Multi Order for WooCommerce Security & Risk Analysis

wordpress.org/plugins/multi-order-for-woocommerce

Split your orders into suborders.

80 active installs v1.5.1 PHP + WP 4.4+ Updated Jul 15, 2023
multipleordersplitsuborderwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multi Order for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Multi Order for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "multi-order-for-woocommerce" plugin version 1.5.1 exhibits a mixed security posture. On one hand, the absence of known CVEs and a clean vulnerability history suggest a generally stable and secure codebase over time. The fact that all SQL queries utilize prepared statements is a significant strength, mitigating risks of SQL injection. However, several concerning signals emerge from the static code analysis. The presence of the `unserialize` function without any apparent nonce or capability checks raises immediate red flags, as it can be a vector for deserialization vulnerabilities if user-controlled data is unserialized. Furthermore, a low percentage of properly escaped output (32%) indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, particularly in areas where user input might be displayed directly in the browser. The complete lack of any entry points being protected by authentication or permission checks, while the attack surface is reported as zero, is confusing and warrants further investigation to ensure no direct code execution paths exist outside of these categories.

Key Concerns

  • Presence of 'unserialize' without checks
  • Low output escaping rate (32%)
  • Bundled outdated library (Select2 v3.0.4)
Vulnerabilities
None known

Multi Order for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Multi Order for WooCommerce Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
2 prepared
Unescaped Output
23
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

unserialize$line_tax_data = unserialize( $line_tax_data );classes\multiorder\class-alg-mowc-order-manager.php:336
unserialize$line_tax_data = unserialize( $line_tax_data );classes\multiorder\class-alg-mowc-order-manager.php:376

Bundled Libraries

Select23.0.4

SQL Query Safety

100% prepared2 total queries

Output Escaping

32% escaped34 total outputs
Attack Surface

Multi Order for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 34
filterwoocommerce_get_settings_pagesclasses\multiorder\admin_settings\class-alg-mowc-admin-settings.php:26
actionadmin_enqueue_scriptsclasses\multiorder\admin_settings\class-alg-mowc-admin-settings.php:27
filterwoocommerce_get_sections_alg_mowcclasses\multiorder\admin_settings\class-alg-mowc-settings-section.php:33
actionwoocommerce_system_status_reportclasses\multiorder\class-alg-mowc-core.php:58
filterwoocommerce_my_account_my_orders_columnsclasses\multiorder\class-alg-mowc-order-columns.php:37
filterwoocommerce_account_orders_columnsclasses\multiorder\class-alg-mowc-order-columns.php:38
actionwoocommerce_my_account_my_orders_column_order-numberclasses\multiorder\class-alg-mowc-order-columns.php:44
filterwoocommerce_order_item_get_formatted_meta_dataclasses\multiorder\class-alg-mowc-order-item.php:23
actionwoocommerce_order_item_meta_startclasses\multiorder\class-alg-mowc-order-item.php:34
actionsave_postclasses\multiorder\class-alg-mowc-order-manager.php:27
actionwoocommerce_before_delete_order_itemclasses\multiorder\class-alg-mowc-order-manager.php:43
actionbefore_delete_postclasses\multiorder\class-alg-mowc-order-manager.php:46
actionwoocommerce_new_order_itemclasses\multiorder\class-alg-mowc-order-manager.php:49
actionwoocommerce_thankyouclasses\multiorder\class-alg-mowc-order-manager.php:52
actionwoocommerce_thankyouclasses\multiorder\class-alg-mowc-order-manager.php:53
actionwoocommerce_emailclasses\multiorder\class-alg-mowc-order-manager.php:62
actionpre_get_postsclasses\multiorder\class-alg-mowc-orders-search.php:25
filterwoocommerce_shortcode_order_tracking_order_idclasses\multiorder\class-alg-mowc-orders-search.php:28
filterget_search_queryclasses\multiorder\class-alg-mowc-orders-search.php:204
actionpre_get_postsclasses\multiorder\class-alg-mowc-orders-view.php:22
filterwoocommerce_order_data_store_cpt_get_orders_queryclasses\multiorder\class-alg-mowc-orders-view.php:25
filterwoocommerce_my_account_my_orders_queryclasses\multiorder\class-alg-mowc-orders-view.php:26
actionwoocommerce_view_orderclasses\multiorder\class-alg-mowc-orders-view.php:29
actionwoocommerce_view_orderclasses\multiorder\class-alg-mowc-orders-view.php:30
filterwoocommerce_order_numberclasses\multiorder\class-alg-mowc-orders-view.php:33
filterwoocommerce_reports_get_order_report_queryclasses\multiorder\class-alg-mowc-wc-report.php:26
filterwoocommerce_analytics_clauses_whereclasses\multiorder\class-alg-mowc-wc-report.php:29
actioncmb2_admin_initclasses\multiorder\meta_boxes\class-alg-mowc-multiorder-cmb.php:23
actioncmb2_admin_initclasses\multiorder\meta_boxes\class-alg-mowc-payment-status-cmb.php:27
actioninitclasses\multiorder\taxonomies\class-alg-mowc-payment-status.php:37
actionparent_fileclasses\multiorder\taxonomies\class-alg-mowc-payment-status.php:47
actionadmin_menuclasses\multiorder\taxonomies\class-alg-mowc-payment-status.php:48
actioninitclasses\wordpress\class-alg-mowc-wp-plugin.php:64
actionplugins_loadedmulti-order-for-woocommerce.php:101
Maintenance & Trust

