
Smart Online Order for Clover Security & Risk Analysis
wordpress.org/plugins/clover-online-ordersSmart Online Order for Clover allows you to receive orders from your Wordpress website and have it sent directly to your Clover POS.
Is Smart Online Order for Clover Safe to Use in 2026?
Generally Safe
Score 97/100Smart Online Order for Clover has a strong security track record. Known vulnerabilities have been patched promptly.
The clover-online-orders plugin presents a significant security risk due to a large attack surface with a concerning number of unprotected AJAX handlers. While the code analysis shows no dangerous functions or critical taint flows, the presence of 64 unprotected AJAX handlers is a major concern, indicating a high likelihood of potential unauthorized actions or data manipulation. Furthermore, the static analysis reveals that a substantial portion of SQL queries (69%) are not using prepared statements, which, combined with 10 flows with unsanitized paths, increases the risk of SQL injection vulnerabilities.
The vulnerability history is particularly troubling. With 9 known medium-severity CVEs, even though none are currently unpatched, it suggests a pattern of recurring security flaws, specifically Cross-site Scripting (XSS) and Missing Authorization. This history points to potential systemic issues in the plugin's development and testing processes. While the plugin does have some strengths, such as a reasonable number of capability checks and moderately good output escaping, these are overshadowed by the significant risks posed by unprotected entry points and historical vulnerability patterns.
Key Concerns
- Large attack surface without auth checks
- SQL queries not using prepared statements
- Flows with unsanitized paths
- High severity taint flows found
- Numerous medium CVEs in history
- Output escaping not properly implemented
Smart Online Order for Clover Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
Smart Online Order for Clover <= 1.5.7 - Reflected Cross-Site Scripting
Smart Online Order for Clover <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via moo_receipt_link Shortcode
Smart Online Order for Clover <= 1.5.6 - Missing Authorization to Authenticated (Subscriber+) Plugin Data Update
Smart Online Order for Clover <= 1.5.6 - Missing Authorization to Plugin Deactivation and Data Deletion
Smart Online Order for Clover <= 1.5.6 - Missing Authorization
Smart Online Order for Clover <= 1.5.6 - Missing Authorization
Smart Online Order for Clover <= 1.5.4 - Cross-Site Request Forgery
Smart Online Order for Clover <= 1.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Smart Online Order for Clover <= 1.5.4 - Reflected Cross-Site Scripting
Smart Online Order for Clover Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Smart Online Order for Clover Attack Surface
AJAX Handlers 64
Shortcodes 9
WordPress Hooks 26
Maintenance & Trust
Smart Online Order for Clover Maintenance & Trust
Maintenance Signals
Community Trust
Smart Online Order for Clover Alternatives
Online Ordering Plus Custom Branded Apps For Clover Merchants
orderem-online-ordering-for-clover
OrderEm Online Orders for Clover allows you to receive orders from your Wordpress website and have it sent directly to your Clover POS
Clover Payments for WooCommerce
clover-payments-for-woocommerce
The Clover Payments plugin enables merchants that use WooCommerce to process online card payments using Clover.
WeeConnectPay – Clover Payment Gateway for WooCommerce
weeconnectpay
Accept payments easily and quickly with the Clover online Payment gateway by WeeConnectPay.
Clover Payment Gateway by Zaytech for WooCommerce
woo-clover-gateway-by-zaytech
Accept Clover POS payments from WooCommerce and auto-print orders to your Clover devices in minutes.
Smart Online Order for Clover Developer Profile
2 plugins · 2K total installs
How We Detect Smart Online Order for Clover
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clover-online-orders/build/moo-online-orders.css/wp-content/plugins/clover-online-orders/build/frontend.js/wp-content/plugins/clover-online-orders/build/frontend.css/wp-content/plugins/clover-online-orders/build/backend.js/wp-content/plugins/clover-online-orders/build/backend.css/wp-content/plugins/clover-online-orders/build/frontend.jsclover-online-orders/build/moo-online-orders.css?ver=clover-online-orders/build/frontend.js?ver=clover-online-orders/build/frontend.css?ver=clover-online-orders/build/backend.js?ver=clover-online-orders/build/backend.css?ver=HTML / DOM Fingerprints
moo-main-sectionmoo-cart-items-listmoo-product-itemmoo-add-to-cart-buttonmoo-checkout-formmoo-cart-totalmoo-order-summarymoo-customer-account<!-- Moo_OnlineOrders_Widgets_Opening_hours --><!-- Moo_OnlineOrders_Widgets_best_selling --><!-- Moo_OnlineOrders_Widgets_categories -->data-product-iddata-cart-item-iddata-clover-order-idMooOnlineOrdersmoo_data/wp-json/moo-online-orders/v1/products/wp-json/moo-online-orders/v1/cart/wp-json/moo-online-orders/v1/orders/wp-json/moo-online-orders/v1/settings[moo_all_items][moo_cart][moo_checkout][moo_my_account]