
COD Default Status for WooCommerce Security & Risk Analysis
wordpress.org/plugins/cod-default-status-for-woocommerceSet default status for Cash on Delivery (COD) orders. Also manage inventory reduction behavior for COD orders.
Is COD Default Status for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100COD Default Status for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "cod-default-status-for-woocommerce" v1.0.1 demonstrates a generally strong security posture in its static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface and therefore no immediate points of entry for attackers. The code also shows good practices by not using dangerous functions, performing file operations, or making external HTTP requests. All SQL queries are handled with prepared statements, and there are no known vulnerabilities or CVEs associated with this plugin, suggesting a history of responsible development. However, a significant concern arises from the low percentage of properly escaped output (17%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the user interface. Furthermore, the taint analysis reveals two flows with unsanitized paths, which could potentially lead to vulnerabilities if these paths are user-controlled and not adequately validated or escaped. While the lack of entry points is a positive, the unescaped output and unsanitized paths are critical weaknesses that require immediate attention.
Key Concerns
- Low percentage of properly escaped output
- Taint analysis shows unsanitized paths
COD Default Status for WooCommerce Security Vulnerabilities
COD Default Status for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
COD Default Status for WooCommerce Attack Surface
WordPress Hooks 6
Maintenance & Trust
COD Default Status for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
COD Default Status for WooCommerce Alternatives
Order Tracking – WordPress Status Tracking Plugin
order-tracking
Order tracking, status and project management plugin. Create tickets and tracking numbers. Send email updates. Works standalone and with WooCommerce.
YITH WooCommerce Ajax Search
yith-woocommerce-ajax-search
YITH WooCommerce Ajax Search allows your users to search products in real time.
Ultimate FAQ Accordion Plugin
ultimate-faqs
Full-featured FAQ and accordion plugin with advanced search, simple UI and easy-to-use FAQ blocks and shortcodes.
Smart COD for WooCommerce
wc-smart-cod
All the COD restrictions and extra fees you'll ever need, in a single plugin.
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
COD Default Status for WooCommerce Developer Profile
2 plugins · 130 total installs
How We Detect COD Default Status for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
cod-default-status-for-woocommerce