
Ni WooCommerce Order Delivery Security & Risk Analysis
wordpress.org/plugins/ni-woocommerce-order-deliveryEnable customers to choose their preferred delivery dates directly at checkout.
Is Ni WooCommerce Order Delivery Safe to Use in 2026?
Generally Safe
Score 85/100Ni WooCommerce Order Delivery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ni-woocommerce-order-delivery v1.2.9 plugin exhibits a mixed security posture. While it demonstrates strong practices in SQL query handling by exclusively using prepared statements and has no recorded historical vulnerabilities, significant concerns arise from its attack surface and code signal analysis. The presence of one unprotected AJAX handler is a critical flaw, as it represents a direct entry point for potential attackers to interact with the plugin's functionality without any authentication or authorization checks. This lack of basic security measures on an AJAX endpoint is a primary risk.
Further analysis reveals that 14% of output is not properly escaped, which can lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The taint analysis, while showing no critical or high severity flows, still identified two flows with unsanitized paths, indicating a potential for insecure data handling, though its severity is not explicitly defined as high. The absence of nonce checks and capability checks on the AJAX handler is a major weakness.
In conclusion, the plugin has a clean vulnerability history and good practices regarding SQL, but the unprotected AJAX handler and a percentage of unescaped output are serious security weaknesses. The lack of comprehensive authorization checks on its sole entry point is the most pressing concern, demanding immediate attention to mitigate potential exploitation.
Key Concerns
- Unprotected AJAX handler
- Insufficient output escaping
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
- Flows with unsanitized paths
Ni WooCommerce Order Delivery Security Vulnerabilities
Ni WooCommerce Order Delivery Release Timeline
Ni WooCommerce Order Delivery Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ni WooCommerce Order Delivery Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
Ni WooCommerce Order Delivery Maintenance & Trust
Maintenance Signals
Community Trust
Ni WooCommerce Order Delivery Alternatives
Delivery Date for WooCommerce
delivery-date-for-woocommerce
This plugin adds a delivery date field to the checkout page.
Order Delivery Date And Time
order-delivery-date-and-time
Order Delivery Date And Time plugin lets customers select delivery/pickup dates and times at checkout page.
Product Delivery Date for WooCommerce – Lite
product-delivery-date-for-woocommerce-lite
Choose delivery/pickup dates & times on product page. Simplify delivery management by setting minimum delivery time, max deliveries per day & more.
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
Order Export & Order Import for WooCommerce
order-import-export-for-woocommerce
The best order export import plugin for WooCommerce. Easily import and export WooCommerce orders and WooCommerce coupons using CSV.
Ni WooCommerce Order Delivery Developer Profile
26 plugins · 5K total installs
How We Detect Ni WooCommerce Order Delivery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ni-woocommerce-order-delivery/css/jquery-ui.css/wp-content/plugins/ni-woocommerce-order-delivery/js/ni-order-delivery.jsHTML / DOM Fingerprints
my-field-classdata-ni-order-delivery-optiondata-delivary-daysni_order_delivery_optiondelivary_days2