
Custom Order Meta Box Security & Risk Analysis
wordpress.org/plugins/custom-order-meta-boxThis plugin adds a custom meta box on WooCommerce order pages in the WordPress admin dashboard. With this plugin, store administrators can view all me …
Is Custom Order Meta Box Safe to Use in 2026?
Generally Safe
Score 92/100Custom Order Meta Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-order-meta-box" plugin v1.0 exhibits an exceptionally strong static security posture, with no apparent vulnerabilities identified in the provided analysis. The absence of any identified attack surface entry points like AJAX handlers, REST API routes, shortcodes, or cron events, coupled with the lack of dangerous function usage, SQL injection risks (100% prepared statements), and unescaped output, suggests a robustly coded plugin. The thoroughness of output escaping and the complete absence of file operations or external HTTP requests further bolster this positive assessment. The plugin's vulnerability history is also clean, with no recorded CVEs, which indicates a consistent pattern of secure development. While the current analysis is highly reassuring, the primary concern stems from the lack of nonces and capability checks. While the attack surface is currently zero, if any entry points were to be introduced in future versions, the absence of these fundamental security mechanisms could quickly become a significant risk, potentially exposing the plugin to unauthorized actions or privilege escalation.
Key Concerns
- Missing nonce checks on potential future entry points
- Missing capability checks on potential future entry points
Custom Order Meta Box Security Vulnerabilities
Custom Order Meta Box Code Analysis
Output Escaping
Custom Order Meta Box Attack Surface
WordPress Hooks 1
Maintenance & Trust
Custom Order Meta Box Maintenance & Trust
Maintenance Signals
Community Trust
Custom Order Meta Box Alternatives
JSM Show Order Metadata for WooCommerce HPOS
jsm-show-order-meta
Show WooCommerce order metadata in a metabox when editing HPOS orders - a great tool for debugging issues with HPOS order metadata.
FlexOrder – Manage & Sync Orders with Google Sheets for WooCommerce
order-sync-with-google-sheets-for-woocommerce
Create, edit, manage, and sync WooCommerce orders with Google Sheets for easy order handling and updates.
WaMate Confirm – Order Confirmation
wamate-confirm
WaMate Confirm is a powerful plugin designed to streamline your order confirmation process
AntiFake Mate – Phone Blocker
antifake-mate-phone-blocker
AntiFake Mate is a WooCommerce plugin that allows you to block specific phone numbers from placing orders, protecting your store from fraud and abuse …
Shop Manager for Woocommerce
shop-manager
🚀 Transform your WooCommerce order management with a powerful, modern React dashboard. Boost efficiency and save time!
Custom Order Meta Box Developer Profile
2 plugins · 10 total installs
How We Detect Custom Order Meta Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widefat