FutureFeathers Order API Security & Risk Analysis

wordpress.org/plugins/futurefeathers-order-api

Send order data to external APIs automatically. Ideal for WooCommerce, SaaS, LMS, and CRM. Includes 25+ variables.

0 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Unknown
apiautomationintegrationrest-apiwebhook
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FutureFeathers Order API Safe to Use in 2026?

Generally Safe

Score 100/100

FutureFeathers Order API has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "futurefeathers-order-api" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of known vulnerabilities in its history, combined with robust code signals like 100% prepared SQL statements and a very high rate of properly escaped output (98%), indicates that the developers have implemented good security practices. The plugin also includes a respectable number of nonce and capability checks, further strengthening its defenses against common attacks.

While the static analysis reveals a low overall risk profile, a single AJAX handler represents the entire attack surface. Although no authentication checks are explicitly mentioned as missing for this handler, it's the only potential entry point. The presence of external HTTP requests warrants attention, though the analysis doesn't indicate any specific risks associated with them. The lack of any recorded vulnerabilities, critical taint flows, or dangerous functions is a significant positive. The plugin's vulnerability history is entirely clean, which suggests either a very well-written plugin or one that has not been subjected to extensive security testing or targeted attacks, a common scenario for less popular plugins.

In conclusion, "futurefeathers-order-api" v1.0.0 appears to be a secure plugin. Its strengths lie in its clean vulnerability history and adherence to secure coding practices like prepared statements and output escaping. The primary area for minor concern is the single AJAX handler, which, while not explicitly flagged as unprotected, represents the plugin's sole interactive entry point. Continued vigilance and security auditing are always recommended for any plugin, regardless of its current security standing.

Key Concerns

  • Single AJAX handler with no explicit auth check mention
  • External HTTP requests present
Vulnerabilities
None known

FutureFeathers Order API Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FutureFeathers Order API Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
48 escaped
Nonce Checks
4
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

98% escaped49 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ajax_test_api (futurefeathers-order-api.php:1153)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FutureFeathers Order API Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_ff_oteapi_testfuturefeathers-order-api.php:96
WordPress Hooks 15
actionbefore_woocommerce_initfuturefeathers-order-api.php:26
actionadmin_noticesfuturefeathers-order-api.php:44
actioninitfuturefeathers-order-api.php:73
actionadmin_menufuturefeathers-order-api.php:74
actionadmin_initfuturefeathers-order-api.php:75
actionadmin_enqueue_scriptsfuturefeathers-order-api.php:78
actionwoocommerce_order_status_completedfuturefeathers-order-api.php:81
actionwoocommerce_subscription_status_activefuturefeathers-order-api.php:82
actionwoocommerce_payment_completefuturefeathers-order-api.php:83
actionadd_meta_boxesfuturefeathers-order-api.php:86
actionsave_postfuturefeathers-order-api.php:87
actionadmin_noticesfuturefeathers-order-api.php:90
actionadmin_post_clear_api_logsfuturefeathers-order-api.php:93
filterredirect_post_locationfuturefeathers-order-api.php:513
filterredirect_post_locationfuturefeathers-order-api.php:528
Maintenance & Trust

FutureFeathers Order API Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads110

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FutureFeathers Order API Developer Profile

futurefeathers

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FutureFeathers Order API

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/futurefeathers-order-api/assets/css/ff-oteapi-admin.css/wp-content/plugins/futurefeathers-order-api/assets/js/ff-oteapi-admin.js
Script Paths
/wp-content/plugins/futurefeathers-order-api/assets/js/ff-oteapi-admin.js
Version Parameters
/wp-content/plugins/futurefeathers-order-api/assets/css/ff-oteapi-admin.css?ver=/wp-content/plugins/futurefeathers-order-api/assets/js/ff-oteapi-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ff-oteapi-settings
Data Attributes
name="ff_oteapi_enabled"id="api-settings-fields"id="ff_oteapi_auth_type"id="auth-token-field"id="show-variables-helper"id="variables-helper"+11 more
JS Globals
ajaxurl
FAQ

Frequently Asked Questions about FutureFeathers Order API