Multi Order for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJul 15, 2023
PHP min version
Downloads10K

Community Trust

Rating92/100
Number of ratings9
Active installs80
Developer Profile

Multi Order for WooCommerce Developer Profile

WP Wham

9 plugins · 37K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
297 days
View full developer profile
Detection Fingerprints

How We Detect Multi Order for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multi-order-for-woocommerce/assets/css/multi-order-for-woocommerce.css/wp-content/plugins/multi-order-for-woocommerce/assets/js/multi-order-for-woocommerce.js/wp-content/plugins/multi-order-for-woocommerce/vendor/CMB2/CMB2/assets/css/cmb2.css/wp-content/plugins/multi-order-for-woocommerce/vendor/CMB2/CMB2/assets/js/cmb2.js/wp-content/plugins/multi-order-for-woocommerce/vendor/wpwham/cmb-field-select2/assets/css/cmb-field-select2.css/wp-content/plugins/multi-order-for-woocommerce/vendor/wpwham/cmb-field-select2/assets/js/cmb-field-select2.js
Script Paths
/wp-content/plugins/multi-order-for-woocommerce/assets/js/multi-order-for-woocommerce.js
Version Parameters
/wp-content/plugins/multi-order-for-woocommerce/assets/css/multi-order-for-woocommerce.css?ver=/wp-content/plugins/multi-order-for-woocommerce/assets/js/multi-order-for-woocommerce.js?ver=/wp-content/plugins/multi-order-for-woocommerce/vendor/CMB2/CMB2/assets/css/cmb2.css?ver=/wp-content/plugins/multi-order-for-woocommerce/vendor/CMB2/CMB2/assets/js/cmb2.js?ver=/wp-content/plugins/multi-order-for-woocommerce/vendor/wpwham/cmb-field-select2/assets/css/cmb-field-select2.css?ver=/wp-content/plugins/multi-order-for-woocommerce/vendor/wpwham/cmb-field-select2/assets/js/cmb-field-select2.js?ver=

HTML / DOM Fingerprints

CSS Classes
alg-mowc-settings-section
HTML Comments
Multi Order for WooCommerce - Core ClassMulti order for WooCommerce - Core ClassMulti order for WooCommerce - WP Plugin Base ClassMulti order for WooCommerce - Order Manager Class+15 more
Data Attributes
data-export-label="Multi Order Settings"
FAQ

Frequently Asked Questions about Multi Order for WooCommerce