
EDDV Notices for WooCommerce Security & Risk Analysis
wordpress.org/plugins/eddv-noticesDisplay Estimated Delivery Date ranges or a Vacation Notice across WooCommerce pages and emails with flexible templates and automatic mode switching.
Is EDDV Notices for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100EDDV Notices for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "eddv-notices" v1.0 exhibits a generally strong security posture based on the static analysis. The absence of known vulnerabilities in its history is a significant positive. The code analysis reveals a clean bill of health with no dangerous functions, file operations, or external HTTP requests. Crucially, all SQL queries are prepared, and a high percentage of output is properly escaped, minimizing risks of injection attacks and XSS. The limited attack surface is also a good sign.
However, the complete lack of nonce checks and capability checks is a significant concern. While the static analysis shows no direct entry points that are *unprotected*, this doesn't mean that potential vulnerabilities within existing functionalities couldn't be exploited without proper authorization. The absence of taint analysis results and the reported zero flows with unsanitized paths are positive, but the lack of nonce/capability checks means that even if no direct taint is found, attackers could potentially manipulate existing features if they can trigger them without proper authorization.
In conclusion, "eddv-notices" v1.0 has implemented several key security best practices, particularly concerning SQL injection and output escaping. The absence of historical vulnerabilities is reassuring. The primary weakness lies in the complete omission of nonce and capability checks, which opens up the possibility of authorization bypasses and privilege escalation if any functionality can be triggered inappropriately. Addressing this would significantly bolster the plugin's security.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Unescaped output detected
EDDV Notices for WooCommerce Security Vulnerabilities
EDDV Notices for WooCommerce Code Analysis
Output Escaping
EDDV Notices for WooCommerce Attack Surface
WordPress Hooks 8
Maintenance & Trust
EDDV Notices for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
EDDV Notices for WooCommerce Alternatives
Estimated Delivery Date Per Product For Woocommerce
estimated-delivery-date-per-product-for-woocommerce
Estimated Shipping Date Per Product For WoocommerceThis Plugin allow you to Display Estimated Delivery Date or Shipping Date Per Product.
Estimate delivery per Product for Woocommerce
estimate-delivery-per-product-for-woocommerce
HELP YOUR CUSTOMERS TO DECIDE IF THEY WILL BUY YOUR PRODUCTS!
AnCode — Estimated Delivery Date for WooCommerce
ancode-estimated-delivery-date-for-woocommerce
Display estimated delivery dates automatically on WooCommerce product pages and emails — supports weekends, holidays, and full customization.
Order Delivery Date for WooCommerce
order-delivery-date-for-woocommerce
Let customers choose delivery dates & times on checkout. Simplify delivery management by blocking holidays & setting max deliveries per day.
WPC Estimated Delivery Date for WooCommerce
wpc-estimated-delivery-date
WPC Estimated Delivery Date allows you to establish and personalize delivery times for each product available in your store on several levels.
EDDV Notices for WooCommerce Developer Profile
4 plugins · 1K total installs
How We Detect EDDV Notices for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.