Ni WooCommerce Order Delivery Security & Risk Analysis

wordpress.org/plugins/ni-woocommerce-order-delivery

Enable customers to choose their preferred delivery dates directly at checkout.

0 active installs v1.2.9 PHP 7.0+ WP 4.7+ Updated May 11, 2024
delivery-datedelivery-reportexport-orderorder-delivery-datewoocommerce-order-delivery
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ni WooCommerce Order Delivery Safe to Use in 2026?

Generally Safe

Score 85/100

Ni WooCommerce Order Delivery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The ni-woocommerce-order-delivery v1.2.9 plugin exhibits a mixed security posture. While it demonstrates strong practices in SQL query handling by exclusively using prepared statements and has no recorded historical vulnerabilities, significant concerns arise from its attack surface and code signal analysis. The presence of one unprotected AJAX handler is a critical flaw, as it represents a direct entry point for potential attackers to interact with the plugin's functionality without any authentication or authorization checks. This lack of basic security measures on an AJAX endpoint is a primary risk.

Further analysis reveals that 14% of output is not properly escaped, which can lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The taint analysis, while showing no critical or high severity flows, still identified two flows with unsanitized paths, indicating a potential for insecure data handling, though its severity is not explicitly defined as high. The absence of nonce checks and capability checks on the AJAX handler is a major weakness.

In conclusion, the plugin has a clean vulnerability history and good practices regarding SQL, but the unprotected AJAX handler and a percentage of unescaped output are serious security weaknesses. The lack of comprehensive authorization checks on its sole entry point is the most pressing concern, demanding immediate attention to mitigate potential exploitation.

Key Concerns

  • Unprotected AJAX handler
  • Insufficient output escaping
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
  • Flows with unsanitized paths
Vulnerabilities
None known

Ni WooCommerce Order Delivery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Ni WooCommerce Order Delivery Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Ni WooCommerce Order Delivery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
31
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared7 total queries

Output Escaping

14% escaped36 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
admin_init_save (include\ni-order-delivery-settings.php:15)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Ni WooCommerce Order Delivery Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_ni_order_delivery_ajaxinclude\ni-order-delivery-init.php:16
WordPress Hooks 12
actionwoocommerce_after_order_notesinclude\ni-order-delivery-hook.php:7
actionwoocommerce_checkout_processinclude\ni-order-delivery-hook.php:8
actionwoocommerce_checkout_update_order_metainclude\ni-order-delivery-hook.php:9
filterwoocommerce_email_order_meta_keysinclude\ni-order-delivery-hook.php:11
actionwoocommerce_admin_order_data_after_billing_addressinclude\ni-order-delivery-hook.php:12
actionwp_headinclude\ni-order-delivery-hook.php:14
actionwp_footerinclude\ni-order-delivery-hook.php:15
actionadmin_menuinclude\ni-order-delivery-init.php:12
actionadmin_enqueue_scriptsinclude\ni-order-delivery-init.php:15
actionadmin_initinclude\ni-order-delivery-init.php:17
actionadmin_menuinclude\ni-order-delivery-settings.php:8
actionadmin_initinclude\ni-order-delivery-settings.php:10
Maintenance & Trust

Ni WooCommerce Order Delivery Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 11, 2024
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Ni WooCommerce Order Delivery Developer Profile

Anzar Ahmed

26 plugins · 5K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
228 days
View full developer profile
Detection Fingerprints

How We Detect Ni WooCommerce Order Delivery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ni-woocommerce-order-delivery/css/jquery-ui.css/wp-content/plugins/ni-woocommerce-order-delivery/js/ni-order-delivery.js

HTML / DOM Fingerprints

CSS Classes
my-field-class
Data Attributes
data-ni-order-delivery-optiondata-delivary-days
JS Globals
ni_order_delivery_optiondelivary_days2
FAQ

Frequently Asked Questions about Ni WooCommerce Order Delivery