ClaimDesk – Return & Exchange Claim Manager Security & Risk Analysis

wordpress.org/plugins/claim-desk

ClaimDesk helps WooCommerce store owners manage product return and exchange claims through a guided multi-step claim submission process.

0 active installs v1.0.0 PHP 7.4+ WP 6.2+ Updated Mar 31, 2026
claim-managementexchangerefundreturnwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ClaimDesk – Return & Exchange Claim Manager Safe to Use in 2026?

Generally Safe

Score 100/100

ClaimDesk – Return & Exchange Claim Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of "claim-desk" v1.0.0 reveals a generally strong security posture, with several key security best practices being followed. All identified entry points (AJAX handlers, shortcodes, cron events) appear to have appropriate authentication checks in place, which is a significant strength. The code also demonstrates excellent use of prepared statements for SQL queries and proper output escaping, indicating good defense against common injection and XSS vulnerabilities. The absence of file operations and external HTTP requests further reduces the potential attack surface.

However, the taint analysis flags two flows with unsanitized paths, which warrants attention. While the static analysis did not assign a high severity to these, unsanitized paths can sometimes lead to local file inclusion or other path traversal vulnerabilities if user input is not strictly validated before being used in file operations or system calls. The presence of nonce checks and capability checks is positive, though the number of these checks is relatively low compared to the number of AJAX handlers, suggesting there might be opportunities for improvement in comprehensive authorization checks.

The plugin's vulnerability history is entirely clear, with zero known CVEs. This is a very positive indicator, suggesting that the development team has likely prioritized security or that the plugin has not been a target for significant exploits. Coupled with the good static analysis results, this suggests "claim-desk" v1.0.0 is currently in a healthy security state. The primary concern stems from the identified unsanitized paths in the taint analysis, which should be investigated and remediated to ensure complete security.

Key Concerns

  • Flows with unsanitized paths found
Vulnerabilities
None known

ClaimDesk – Return & Exchange Claim Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ClaimDesk – Return & Exchange Claim Manager Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

ClaimDesk – Return & Exchange Claim Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
26 prepared
Unescaped Output
0
523 escaped
Nonce Checks
8
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared26 total queries

Output Escaping

100% escaped523 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
display_claims_list (admin/class-claim-desk-admin.php:135)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ClaimDesk – Return & Exchange Claim Manager Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 6

authwp_ajax_claim_desk_save_configincludes/class-claim-desk-config-manager.php:27
authwp_ajax_claim_desk_get_configincludes/class-claim-desk-config-manager.php:28
authwp_ajax_claim_desk_get_order_itemspublic/class-claim-desk-public.php:108
noprivwp_ajax_claim_desk_get_order_itemspublic/class-claim-desk-public.php:109
authwp_ajax_claim_desk_submit_claimpublic/class-claim-desk-public.php:110
noprivwp_ajax_claim_desk_submit_claimpublic/class-claim-desk-public.php:111

Shortcodes 1

[claim_desk_wizard] includes/class-claim-desk.php:171
WordPress Hooks 20
actionbefore_woocommerce_initclaim-desk.php:64
actionadmin_enqueue_scriptsincludes/class-claim-desk.php:142
actionadmin_enqueue_scriptsincludes/class-claim-desk.php:143
actionadmin_menuincludes/class-claim-desk.php:144
actionadmin_initincludes/class-claim-desk.php:145
actionwp_enqueue_scriptsincludes/class-claim-desk.php:161
actionwp_enqueue_scriptsincludes/class-claim-desk.php:162
filterwoocommerce_my_account_my_orders_actionsincludes/class-claim-desk.php:165
actionwoocommerce_order_details_after_order_tableincludes/class-claim-desk.php:168
filterwoocommerce_email_classesincludes/class-claim-desk.php:184
actionclaim_desk_claim_createdincludes/class-claim-desk.php:185
actionclaim_desk_claim_status_updatedincludes/class-claim-desk.php:186
actionclaim_desk_check_remindersincludes/class-claim-desk.php:187
actioninitincludes/class-claim-desk.php:188
actionclaim_desk_claim_createdincludes/class-claim-desk.php:189
actionclaim_desk_claim_status_updatedincludes/class-claim-desk.php:190
actionclaim_desk_trigger_admin_reminder_emailincludes/emails/class-claim-desk-email-admin-reminder.php:37
actionclaim_desk_trigger_claim_created_admin_emailincludes/emails/class-claim-desk-email-claim-created-admin.php:37
actionclaim_desk_trigger_claim_created_customer_emailincludes/emails/class-claim-desk-email-claim-created-customer.php:36
actionclaim_desk_trigger_claim_status_updated_customer_emailincludes/emails/class-claim-desk-email-claim-status-updated-customer.php:36

Scheduled Events 2

claim_desk_check_reminders
claim_desk_check_reminders
Maintenance & Trust

ClaimDesk – Return & Exchange Claim Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 31, 2026
PHP min version7.4
Downloads76

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ClaimDesk – Return & Exchange Claim Manager Developer Profile

Prozoned

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ClaimDesk – Return & Exchange Claim Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/claim-desk/admin/css/claim-desk-admin.css/wp-content/plugins/claim-desk/admin/js/claim-desk-admin.js
Script Paths
/wp-content/plugins/claim-desk/admin/js/claim-desk-admin.js
Version Parameters
claim-desk/css/claim-desk-admin.css?ver=claim-desk/js/claim-desk-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
claim-desk-contentnav-tab-wrappernav-tabnav-tab-active
Data Attributes
data-tab
JS Globals
claim_desk_admin
FAQ

Frequently Asked Questions about ClaimDesk – Return & Exchange Claim Manager