DS Woocommerce Order Email Export Security & Risk Analysis

wordpress.org/plugins/ds-woocommerce-order-email-export

An essential plugin to export customer's emails and other information from admin panel.

40 active installs v1.0 PHP + WP 3.5+ Updated Dec 23, 2016
billing-addresscustomershipping-addresswoocommercewoocommerce-customer-emails-export
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DS Woocommerce Order Email Export Safe to Use in 2026?

Generally Safe

Score 85/100

DS Woocommerce Order Email Export has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "ds-woocommerce-order-email-export" v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any recorded CVEs and the minimal number of identified code signals, particularly a lack of dangerous functions and external HTTP requests, suggest a commitment to secure coding practices. The plugin also demonstrates some basic security checks like a nonce check, which is a positive sign. However, there are significant areas of concern that require attention. The presence of a SQL query without prepared statements is a critical risk that could lead to SQL injection vulnerabilities, especially given the absence of other entry points to exploit. Furthermore, the low percentage of properly escaped output indicates a potential for cross-site scripting (XSS) vulnerabilities, which could allow attackers to inject malicious scripts into the website. The single flow with an unsanitized path, although not flagged as critical or high severity, also warrants investigation as it could represent an indirect vulnerability. The vulnerability history of zero known CVEs is excellent, but it should not lead to complacency, especially with the identified risks in the current version. The plugin's strength lies in its limited attack surface, but its weaknesses in SQL sanitization and output escaping present tangible security threats.

Key Concerns

  • SQL queries without prepared statements
  • Low percentage of properly escaped output
  • Flows with unsanitized paths
  • No capability checks
Vulnerabilities
None known

DS Woocommerce Order Email Export Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DS Woocommerce Order Email Export Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
4
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

20% escaped5 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
get_settings (index.php:305)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

DS Woocommerce Order Email Export Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterwoocommerce_settings_tabs_arrayindex.php:30
actionwoocommerce_settings_tabs_settings_tab_demoindex.php:31
actioninitindex.php:62
actionadmin_menuindex.php:63
Maintenance & Trust

DS Woocommerce Order Email Export Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedDec 23, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

DS Woocommerce Order Email Export Developer Profile

DotsquaresLtd

6 plugins · 110 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DS Woocommerce Order Email Export

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ds-woocommerce-order-email-export/css/jquery-ui.css/wp-content/plugins/ds-woocommerce-order-email-export/css/customstyle.css/wp-content/plugins/ds-woocommerce-order-email-export/js/woo-order-emails.js
Script Paths
/wp-content/plugins/ds-woocommerce-order-email-export/js/woo-order-emails.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about DS Woocommerce Order Email Export