Easy Order View Security & Risk Analysis

wordpress.org/plugins/easy-order-view

A beautiful way to manage your woocommerce orders.

0 active installs v1.0.0 PHP 7.0+ WP 5.2+ Updated Sep 12, 2022
newordernotificationorderwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Order View Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Order View has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "easy-order-view" plugin v1.0.0 exhibits a generally good security posture with several positive indicators. The absence of known CVEs and a clean vulnerability history suggests a commitment to security or a lack of past exploitable issues. Furthermore, the plugin demonstrates good practices by implementing nonce checks and capability checks on its entry points, and a high percentage of its code signals involve proper output escaping and prepared statements in SQL queries. The limited attack surface, with all AJAX handlers protected, is also a strength.

However, there are areas of concern. The taint analysis reveals four flows with unsanitized paths, which, while not classified as critical or high severity, represent potential vectors for unexpected behavior or information leakage if exploited. The presence of file operations and external HTTP requests, though not inherently risky, warrants careful consideration in the context of unsanitized inputs. The fact that only 50% of SQL queries use prepared statements is a notable weakness, as raw SQL queries can be susceptible to injection attacks if not handled with extreme care.

In conclusion, the plugin has a solid foundation with strong defensive mechanisms in place. The lack of known vulnerabilities is a significant positive. Nonetheless, the identified unsanitized taint flows and the moderate use of prepared statements in SQL queries indicate potential areas for improvement and vigilance. The bundled Freemius library should also be monitored for updates.

Key Concerns

  • Flows with unsanitized paths detected
  • Only 50% of SQL queries use prepared statements
  • Less than half of outputs properly escaped
  • Bundled Freemius v1.0 library detected
Vulnerabilities
None known

Easy Order View Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Order View Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Easy Order View Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
463
440 escaped
Nonce Checks
8
Capability Checks
5
File Operations
1
External Requests
2
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

50% prepared4 total queries

Output Escaping

49% escaped903 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

7 flows4 with unsanitized paths
install_plugin_information (includes\library\includes\fs-plugin-info-dialog.php:928)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Easy Order View Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_eov_order_status_changeincludes\functions.php:8
authwp_ajax_eov_order_status_change_to_completeincludes\functions.php:9
authwp_ajax_eov_order_status_change_to_randomincludes\functions.php:10
authwp_ajax_eov_check_new_orderincludes\functions.php:11
authwp_ajax_eov_order_saves_order_notesincludes\functions.php:12
authwp_ajax_eov_check_more_preparing_ordersincludes\functions.php:14
WordPress Hooks 31
filterplugin_action_linkseasy-order-view.php:119
actionadmin_initeasy-order-view.php:125
actionadmin_noticeseasy-order-view.php:132
filteradmin_body_classincludes\class-easy-order-view-store.php:100
actionadmin_menuincludes\class-easy-order-view-store.php:103
actioninitincludes\class-easy-order-view-store.php:104
filterwc_order_statusesincludes\class-easy-order-view-store.php:105
actionadmin_enqueue_scriptsincludes\functions.php:7
actionadmin_footerincludes\library\includes\class-fs-logger.php:107
actionwp_footerincludes\library\includes\class-fs-logger.php:109
filterplugins_apiincludes\library\includes\class-fs-plugin-updater.php:83
actionadmin_headincludes\library\includes\class-fs-plugin-updater.php:106
filterhttp_request_host_is_externalincludes\library\includes\class-fs-plugin-updater.php:110
filterupgrader_post_installincludes\library\includes\class-fs-plugin-updater.php:118
filterupgrader_pre_installincludes\library\includes\class-fs-plugin-updater.php:121
filterupgrader_source_selectionincludes\library\includes\class-fs-plugin-updater.php:122
filterwp_prepare_themes_for_jsincludes\library\includes\class-fs-plugin-updater.php:125
actionadmin_footerincludes\library\includes\class-fs-plugin-updater.php:142
filterpre_set_site_transient_update_pluginsincludes\library\includes\class-fs-plugin-updater.php:249
filterpre_set_site_transient_update_themesincludes\library\includes\class-fs-plugin-updater.php:254
filterupgrader_source_selectionincludes\library\includes\class-fs-plugin-updater.php:1342
filterdebug_bar_panelsincludes\library\includes\debug\debug-bar-start.php:51
filterdebug_bar_statusesincludes\library\includes\debug\debug-bar-start.php:52
actioninstall_plugins_pre_plugin-informationincludes\library\includes\fs-plugin-info-dialog.php:66
filterfs_plugins_apiincludes\library\includes\fs-plugin-info-dialog.php:69
actionadmin_footerincludes\library\includes\managers\class-fs-admin-notice-manager.php:208
actionnetwork_admin_noticesincludes\library\includes\managers\class-fs-admin-notice-manager.php:362
actionadmin_noticesincludes\library\includes\managers\class-fs-admin-notice-manager.php:363
actionadmin_enqueue_scriptsincludes\library\includes\managers\class-fs-admin-notice-manager.php:366
actionhttp_api_curlincludes\library\includes\sdk\FreemiusWordPress.php:445
actionadmin_footerincludes\library\templates\account.php:83
Maintenance & Trust

Easy Order View Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 12, 2022
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Easy Order View Developer Profile

Mozzo Plugins

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Order View

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-order-view/css/style.css/wp-content/plugins/easy-order-view/js/script.js
Script Paths
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css/wp-content/plugins/easy-order-view/js/script.js
Version Parameters
/wp-content/plugins/easy-order-view/css/style.css?ver=/wp-content/plugins/easy-order-view/js/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-easy-order-view
JS Globals
eovScriptData
FAQ

Frequently Asked Questions about Easy Order View