
Manual Order For WooCommerce Security & Risk Analysis
wordpress.org/plugins/manual-orderSave your time by quickly creating orders for your woocommerce powered shops, and for existing or new users. Apply a flat discount or a coupon code in …
Is Manual Order For WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Manual Order For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The manual-order plugin v1.3.0 exhibits a generally strong security posture based on the provided static analysis. It boasts no known CVEs, a complete absence of SQL injection vulnerabilities due to prepared statements, and no file operations or external HTTP requests, which are common vectors for attacks. The attack surface is also minimal, with only two AJAX handlers and no direct REST API routes, shortcodes, or cron events. The presence of nonce checks is also a positive indicator of good security practices.
However, there are a few areas for concern. The most significant is the output escaping, which is only properly implemented in 47% of cases. This indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities, where unsanitized data could be injected and executed in users' browsers. Additionally, the plugin lacks any capability checks. While the AJAX handlers are currently protected, the absence of capability checks means that if an authentication bypass were to occur or if a future vulnerability were introduced that exposed these handlers, there would be no secondary layer of defense to prevent unauthorized actions.
Given the clean vulnerability history, it suggests the developers have been diligent in the past. Nonetheless, the identified output escaping issue and the lack of capability checks represent a tangible risk that should be addressed. The plugin's strengths lie in its lack of known exploits and its use of secure SQL practices, but the identified weaknesses, particularly the unescaped output, mean it is not entirely risk-free.
Key Concerns
- Insufficient output escaping
- Missing capability checks
Manual Order For WooCommerce Security Vulnerabilities
Manual Order For WooCommerce Code Analysis
Output Escaping
Manual Order For WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
Manual Order For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Manual Order For WooCommerce Alternatives
Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management
smart-manager-for-wp-e-commerce
WooCommerce Advanced Bulk Edit products, orders, & posts in an Excel-like sheet editor. Get advanced WooCommerce stock, pricing, & order management.
Order Approval for Woocommerce
order-approval-woocommerce
Approve or reject WooCommerce orders before payment. Manual order approval, email notifications, payment link, all gateways supported.
Phone Orders for WooCommerce
phone-orders-for-woocommerce
Easy way to take a manual/phone order in WooCommerce
Veeqo for WooCommerce
veeqo-for-woocommerce
Veeqo integrates with your WooCommerce stock with other online marketplaces and allows you to print shipping labels in one click.
Billbee – Auftragsabwicklung, Warenwirtschaft, Automatisierung
billbee-auftragsabwicklung-warenwirtschaft-automatisierung
Requires at least: 3.0.1 Tested up to: 5.9 Stable tag: 1.3 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.
Manual Order For WooCommerce Developer Profile
6 plugins · 3K total installs
How We Detect Manual Order For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/manual-order/assets/css/style.css/wp-content/plugins/manual-order/assets/js/mofw.js/wp-content/plugins/manual-order/assets/js/mofw.jsmanual-order/assets/css/style.css?ver=manual-order/assets/js/mofw.js?ver=HTML / DOM Fingerprints
mofw-order-formmofw_wrapmofw_generate_passworddata-noncedata-ajax-urldata-spdata-dcdata-ccdata-dtmofw