MultiOrder Sync For WooCommerce Security & Risk Analysis

wordpress.org/plugins/emw-multiple-order-management

A plugin to manage and link multiple WooCommerce orders based on custom criteria.

0 active installs v1.2.3 PHP 7.2+ WP 5.0+ Updated Unknown
link-ordersmultipleordersyncwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MultiOrder Sync For WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

MultiOrder Sync For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "emw-multiple-order-management" plugin v1.2.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good practices by implementing thorough authentication and permission checks on all identified entry points, including AJAX handlers and REST API routes. The high percentage of prepared statements for SQL queries and properly escaped output further suggests a commitment to secure coding.

Notably, there are no identified critical or high severity taint flows, indicating that user input is generally handled safely and not leading to direct code execution or sensitive data leakage. The absence of any known CVEs, past or present, is a significant positive indicator of the plugin's security. The plugin also avoids bundling external libraries, which can sometimes introduce vulnerabilities if not maintained.

While the plugin shows excellent security fundamentals, the sheer number of SQL queries (49) and file operations (2) present a larger area for potential oversight, even with high prepared statement usage. However, given the overall lack of critical findings, the risk associated with these is currently assessed as low. The plugin's strengths in authentication, sanitization, and lack of historical vulnerabilities outweigh any minor concerns.

Vulnerabilities
None known

MultiOrder Sync For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MultiOrder Sync For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
41 prepared
Unescaped Output
11
297 escaped
Nonce Checks
14
Capability Checks
4
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

84% prepared49 total queries

Output Escaping

96% escaped308 total outputs
Data Flows
All sanitized

Data Flow Analysis

13 flows
ajax_get_group_details (includes\class-emw-mom-admin.php:321)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MultiOrder Sync For WooCommerce Attack Surface

Entry Points17
Unprotected0

AJAX Handlers 9

authwp_ajax_emw_mom_get_group_detailsincludes\class-emw-mom-admin.php:57
authwp_ajax_emw_mom_link_ordersincludes\class-emw-mom-admin.php:58
authwp_ajax_emw_mom_unlink_ordersincludes\class-emw-mom-admin.php:59
authwp_ajax_emw_mom_regroup_groupincludes\class-emw-mom-admin.php:60
authwp_ajax_emw_mom_get_linked_order_detailsincludes\class-emw-mom-admin.php:61
authwp_ajax_emw_mom_get_group_detailstrunk\includes\class-emw-mom-admin.php:56
authwp_ajax_emw_mom_link_orderstrunk\includes\class-emw-mom-admin.php:57
authwp_ajax_emw_mom_unlink_orderstrunk\includes\class-emw-mom-admin.php:58
authwp_ajax_emw_mom_get_linked_order_detailstrunk\includes\class-emw-mom-admin.php:59

REST API Routes 8

GET/wp-json/emw-mom/v1/ordersincludes\class-emw-mom-rest-api.php:55
GET/wp-json/emw-mom/v1/multiple-order-group/(?P<order_id>\d+)includes\class-emw-mom-rest-api.php:65
GET/wp-json/emw-mom/v1/orders/(?P<order_id>\d+)/force-regroupincludes\class-emw-mom-rest-api.php:83
GET/wp-json/emw-mom/v1/groups/(?P<group_id>\d+)/force-unlinkincludes\class-emw-mom-rest-api.php:93
GET/wp-json/emw-mom/v1/orders/(?P<order_id>\d+)/historyincludes\class-emw-mom-rest-api.php:103
GET/wp-json/emw-mom/v1/groups/(?P<group_id>\d+)/historyincludes\class-emw-mom-rest-api.php:113
GET/wp-json/emw-mom/v1/orderstrunk\includes\class-emw-mom-rest-api.php:55
GET/wp-json/emw-mom/v1/multiple-order-group/(?P<order_id>\d+)trunk\includes\class-emw-mom-rest-api.php:65
WordPress Hooks 25
actionadmin_noticesemw-multiple-order-management.php:39
actionplugins_loadedemw-multiple-order-management.php:47
actionadmin_menuincludes\class-emw-mom-admin.php:48
actionadmin_enqueue_scriptsincludes\class-emw-mom-admin.php:55
actionadmin_post_emw_mom_rebuild_groupsincludes\class-emw-mom-admin.php:56
actionadd_meta_boxesincludes\class-emw-mom-admin.php:62
actionwoocommerce_order_status_changedincludes\class-emw-mom-email-notifier.php:39
actionwoocommerce_new_orderincludes\class-emw-mom-handler.php:44
actionwoocommerce_order_status_changedincludes\class-emw-mom-handler.php:45
actionplugins_loadedincludes\class-emw-mom-loader.php:43
actionadmin_initincludes\class-emw-mom-loader.php:44
actionrest_api_initincludes\class-emw-mom-rest-api.php:48
actionadmin_initincludes\class-emw-mom-settings.php:23
actionadmin_noticestrunk\emw-multiple-order-management.php:39
actionplugins_loadedtrunk\emw-multiple-order-management.php:47
actionadmin_menutrunk\includes\class-emw-mom-admin.php:48
actionadmin_enqueue_scriptstrunk\includes\class-emw-mom-admin.php:55
actionadd_meta_boxestrunk\includes\class-emw-mom-admin.php:60
actionwoocommerce_order_status_changedtrunk\includes\class-emw-mom-email-notifier.php:39
actionwoocommerce_new_ordertrunk\includes\class-emw-mom-handler.php:23
actionwoocommerce_order_status_changedtrunk\includes\class-emw-mom-handler.php:24
actionplugins_loadedtrunk\includes\class-emw-mom-loader.php:43
actionadmin_inittrunk\includes\class-emw-mom-loader.php:44
actionrest_api_inittrunk\includes\class-emw-mom-rest-api.php:48
actionadmin_inittrunk\includes\class-emw-mom-settings.php:23
Maintenance & Trust

MultiOrder Sync For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.2
Downloads436

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

MultiOrder Sync For WooCommerce Developer Profile

Kiran M S

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MultiOrder Sync For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/emw-multiple-order-management/assets/css/admin-settings.css/wp-content/plugins/emw-multiple-order-management/assets/css/order-edit.css/wp-content/plugins/emw-multiple-order-management/assets/js/admin-settings.js
Script Paths
/wp-content/plugins/emw-multiple-order-management/assets/js/admin-settings.js
Version Parameters
emw-multiple-order-management/assets/css/admin-settings.css?ver=emw-multiple-order-management/assets/css/order-edit.css?ver=emw-multiple-order-management/assets/js/admin-settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
emw-mom-main-pageemw-mom-group-orders-pageemw-mom-rebuild-pageemw-mom-settings-pageemw-mom-order-meta-boxemw-mom-grouped-orders-tableemw-mom-order-group-rowemw-mom-linked-orders-list
Data Attributes
data-group-id
JS Globals
emw_mom_admin
FAQ

Frequently Asked Questions about MultiOrder Sync For WooCommerce