NG-WooCommerce-MoeDelo Security & Risk Analysis

wordpress.org/plugins/ng-woo-moedelo-org-integration

Allows to issue invoices via https://moedelo.org/ cloud

0 active installs v1.5.1 PHP 5.6+ WP 3.6+ Updated Apr 30, 2020
moedelomoedelo-orgpayment-gatewaywoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NG-WooCommerce-MoeDelo Safe to Use in 2026?

Generally Safe

Score 85/100

NG-WooCommerce-MoeDelo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin 'ng-woo-moedelo-org-integration' version 1.5.1 exhibits a seemingly robust security posture based on the provided static analysis. There are no detected AJAX handlers, REST API routes, shortcodes, or cron events that could serve as direct entry points into the plugin's functionality. Furthermore, the analysis indicates no dangerous functions are utilized, all SQL queries are properly prepared, and the majority of output is escaped. The absence of file operations and the controlled use of external HTTP requests also contribute positively to its security.

However, several areas raise concerns despite the lack of critical vulnerabilities in the static analysis. The complete absence of nonce checks and capability checks is a significant weakness. While the attack surface appears to be zero, this could be a consequence of the limited scope of the analysis or the plugin's design, rather than an inherent security feature. The presence of external HTTP requests without clear authentication or sanitization is another potential area of risk that warrants further investigation. The lack of any recorded vulnerabilities in its history is a positive indicator, suggesting the developers may be proactive or that the plugin has not been a target. Nevertheless, the reliance on external services and the absence of fundamental WordPress security checks like nonces and capabilities leave it susceptible to various attacks if even a minor vulnerability exists elsewhere or if the external service is compromised.

In conclusion, while 'ng-woo-moedelo-org-integration' v1.5.1 benefits from clean code regarding SQL and a relatively small attack surface, the complete lack of nonce and capability checks, coupled with the potential risks associated with external HTTP requests, presents significant security gaps. The vulnerability history being clear is encouraging, but it does not negate the inherent risks introduced by these missing security controls. The plugin's overall security is moderate, with notable areas for improvement to mitigate potential threats.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • External HTTP requests without clear checks
  • Output escaping is not 100% proper
Vulnerabilities
None known

NG-WooCommerce-MoeDelo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

NG-WooCommerce-MoeDelo Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

NG-WooCommerce-MoeDelo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

75% escaped8 total outputs
Attack Surface

NG-WooCommerce-MoeDelo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedng-woo-moedelo-org-integration.php:50
filterwoocommerce_payment_gatewaysng-woo-moedelo-org-integration.php:51
actioninitng-woo-moedelo-org-integration.php:55
filterwoocommerce_product_data_tabsng-woo-moedelo-org-integration.php:102
actionwoocommerce_product_data_panelsng-woo-moedelo-org-integration.php:106
actionwoocommerce_process_product_metang-woo-moedelo-org-integration.php:111
Maintenance & Trust

NG-WooCommerce-MoeDelo Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 30, 2020
PHP min version5.6
Downloads925

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

NG-WooCommerce-MoeDelo Developer Profile

nikita.global

4 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NG-WooCommerce-MoeDelo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ng-woo-moedelo-org-integration/assets/js/script.js/wp-content/plugins/ng-woo-moedelo-org-integration/assets/css/style.css
Script Paths
/wp-content/plugins/ng-woo-moedelo-org-integration/assets/js/script.js
Version Parameters
ng-woo-moedelo-org-integration/assets/js/script.js?ver=ng-woo-moedelo-org-integration/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
moedelo-org-integration-settings
Data Attributes
data-prefixdata-methodname
JS Globals
NGWMD_JS_Vars
FAQ

Frequently Asked Questions about NG-WooCommerce-MoeDelo