
Draft Order Control Security & Risk Analysis
wordpress.org/plugins/draft-order-controlControl when and how WooCommerce creates draft orders with granular settings for each creation condition.
Is Draft Order Control Safe to Use in 2026?
Generally Safe
Score 100/100Draft Order Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The draft-order-control plugin version 1.0.0 presents a generally good security posture, with no known vulnerabilities or critical taint flows identified. The absence of direct SQL queries without prepared statements and no file operations or external HTTP requests are positive indicators. The presence of nonce checks, while limited to two instances, suggests some awareness of preventing CSRF attacks. However, the significant concern lies in the extremely low percentage of properly escaped output (5%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data, if not properly sanitized before being displayed, could be injected into the page and executed by users' browsers. The lack of capability checks on entry points also means that authorization is not explicitly enforced on potentially sensitive actions, though the current attack surface is minimal.
Key Concerns
- Low output escaping percentage (5%)
- No capability checks on entry points
Draft Order Control Security Vulnerabilities
Draft Order Control Code Analysis
Output Escaping
Draft Order Control Attack Surface
WordPress Hooks 7
Maintenance & Trust
Draft Order Control Maintenance & Trust
Maintenance Signals
Community Trust
Draft Order Control Alternatives
WC Order Test
woo-order-test
Test your WooCommerce order process in seconds to ensure your checkout works correctly.
WC Direct Place Order Without Payment
wc-direct-place-order-without-payment
Plugin will customize checkout page and offers to direct place order without payment.
WhatsOrder – Instant Checkout for WooCommerce
whatsorder-instant-checkout-for-woocommerce
Enable instant WooCommerce checkout via WhatsApp with auto-generated invoices for seamless order processing.
Guest Order Assigner
guest-order-assigner
Automatically attaches WooCommerce guest orders to matching existing user accounts by billing email.
Avify
avify
Connect your WooCommerce account to Avify and send all your orders to one centralized inventory.
Draft Order Control Developer Profile
3 plugins · 20 total installs
How We Detect Draft Order Control
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/draft-order-control/admin/css/admin.css/wp-content/plugins/draft-order-control/admin/js/admin.js/wp-content/plugins/draft-order-control/admin/js/admin.jsdraft-order-control/admin/css/admin.css?ver=draft-order-control/admin/js/admin.js?ver=