WooComerce Colored Order Notes Security & Risk Analysis

wordpress.org/plugins/colored-order-notes-for-woocommerce

This plugin allows you to customize order note color for each order status.

60 active installs v1.0.2 PHP + WP + Updated Mar 6, 2019
colored-order-notecoloured-order-notesorder-note-colorwoocommerce-coloured-order-noteswoocommerce-custom-order-note-color
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WooComerce Colored Order Notes Safe to Use in 2026?

Generally Safe

Score 85/100

WooComerce Colored Order Notes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin 'colored-order-notes-for-woocommerce' v1.0.2 demonstrates a strong adherence to secure coding practices based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Furthermore, the claim of 100% of SQL queries utilizing prepared statements suggests good protection against SQL injection vulnerabilities.

However, the analysis does reveal potential areas of concern. A significant weakness is the complete lack of nonce checks and capability checks. This is particularly worrying given that any entry points, even if currently zero, could be exploited without proper authorization checks. The output escaping is also not entirely robust, with only 50% of outputs being properly escaped, which could leave the plugin vulnerable to cross-site scripting (XSS) attacks if any new output functionalities are added or if the existing ones are misused.

The vulnerability history is clean, with no recorded CVEs. This, combined with the secure coding practices, paints a picture of a generally well-maintained plugin. However, the absence of vulnerability history doesn't negate the risks identified in the static analysis, particularly the missing authorization checks. In conclusion, while the plugin shows strengths in its basic secure coding, the lack of comprehensive authorization checks and incomplete output escaping represent notable weaknesses that should be addressed to ensure a robust security posture.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • 50% of outputs are not properly escaped
Vulnerabilities
None known

WooComerce Colored Order Notes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WooComerce Colored Order Notes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

WooComerce Colored Order Notes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitwoocommerce-colored-order-notes.php:36
actionadmin_noticeswoocommerce-colored-order-notes.php:47
filterwoocommerce_settings_tabs_arraywoocommerce-colored-order-notes.php:51
filterwoocommerce_order_note_classwoocommerce-colored-order-notes.php:52
actionwoocommerce_settings_tabs_order_note_colorwoocommerce-colored-order-notes.php:53
actionwoocommerce_update_options_order_note_colorwoocommerce-colored-order-notes.php:54
actionadmin_headwoocommerce-colored-order-notes.php:55
Maintenance & Trust

WooComerce Colored Order Notes Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMar 6, 2019
PHP min version
Downloads7K

Community Trust

Rating80/100
Number of ratings4
Active installs60
Alternatives

WooComerce Colored Order Notes Alternatives

No alternatives data available yet.

Developer Profile

WooComerce Colored Order Notes Developer Profile

Prasad Nevase

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WooComerce Colored Order Notes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
note_contentnote
FAQ

Frequently Asked Questions about WooComerce Colored Order Notes