Note Finder for WooCommerce Security & Risk Analysis

wordpress.org/plugins/note-finder-for-woocommerce

Search for WooCommerce order notes

100 active installs v1.3 PHP 5.6+ WP 4.5+ Updated May 15, 2022
find-woocommerce-notesorder-notes-searchsearch-for-noteswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Note Finder for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Note Finder for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'note-finder-for-woocommerce' v1.3 exhibits a generally positive security posture based on the provided static analysis. It has no recorded vulnerabilities, suggesting a good track record of secure development or a lack of sophisticated security audits. The static analysis shows no identifiable entry points (AJAX, REST API, shortcodes, cron events), which significantly limits the potential attack surface. Furthermore, the absence of dangerous function calls, file operations, and external HTTP requests is encouraging. However, there are notable concerns. The presence of a raw SQL query without prepared statements is a significant risk, potentially leading to SQL injection vulnerabilities if user input is not meticulously sanitized and validated. Additionally, the output escaping is only 61% proper, indicating that approximately 39% of outputs might be vulnerable to cross-site scripting (XSS) attacks. The complete lack of nonce and capability checks, while not directly exploitable due to the zero entry points, highlights a missed opportunity for robust authorization and security best practices that would be crucial if new entry points were ever introduced.

Key Concerns

  • Raw SQL query without prepared statements
  • Low percentage of properly escaped output
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

Note Finder for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Note Finder for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
7
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

61% escaped18 total outputs
Attack Surface

Note Finder for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadednote-finder-for-woocommerce.php:29
actionadmin_menunote-finder-for-woocommerce.php:30
actionplugins_loadednote-finder-for-woocommerce.php:86
filtercomments_clausesnote-finder-html.php:63
filtercomments_clausesnote-finder-html.php:65
Maintenance & Trust

Note Finder for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedMay 15, 2022
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Note Finder for WooCommerce Developer Profile

Disable Bloat

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Note Finder for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wc-note-finder
Data Attributes
name="searchkeyword"value="<?php echo esc_attr( $searchkeyword ); ?>"
FAQ

Frequently Asked Questions about Note Finder for WooCommerce