Easy Product Delivery Date Security & Risk Analysis

wordpress.org/plugins/easy-product-delivery-date

A plugin to show product delivery estimated day & date in product page, cart page, checkout page, order confirmation page, admin order list and in …

10 active installs v1.0.0 PHP 7.0+ WP 4.7+ Updated Mar 6, 2021
date-woocommerce-delivery-datedelivery-dateeasy-product-deliveryshipping-dateshipping-delivery-date
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Easy Product Delivery Date Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Product Delivery Date has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "easy-product-delivery-date" plugin version 1.0.0 demonstrates a generally strong security posture based on the provided static analysis. The plugin has no recorded vulnerabilities, which is a significant positive indicator. Furthermore, the code signals are largely reassuring: there are no dangerous functions, all SQL queries utilize prepared statements, file operations and external HTTP requests are absent, and a high percentage of output is properly escaped. The presence of nonce checks and the bundling of Select2 are also good practices.

However, there are some areas for potential concern. The analysis indicates zero capability checks on its two AJAX handlers. While the total number of entry points is low and none are explicitly noted as unprotected in the attack surface metrics, the absence of capability checks on AJAX endpoints means that any user, regardless of their role or permissions, could potentially interact with these handlers. While no taint flows were found to be unsanitized, this is based on zero analyzed flows, which might not be exhaustive.

In conclusion, the plugin is off to a promising start with a clean vulnerability history and good internal code practices. The primary area for improvement is the implementation of capability checks on the AJAX handlers to ensure that only authorized users can trigger these functionalities. This would further harden the plugin against potential privilege escalation or unauthorized actions.

Key Concerns

  • AJAX handlers without capability checks
Vulnerabilities
None known

Easy Product Delivery Date Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Product Delivery Date Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Easy Product Delivery Date Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
29 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

97% escaped30 total outputs
Attack Surface

Easy Product Delivery Date Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_woopdd_get_messsage_by_variationadmin/WooCommerce/Messages/InVariableProduct.php:14
noprivwp_ajax_woopdd_get_messsage_by_variationadmin/WooCommerce/Messages/InVariableProduct.php:15
WordPress Hooks 23
actionadmin_menuadmin/Settings.php:10
actionadmin_initadmin/Settings.php:11
actionwp_headadmin/Settings.php:12
filterwoocommerce_add_cart_item_dataadmin/WooCommerce/Data/InCartItem.php:12
actionwoocommerce_checkout_create_order_line_itemadmin/WooCommerce/Data/InOrderItem.php:7
filterwoocommerce_product_data_tabsadmin/WooCommerce/InProductTab.php:7
filterwoocommerce_product_data_panelsadmin/WooCommerce/InProductTab.php:8
actionwoocommerce_process_product_metaadmin/WooCommerce/InProductTab.php:9
actionwoocommerce_product_after_variable_attributesadmin/WooCommerce/InProductVariation.php:7
actionwoocommerce_save_product_variationadmin/WooCommerce/InProductVariation.php:8
filterwoocommerce_get_item_dataadmin/WooCommerce/Messages/InCartPage.php:7
filterwoocommerce_order_item_nameadmin/WooCommerce/Messages/InEmail.php:7
actionwoocommerce_before_add_to_cart_buttonadmin/WooCommerce/Messages/InSimpleProduct.php:25
actionwoocommerce_after_add_to_cart_buttonadmin/WooCommerce/Messages/InSimpleProduct.php:28
actionwoocommerce_product_meta_startadmin/WooCommerce/Messages/InSimpleProduct.php:31
actionwoocommerce_product_meta_endadmin/WooCommerce/Messages/InSimpleProduct.php:34
actionwoocommerce_before_add_to_cart_buttonadmin/WooCommerce/Messages/InSimpleProduct.php:37
actionplugins_loadedeasy-product-delivery-date.php:47
actionwp_enqueue_scriptsincludes/Assets.php:17
actionwp_enqueue_scriptsincludes/Assets.php:18
actionadmin_enqueue_scriptsincludes/Assets.php:27
actionadmin_enqueue_scriptsincludes/Assets.php:28
actionin_plugin_update_message-easy-product-delivery-date/easy-product-delivery-date.phpincludes/PluginUpdater.php:42
Maintenance & Trust

Easy Product Delivery Date Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedMar 6, 2021
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Easy Product Delivery Date Developer Profile

MD. Rabiul Islam Robi

3 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Product Delivery Date

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-product-delivery-date/assets/js/admin.js/wp-content/plugins/easy-product-delivery-date/assets/js/select2.min.js/wp-content/plugins/easy-product-delivery-date/assets/css/admin.css/wp-content/plugins/easy-product-delivery-date/assets/css/select2.min.css/wp-content/plugins/easy-product-delivery-date/assets/js/public.js/wp-content/plugins/easy-product-delivery-date/assets/css/public.css
Script Paths
/wp-content/plugins/easy-product-delivery-date/assets/js/admin.js/wp-content/plugins/easy-product-delivery-date/assets/js/select2.min.js/wp-content/plugins/easy-product-delivery-date/assets/js/public.js
Version Parameters
easy-product-delivery-date/assets/js/admin.js?ver=easy-product-delivery-date/assets/js/select2.min.js?ver=easy-product-delivery-date/assets/css/admin.css?ver=easy-product-delivery-date/assets/css/select2.min.css?ver=easy-product-delivery-date/assets/js/public.js?ver=easy-product-delivery-date/assets/css/public.css?ver=

HTML / DOM Fingerprints

CSS Classes
woopdd-wrap
JS Globals
woopddPublic
FAQ

Frequently Asked Questions about Easy Product Delivery Date