WooODT Lite – Delivery & pickup date time location for WooCommerce Security & Risk Analysis

wordpress.org/plugins/byconsole-woo-order-delivery-time

WooODT Lite is a WooCommerce Delivery & Pickup Date Time extension that gives the facility of selecting delivery/pickup date and time/time slot o …

500 active installs v2.5.2 PHP 7.4+ WP 3.5+ Updated Mar 1, 2025
delivery-pickup-date-time-for-woocommercewoocommerce-delivery-datewoocommerce-delivery-timewoocommerce-pickup-datewoocommerce-pickup-time
61
C · Use Caution
CVEs total4
Unpatched1
Last CVEFeb 11, 2026
Safety Verdict

Is WooODT Lite – Delivery & pickup date time location for WooCommerce Safe to Use in 2026?

Use With Caution

Score 61/100

WooODT Lite – Delivery & pickup date time location for WooCommerce has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

4 known CVEs 1 unpatched Last CVE: Feb 11, 2026Updated 1yr ago
Risk Assessment

The "byconsole-woo-order-delivery-time" plugin v2.5.2 exhibits a mixed security posture. Static analysis reveals good practices in several areas, including a complete lack of dangerous functions, all SQL queries using prepared statements, and a high percentage of output escaping. Furthermore, the plugin has no identified unsanitized paths in taint analysis and a relatively small attack surface consisting of one AJAX handler and one shortcode, with no unprotected entry points identified in the static analysis. However, the plugin's vulnerability history is a significant concern. With four known CVEs, one of which remains unpatched, and the presence of high and medium severity vulnerabilities in the past, this indicates a pattern of security weaknesses. The common vulnerability types listed (Insufficient Verification of Data Authenticity, Generation of Error Message Containing Sensitive Information, Missing Authorization, and Cross-site Scripting) are all critical areas for plugin security. While recent static analysis shows improvements, the historical data suggests a need for increased vigilance and potentially more robust security testing in future development cycles.

Key Concerns

  • Unpatched high severity CVE found
  • History of multiple medium severity CVEs
  • History of Cross-site Scripting vulnerabilities
  • History of Missing Authorization vulnerabilities
  • Bundled library Select2
Vulnerabilities
4

WooODT Lite – Delivery & pickup date time location for WooCommerce Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
1 CVE in 2025
2025
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

High
1
Medium
3

4 total CVEs

CVE-2025-69401medium · 5.3Insufficient Verification of Data Authenticity

WooODT Lite <= 2.5.2 - Unauthenticated Payment Bypass

Feb 11, 2026Unpatched
CVE-2024-13540medium · 5.3Generation of Error Message Containing Sensitive Information

WooODT Lite – Delivery & pickup date time location for WooCommerce <= 2.5.1 - Unauthenticated Full Path Dsiclosure

Feb 17, 2025 Patched in 2.5.2 (17d)
CVE-2023-47179high · 8.8Missing Authorization

WooODT Lite <= 2.4.6 - Missing Authorization to Arbitrary Options Update

Oct 31, 2023 Patched in 2.4.7 (84d)
CVE-2023-45006medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WooODT Lite <= 2.4.6 - Reflected Cross-Site Scripting

Oct 3, 2023 Patched in 2.4.7 (112d)
Code Analysis
Analyzed Mar 16, 2026

WooODT Lite – Delivery & pickup date time location for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
60
858 escaped
Nonce Checks
4
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

Select2jQuery

Output Escaping

93% escaped918 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
widget (ByConsoleWooODT.php:242)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WooODT Lite – Delivery & pickup date time location for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_byconsolewooodt_admin_fields_setting_filesByConsoleWooODT.php:3686

Shortcodes 1

[ByConsole_WooODT] ByConsoleWooODT.php:3246
WordPress Hooks 32
actionadmin_noticesByConsoleWooODT.php:80
actionplugins_loadedByConsoleWooODT.php:95
actionwpByConsoleWooODT.php:102
actionwidgets_initByConsoleWooODT.php:623
actioninitByConsoleWooODT.php:675
actionwoocommerce_checkout_before_customer_detailsByConsoleWooODT.php:681
actionwoocommerce_checkout_before_customer_detailsByConsoleWooODT.php:687
actionwoocommerce_checkout_processByConsoleWooODT.php:1205
actionwoocommerce_checkout_update_order_metaByConsoleWooODT.php:1319
actionwoocommerce_admin_order_data_after_shipping_addressByConsoleWooODT.php:1464
actionwoocommerce_order_details_after_order_table_itemsByConsoleWooODT.php:1603
actionwoocommerce_order_details_after_order_tableByConsoleWooODT.php:1607
actionwoocommerce_order_details_after_order_table_itemsByConsoleWooODT.php:1610
actionwoocommerce_email_after_order_tableByConsoleWooODT.php:1769
actionwp_enqueue_scriptsByConsoleWooODT.php:1890
actionwp_enqueue_scriptsByConsoleWooODT.php:1914
actionwp_enqueue_scriptsByConsoleWooODT.php:1917
actionadmin_enqueue_scriptsByConsoleWooODT.php:1959
filterwoocommerce_package_ratesByConsoleWooODT.php:1963
actionwp_headByConsoleWooODT.php:2033
actionwp_footerByConsoleWooODT.php:3218
actionwp_footerByConsoleWooODT.php:3221
actionadmin_noticesByConsoleWooODT.php:3357
actionwoocommerce_cart_calculate_feesByConsoleWooODT.php:3359
actionwoocommerce_cart_calculate_feesByConsoleWooODT.php:3425
actionadmin_footerByConsoleWooODT.php:3467
actionadmin_menuinc\admin.php:5
filtersubmenu_fileinc\admin.php:94
actionadmin_initinc\admin.php:1010
actionadmin_initinc\byconsolewooodt_holiday_management.php:1584
actionadmin_initinc\byconsolewooodt_location_field_settings.php:10
actionadmin_initinc\byconsolewooodt_modification_request_details.php:939
Maintenance & Trust

WooODT Lite – Delivery & pickup date time location for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 1, 2025
PHP min version7.4
Downloads106K

Community Trust

Rating84/100
Number of ratings112
Active installs500
Developer Profile

WooODT Lite – Delivery & pickup date time location for WooCommerce Developer Profile

mdalabar

5 plugins · 560 total installs

71
trust score
Avg Security Score
76/100
Avg Patch Time
71 days
View full developer profile
Detection Fingerprints

How We Detect WooODT Lite – Delivery & pickup date time location for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/byconsole-woo-order-delivery-time/css/byconsole-woo-order-delivery-time.css/wp-content/plugins/byconsole-woo-order-delivery-time/js/byconsole-woo-order-delivery-time.js
Version Parameters
byconsole-woo-order-delivery-time/css/byconsole-woo-order-delivery-time.css?ver=byconsole-woo-order-delivery-time/js/byconsole-woo-order-delivery-time.js?ver=

HTML / DOM Fingerprints

CSS Classes
byconsolewooodt-widget-formbyconsolewooodt-widget-wrapper
Data Attributes
data-plugin-name="byconsole-woo-order-delivery-time"data-plugin-version="2.5.2"
JS Globals
ByConsoleWooODTLite
FAQ

Frequently Asked Questions about WooODT Lite – Delivery & pickup date time location for WooCommerce