, is a good sign of authorization being considered. However, the complete absence of nonce checks across all identified entry points (AJAX, cron events) presents a potential weakness. Cron events, if they interact with user-modifiable data or perform sensitive actions, could be susceptible to timing attacks or unauthorized execution if not properly secured with nonces. The lack of any recorded vulnerabilities in its history is reassuring but should be viewed with the caveat that this might not reflect real-world exploit attempts or comprehensive audits.

Overall, the plugin appears to be developed with security in mind, prioritizing secure coding practices for SQL and output handling. The main area of concern is the lack of nonce protection on its entry points, particularly cron events. If these cron events are not entirely self-contained and non-interactive, this could represent a minor risk. The absence of known vulnerabilities is a positive indicator of its current security status.

Key Concerns

  • No nonce checks on entry points
Vulnerabilities
None known

Bulk Orders Remover for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bulk Orders Remover for WooCommerce Release Timeline

v1.0Current
Code Analysis
Analyzed Apr 16, 2026

Bulk Orders Remover for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
5
34 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared10 total queries

Output Escaping

87% escaped39 total outputs
Attack Surface

Bulk Orders Remover for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionplugins_loadedbulk-orders-remover-for-woocommerce.php:62
filtercron_schedulesbulk-orders-remover-for-woocommerce.php:67
actionupdated_optionbulk-orders-remover-for-woocommerce.php:72
actionborfw_set_orders_to_remove_cronbulk-orders-remover-for-woocommerce.php:77
actionborfw_delete_order_item_meta_cronbulk-orders-remover-for-woocommerce.php:82
actionborfw_delete_order_items_cronbulk-orders-remover-for-woocommerce.php:87
actionborfw_delete_order_note_meta_cronbulk-orders-remover-for-woocommerce.php:92
actionborfw_delete_order_notes_cronbulk-orders-remover-for-woocommerce.php:97
actionborfw_delete_order_meta_cronbulk-orders-remover-for-woocommerce.php:102
actionborfw_delete_orders_cronbulk-orders-remover-for-woocommerce.php:107
actionadmin_noticesbulk-orders-remover-for-woocommerce.php:113
actionadmin_initclasses/Admin_Options.php:46
actionadmin_initclasses/Admin_Options.php:52
actionadmin_menuclasses/Admin_Options.php:58

Scheduled Events 2

borfw_set_orders_to_remove_cron
borfw_delete_order_item_meta_cron
Maintenance & Trust

Bulk Orders Remover for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedNov 21, 2019
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Bulk Orders Remover for WooCommerce Developer Profile

From Poland With Dev

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bulk Orders Remover for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Bulk Orders Remover for WooCommerce