
Custom Product in Woo Order Security & Risk Analysis
wordpress.org/plugins/custom-product-in-woo-orderWhen manually editing orders from admin dashboard, add custom products directly to orders without adding them to the product catalog.
Is Custom Product in Woo Order Safe to Use in 2026?
Generally Safe
Score 100/100Custom Product in Woo Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "custom-product-in-woo-order" v1.4 exhibits a strong security posture based on the provided static analysis. It adheres to several key security best practices, including the complete use of prepared statements for SQL queries and proper output escaping for all identified outputs. Furthermore, the absence of dangerous function usage, file operations, and external HTTP requests significantly reduces the plugin's attack surface. The presence of a nonce check on its single AJAX handler is also a positive indicator of security awareness.
The vulnerability history also suggests a clean track record with zero known CVEs, indicating a low likelihood of previously exploited weaknesses. The static analysis did not reveal any taint flows or critical code signals that would suggest immediate high-risk vulnerabilities. However, the lack of capability checks on the AJAX handler is a potential area of concern, as it means that any authenticated user could potentially trigger this handler, regardless of their role or permissions. While no specific vulnerabilities are immediately evident, this missing capability check represents a weakness that could be exploited in conjunction with other factors or in future plugin updates.
In conclusion, this plugin demonstrates good security practices in its code, particularly in its handling of data and prevention of common injection vulnerabilities. The absence of known vulnerabilities is encouraging. The primary area for improvement lies in strengthening the authentication and authorization mechanisms for its entry points, specifically by implementing capability checks where appropriate. This would further harden the plugin against potential misuse.
Key Concerns
- Missing capability checks on AJAX handler
Custom Product in Woo Order Security Vulnerabilities
Custom Product in Woo Order Code Analysis
Output Escaping
Custom Product in Woo Order Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Custom Product in Woo Order Maintenance & Trust
Maintenance Signals
Community Trust
Custom Product in Woo Order Alternatives
Flexible Product Fields (WooCommerce Product Addons) – WooCommerce Product Page Editor
flexible-product-fields
Add extra product options on your WooCommerce product page. Product addons for all product variations. 20 free product addons.
Custom Product Tabs for WooCommerce & WordPress Tabs Builder – Smart Tabs
wp-expand-tabs-free
A customizable plugin to create and manage WooCommerce product tabs and WordPress tabs to organize content.
Storelly Product Builder for WooCommerce
storelly-product-builder-for-woocommerce
Storelly Product Builder allows customers to configure and personalize products. Ideal for customizable or made-to-order items.
Sequential Order Number for WooCommerce
wt-woocommerce-sequential-order-numbers
Sequential order number for WooCommerce is the best plugin to generate sequential or custom order numbers for existing and new WooCommerce orders.
Custom Order Status Manager for WooCommerce
bp-custom-order-status-for-woocommerce
Custom Order Status Manager for WooCommerce plugin allows you to create, delete and edit order statuses to better control the flow of your orders.
Custom Product in Woo Order Developer Profile
3 plugins · 1K total installs
How We Detect Custom Product in Woo Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-product-in-woo-order/includes/add-element.jsjqueryHTML / DOM Fingerprints
custom_item_rowproduct_thumproduct_namecustom_pricequantityadd_custom_itemremove_custom_itemname="custom_product_namename="custom_pricename="custom_quantitycpwo_ajax_obj