NavThemes – Export Single Order Data Woo-commerce Security & Risk Analysis

wordpress.org/plugins/navthemes-export-single-order-data-woo-commerce

This plugin simply let you download single order meta for third party shipping purpose.

0 active installs v1.0 PHP 5.2.4+ WP 3.0.1+ Updated Nov 30, 2018
woocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is NavThemes – Export Single Order Data Woo-commerce Safe to Use in 2026?

Generally Safe

Score 85/100

NavThemes – Export Single Order Data Woo-commerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of 'navthemes-export-single-order-data-woo-commerce' v1.0 indicates a generally good security posture with no critical vulnerabilities identified in the code. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by not using dangerous functions and employing prepared statements for all SQL queries. However, there are areas for improvement. The taint analysis revealed two flows with unsanitized paths, which, while not reaching critical or high severity, warrant attention as they indicate potential for unexpected behavior or unintended data handling. Additionally, the presence of file operations without explicit details on their sanitization and a concerning 50% of output escaping failures suggest potential for cross-site scripting (XSS) or information disclosure vulnerabilities. The plugin also lacks any nonce or capability checks, which is a significant weakness, especially if any of its functions were to become exposed via an entry point in the future. The lack of any recorded vulnerability history is a positive sign, suggesting a mature and stable codebase, but it does not negate the identified code-level risks.

Key Concerns

  • Flows with unsanitized paths detected
  • Half of output escaping checks failed
  • File operations performed
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

NavThemes – Export Single Order Data Woo-commerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NavThemes – Export Single Order Data Woo-commerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
navthemes_download_csv (navthemes-export-order-csv.php:63)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

NavThemes – Export Single Order Data Woo-commerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadd_meta_boxesnavthemes-export-order-csv.php:31
actionadmin_post_download_csvnavthemes-export-order-csv.php:61
Maintenance & Trust

NavThemes – Export Single Order Data Woo-commerce Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedNov 30, 2018
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

NavThemes – Export Single Order Data Woo-commerce Developer Profile

NavThemes

7 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NavThemes – Export Single Order Data Woo-commerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/navthemes-export-single-order-data-woo-commerce/style.css
Version Parameters
navthemes-export-single-order-data-woo-commerce/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
save_order
HTML Comments
Plugin Name: NavThemes - Export Single Order Data Woo-commerceDescription: This Plugin Simply Downloads All Data of an Order for shipping Purposes such as Seller Cloud.Author: NavThemesVersion: 1.0+8 more
Data Attributes
orderidaction=download_csv
Shortcode Output
<a class="button save_order button-primary" href="
FAQ

Frequently Asked Questions about NavThemes – Export Single Order Data Woo-commerce