
PiWeb Cancel order / Refund request for WooCommerce Security & Risk Analysis
wordpress.org/plugins/cancel-order-request-woocommerceOrder cancellation request / Refund request / Return order request. Repeat order option to customer for WooCommerce
Is PiWeb Cancel order / Refund request for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100PiWeb Cancel order / Refund request for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The 'cancel-order-request-woocommerce' plugin version 1.3.4.24 presents a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries using prepared statements and a high percentage of properly escaped output, which are crucial for preventing common web vulnerabilities. The absence of dangerous functions, file operations, and bundled libraries further contributes to its overall robustness. However, a significant concern arises from the substantial attack surface, with 10 AJAX handlers, 7 of which lack authentication checks. This could expose functionalities to unauthorized access and manipulation.
The taint analysis reveals one flow with an unsanitized path, although it is not classified as critical or high severity. This suggests a potential for subtle vulnerabilities if not addressed. The plugin's vulnerability history includes one known CVE related to Cross-site Scripting (XSS), which, while currently patched, indicates a past weakness that could re-emerge if not carefully managed. The presence of external HTTP requests also warrants scrutiny for potential vulnerabilities related to data exfiltration or man-in-the-middle attacks.
In conclusion, while the plugin exhibits strengths in secure coding practices for SQL and output handling, the unprotected AJAX endpoints represent a notable risk. The single tainted flow and past XSS vulnerability, though mitigated, highlight areas requiring vigilance. A balanced approach is recommended, prioritizing the securing of the exposed AJAX handlers and continuous monitoring for new vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- External HTTP requests
- 1 Medium severity CVE historically
PiWeb Cancel order / Refund request for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Cancel order request WooCommerce <= 1.3.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
PiWeb Cancel order / Refund request for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
PiWeb Cancel order / Refund request for WooCommerce Attack Surface
AJAX Handlers 10
WordPress Hooks 39
Maintenance & Trust
PiWeb Cancel order / Refund request for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
PiWeb Cancel order / Refund request for WooCommerce Alternatives
Return Refund and Exchange For WooCommerce
woo-refund-and-exchange-lite
Provide an easy refund service and increase customer satisfaction with WooCommerce Return Refund, and Exchange Warranty Management Plugin.
Flexible Refund and Return Order for WooCommerce
flexible-refund-and-return-order-for-woocommerce
WooCommerce refund and returns process made simple. Let your customers request a refund and return products directly from the My Account page.
Order Cancellation & Returns for WooCommerce
wc-order-cancellation-return
Empower your customers with the ability to cancel and return their orders seamlessly on your WooCommerce site.
WC Cancel Order
wc-cancel-order
Add order cancellation request functionality to your woocommerce powered store.
One Click Order Re-Order
one-click-order-reorder
Place any previous WooCommerce orders again into cart without any restrictions of orders status by just ONE CLICK.
PiWeb Cancel order / Refund request for WooCommerce Developer Profile
30 plugins · 93K total installs
How We Detect PiWeb Cancel order / Refund request for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cancel-order-request-woocommerce/admin/css/cancel-order-request-woocommerce-admin.css/wp-content/plugins/cancel-order-request-woocommerce/admin/css/bootstrap.css/wp-content/plugins/cancel-order-request-woocommerce/admin/js/cancel-order-request-woocommerce-admin.js/wp-content/plugins/cancel-order-request-woocommerce/admin/js/cancel-order-request-woocommerce-admin.jscancel-order-request-woocommerce/admin/css/cancel-order-request-woocommerce-admin.css?ver=cancel-order-request-woocommerce/admin/css/bootstrap.css?ver=cancel-order-request-woocommerce/admin/js/cancel-order-request-woocommerce-admin.js?ver=