DevNajmus OneClick Order Popup – for WooCommerce Security & Risk Analysis

wordpress.org/plugins/devnajmus-oneclick-order-popup-for-woocommerce

Fast WooCommerce checkout through AJAX-powered popup with variable product support and direct ordering.

0 active installs v1.1.0 PHP 7.4+ WP 5.5+ Updated Jan 13, 2026
direct-buyone-click-orderorder-popuppopup-checkoutquick-checkout
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DevNajmus OneClick Order Popup – for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

DevNajmus OneClick Order Popup – for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "devnajmus-oneclick-order-popup-for-woocommerce" plugin version 1.1.0 exhibits a strong security posture based on the provided static analysis. All identified entry points, specifically the 6 AJAX handlers, are secured with either nonce or capability checks, and there are no unprotected REST API routes, shortcodes, or cron events. The code demonstrates excellent security practices by using prepared statements for all SQL queries and ensuring 100% of outputs are properly escaped. The absence of any identified dangerous functions, file operations (beyond a single, likely benign one), external HTTP requests, or taint flows indicates a low risk of common web vulnerabilities like SQL injection, cross-site scripting (XSS), or remote code execution (RCE). The plugin's vulnerability history is also clean, with zero recorded CVEs, suggesting a commitment to secure development or a lack of prior exploitation. Overall, the plugin appears to be well-secured with robust protection mechanisms in place. The only area that could potentially raise a minor concern is the presence of file operations, which, while not flagged as a risk here, warrants a quick review in a deeper audit to ensure no sensitive files are being accessed or manipulated insecurely. However, based solely on the provided data, the plugin is in a very good security state.

Vulnerabilities
None known

DevNajmus OneClick Order Popup – for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DevNajmus OneClick Order Popup – for WooCommerce Release Timeline

v1.1.0Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

DevNajmus OneClick Order Popup – for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
113 escaped
Nonce Checks
3
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped113 total outputs
Attack Surface

DevNajmus OneClick Order Popup – for WooCommerce Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_DOPW_process_orderincludes/class-dopw-ajax.php:27
noprivwp_ajax_DOPW_process_orderincludes/class-dopw-ajax.php:28
authwp_ajax_DOPW_get_variationsincludes/class-dopw-ajax.php:29
noprivwp_ajax_DOPW_get_variationsincludes/class-dopw-ajax.php:30
authwp_ajax_DOPW_get_gateway_fieldsincludes/class-dopw-ajax.php:31
noprivwp_ajax_DOPW_get_gateway_fieldsincludes/class-dopw-ajax.php:32
WordPress Hooks 10
actionadmin_noticesdevnajmus-oneclick-order-popup-for-woocommerce.php:31
actionwp_enqueue_scriptsincludes/class-dopw-admin.php:27
actionadmin_enqueue_scriptsincludes/class-dopw-admin.php:28
actionadmin_menuincludes/class-dopw-admin.php:29
actionadmin_initincludes/class-dopw-admin.php:30
actionwp_enqueue_scriptsincludes/class-dopw-frontend.php:28
actionwp_enqueue_scriptsincludes/class-dopw-frontend.php:29
actionwp_footerincludes/class-dopw-frontend.php:30
actionwoocommerce_after_shop_loop_itemincludes/class-dopw-frontend.php:33
actionwoocommerce_after_add_to_cart_buttonincludes/class-dopw-frontend.php:34
Maintenance & Trust

DevNajmus OneClick Order Popup – for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 13, 2026
PHP min version7.4
Downloads309

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

DevNajmus OneClick Order Popup – for WooCommerce Developer Profile

MD NAJMUS SHADAT

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DevNajmus OneClick Order Popup – for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/devnajmus-oneclick-order-popup-for-woocommerce/assets/css/quickorder.css/wp-content/plugins/devnajmus-oneclick-order-popup-for-woocommerce/assets/css/admin.css/wp-content/plugins/devnajmus-oneclick-order-popup-for-woocommerce/assets/js/admin.js
Version Parameters
devnajmus-oneclick-order-popup-for-woocommerce/assets/css/quickorder.css?ver=devnajmus-oneclick-order-popup-for-woocommerce/assets/css/admin.css?ver=devnajmus-oneclick-order-popup-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
DOPW-color-field
HTML Comments
<!-- DevNajmus OneClick Order Popup --><!-- Admin specific functionality of the plugin --><!-- Plugin settings page -->
Data Attributes
data-dopw-product-iddata-dopw-quantitydata-dopw-variation-iddata-dopw-add-to-cart-urldata-dopw-product-id
JS Globals
DOPW_VERSION
FAQ

Frequently Asked Questions about DevNajmus OneClick Order Popup – for WooCommerce