Delivery Date for WooCommerce Security & Risk Analysis

wordpress.org/plugins/delivery-date-for-woocommerce

This plugin adds a delivery date field to the checkout page.

100 active installs v2.0.2 PHP + WP 3.0.1+ Updated Jul 30, 2025
delivery-datedelivery-date-woocommerce-pluginwoocommercewoocommerce-delivery-datewoocommerce-order-delivery-date-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Delivery Date for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Delivery Date for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'delivery-date-for-woocommerce' v2.0.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, properly escaped output, and the exclusive use of prepared statements for SQL queries are commendable security practices. The plugin also demonstrates good security hygiene by performing nonce checks. However, the lack of capability checks on any entry points is a notable concern, as it implies that potentially sensitive actions might be accessible to any logged-in user, regardless of their role or permissions. The presence of two external HTTP requests also warrants attention, as these could potentially be exploited if the external service is compromised or if the requests are not handled securely.

The taint analysis revealed no unsanitized paths, indicating that data flow is being managed with care. The vulnerability history is also clean, with no recorded CVEs, suggesting a mature and well-maintained codebase or a lack of past exploitation. Despite the clean history, the identified absence of capability checks and the external HTTP requests represent potential areas of risk that should be addressed to further harden the plugin's security. The plugin's strengths lie in its fundamental code security practices, but its weaknesses are in the broader permission model and external interactions.

Key Concerns

  • No capability checks on entry points
  • External HTTP requests present
Vulnerabilities
None known

Delivery Date for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Delivery Date for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
27 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped27 total outputs
Attack Surface

Delivery Date for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionplugins_loadedincludes\class-delivery_date_for_woocommerce.php:145
actionadmin_enqueue_scriptsincludes\class-delivery_date_for_woocommerce.php:159
actionadmin_enqueue_scriptsincludes\class-delivery_date_for_woocommerce.php:160
actionadmin_initincludes\class-delivery_date_for_woocommerce.php:161
actionadmin_menuincludes\class-delivery_date_for_woocommerce.php:162
actionwoocommerce_admin_order_data_after_billing_addressincludes\class-delivery_date_for_woocommerce.php:178
filtermanage_edit-shop_order_columnsincludes\class-delivery_date_for_woocommerce.php:179
actionmanage_shop_order_posts_custom_columnincludes\class-delivery_date_for_woocommerce.php:180
actionwoocommerce_saved_order_itemsincludes\class-delivery_date_for_woocommerce.php:181
actionwoocommerce_review_order_before_paymentincludes\class-delivery_date_for_woocommerce.php:182
actionwp_enqueue_scriptsincludes\class-delivery_date_for_woocommerce.php:200
actionwp_enqueue_scriptsincludes\class-delivery_date_for_woocommerce.php:201
actionwp_enqueue_scriptsincludes\class-delivery_date_for_woocommerce.php:202
actionwoocommerce_after_order_notesincludes\class-delivery_date_for_woocommerce.php:206
actionwoocommerce_checkout_processincludes\class-delivery_date_for_woocommerce.php:207
actionwoocommerce_checkout_update_order_metaincludes\class-delivery_date_for_woocommerce.php:208
actionwoocommerce_email_after_order_tableincludes\class-delivery_date_for_woocommerce.php:209
Maintenance & Trust

Delivery Date for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 30, 2025
PHP min version
Downloads9K

Community Trust

Rating80/100
Number of ratings12
Active installs100
Developer Profile

Delivery Date for WooCommerce Developer Profile

pixlogix

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Delivery Date for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/delivery-date-for-woocommerce/assets/css/style.css/wp-content/plugins/delivery-date-for-woocommerce/assets/js/script.js/wp-content/plugins/delivery-date-for-woocommerce/assets/js/frontend.js
Script Paths
/wp-content/plugins/delivery-date-for-woocommerce/assets/js/script.js/wp-content/plugins/delivery-date-for-woocommerce/assets/js/frontend.js
Version Parameters
delivery-date-for-woocommerce/assets/css/style.css?ver=delivery-date-for-woocommerce/assets/js/script.js?ver=delivery-date-for-woocommerce/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
delivery_date_fielddelivery_date
Data Attributes
data-delivery_date_enable
JS Globals
ddfw_frontend_params
FAQ

Frequently Asked Questions about Delivery Date for WooCommerce