
Do Deliver Orders Security & Risk Analysis
wordpress.org/plugins/do-deliver-ordersStreamline WooCommerce order delivery with Do Deliver integration. Note: This plugin connects to a third-partyr external service (Do Deliver).
Is Do Deliver Orders Safe to Use in 2026?
Generally Safe
Score 100/100Do Deliver Orders has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "do-deliver-orders" plugin version 1.9 exhibits a generally good security posture with several positive indicators. The absence of known CVEs and no recorded vulnerabilities in its history suggest a well-maintained and secure codebase. The static analysis reveals a strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and a high percentage (94%) of output properly escaped. Furthermore, the plugin doesn't bundle any external libraries, mitigating risks associated with outdated dependencies. The taint analysis also shows no critical or high severity unsanitized flows, which is a significant strength.
However, there are notable areas of concern, primarily stemming from the attack surface. The plugin exposes 22 AJAX handlers, with a significant two of them lacking any authentication checks. This represents a potential entry point for attackers to trigger unintended actions within the plugin without proper authorization. While the overall code quality is high, these unprotected AJAX endpoints introduce a tangible risk that needs immediate attention. The absence of capability checks is also a weakness, meaning even if AJAX handlers were authenticated, they might not be properly authorized for specific user roles.
In conclusion, "do-deliver-orders" v1.9 is a plugin with many security strengths, particularly in its handling of database interactions and output. The lack of historical vulnerabilities is a strong positive. Nevertheless, the two unprotected AJAX handlers are a critical flaw that overshadows these positives and significantly elevates the risk profile. Addressing these unprotected entry points should be the highest priority to improve the plugin's overall security.
Key Concerns
- AJAX handlers without auth checks
- No capability checks found
Do Deliver Orders Security Vulnerabilities
Do Deliver Orders Code Analysis
Output Escaping
Data Flow Analysis
Do Deliver Orders Attack Surface
AJAX Handlers 22
WordPress Hooks 40
Maintenance & Trust
Do Deliver Orders Maintenance & Trust
Maintenance Signals
Community Trust
Do Deliver Orders Alternatives
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
SnappBox
snappbox
The SnappBox WordPress plugin offers a fast and simple way to register and manage order deliveries. By installing this plugin, you can send your store …
Bijak
bijak
Add smart freight shipping to WooCommerce with live rate estimates and order integration via the Bijak API.
CODPartner
codpartner
A Platform that covers all logistics needs for COD e-commerce sellers.
LlegoYa Envíos
llegoya-envios
Este plugin permite a WooCommerce calcular el costo de envío mediante la API de LlegoYa y enviar los detalles del pedido a un servicio externo.
Do Deliver Orders Developer Profile
1 plugin · 0 total installs
How We Detect Do Deliver Orders
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/do-deliver-orders/css/fontwesome/all.min.css/wp-content/plugins/do-deliver-orders/css/style.css/wp-content/plugins/do-deliver-orders/css/dd-wc-order.css/wp-content/plugins/do-deliver-orders/dd-icon.png/wp-content/plugins/do-deliver-orders/dd-icon-deliver.pngdo-deliver-orders/css/fontwesome/all.min.css?ver=do-deliver-orders/css/style.css?ver=do-deliver-orders/css/dd-wc-order.css?ver=HTML / DOM Fingerprints
order-statusstatus-booked-ddstatus-cancelled-ddstatus-shipped-ddstatus-delivered-ddstatus-refused-ddstatus-returned-ddtimeline-container+7 moredata-tracking-iddata-customer-iddata-customer-namedata-customer-phonedata-customer-addressdata-customer-city+4 moredodeor_vars