COD Order Confirmation for India Security & Risk Analysis

wordpress.org/plugins/cod-confirmation-for-india

Using this plugin you can ensure that your COD orders are legitimate before you ship them out. This plugin will confirm your COD orders on call or SMS …

80 active installs v1.2.0 PHP 5.6.35+ WP 4.0+ Updated Jan 27, 2026
cash-on-delivery-ordercod-confirmationcod-ordercod-order-confirmationorder-confirm
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is COD Order Confirmation for India Safe to Use in 2026?

Generally Safe

Score 100/100

COD Order Confirmation for India has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "cod-confirmation-for-india" plugin v1.2.0 exhibits a mixed security posture. On the positive side, it has no recorded vulnerability history, including CVEs, and the taint analysis found no critical or high severity issues with unsanitized paths. The majority of its SQL queries utilize prepared statements, indicating good practice in database interaction. However, significant concerns arise from its attack surface. With a total of 4 AJAX handlers, 2 of them lack authentication checks, presenting a direct entry point for potential abuse.

Furthermore, the plugin demonstrates poor output escaping practices, with only 12% of outputs being properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data could be injected into the page without proper sanitization. While there are no directly identified critical code signals like dangerous functions or raw SQL queries, the combination of unprotected AJAX endpoints and widespread unescaped output creates substantial weaknesses.

The absence of any recorded vulnerabilities in its history is a positive indicator, but it doesn't negate the inherent risks identified in the static analysis. The plugin seems to lack robust capability checks, relying instead on nonce checks for some AJAX handlers. The overall conclusion is that while the plugin avoids known external vulnerabilities, its internal code quality, particularly regarding authentication on AJAX endpoints and output sanitization, introduces significant exploitable weaknesses that require immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • No capability checks
Vulnerabilities
None known

COD Order Confirmation for India Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

COD Order Confirmation for India Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
23 prepared
Unescaped Output
58
8 escaped
Nonce Checks
4
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

79% prepared29 total queries

Output Escaping

12% escaped66 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
<cod_setting> (cod_setting.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

COD Order Confirmation for India Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 4

authwp_ajax_COD_plugin_ordersListmuyplg.php:107
authwp_ajax_COD_plugin_AllTransactionmuyplg.php:108
authwp_ajax_COD_plugin_sender_requestmuyplg.php:109
authwp_ajax_COD_reCallCustomermuyplg.php:110
WordPress Hooks 8
actionadmin_menumuyplg.php:104
actionwoocommerce_thankyoumuyplg.php:105
actionadmin_initmuyplg.php:106
actionwp_enqueue_scriptsmuyplg.php:111
actioninitmuyplg.php:129
filterquery_varsmuyplg.php:130
actionparse_requestmuyplg.php:131
filteradmin_footer_textmuyplg.php:132
Maintenance & Trust

COD Order Confirmation for India Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 27, 2026
PHP min version5.6.35
Downloads5K

Community Trust

Rating90/100
Number of ratings11
Active installs80
Developer Profile

COD Order Confirmation for India Developer Profile

softpulseinfotech

3 plugins · 230 total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect COD Order Confirmation for India

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cod-confirmation-for-india/css/demo_table.css/wp-content/plugins/cod-confirmation-for-india/css/common.css/wp-content/plugins/cod-confirmation-for-india/js/jquery.dataTables.js/wp-content/plugins/cod-confirmation-for-india/css/jquery-ui.css
Script Paths
/wp-content/plugins/cod-confirmation-for-india/js/jquery.dataTables.js
Version Parameters
cod-confirmation-for-india/css/demo_table.css?ver=cod-confirmation-for-india/css/common.css?ver=cod-confirmation-for-india/js/jquery.dataTables.js?ver=cod-confirmation-for-india/css/jquery-ui.css?ver=

HTML / DOM Fingerprints

JS Globals
COD_plugin_object
FAQ

Frequently Asked Questions about COD Order Confirmation for India