ONDC Woo Integration Security & Risk Analysis

wordpress.org/plugins/ondc-woo-integration

ONDC Woo Integration is a plugin that allows you to integrate WooCommerce with the ONDC network.

0 active installs v1.0.0 PHP + WP 6.0+ Updated Unknown
integrationondcseller-appwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ONDC Woo Integration Safe to Use in 2026?

Generally Safe

Score 100/100

ONDC Woo Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The ondc-woo-integration v1.0.0 plugin presents a mixed security posture. While it demonstrates good practices in output escaping and a lack of known historical vulnerabilities, there are significant concerns related to its attack surface and data handling.

The plugin has a single unprotected REST API route, which is a direct entry point for potential attackers. Furthermore, the analysis reveals three flows with unsanitized paths in the taint analysis, with one being of high severity. This indicates a real risk of sensitive data being exposed or manipulated through these paths.

The absence of any recorded CVEs is positive, suggesting the plugin has been relatively secure in the past. However, this cannot override the immediate risks identified in the static and taint analysis. The plugin's strengths lie in its diligent output escaping and lack of historical issues, but its weaknesses in input validation and unprotected endpoints necessitate caution.

Key Concerns

  • Unprotected REST API route
  • High severity unsanitized path flow
  • 3 flows with unsanitized paths
  • SQL queries without prepared statements
Vulnerabilities
None known

ONDC Woo Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ONDC Woo Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
3
183 escaped
Nonce Checks
1
Capability Checks
1
File Operations
7
External Requests
5
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

98% escaped186 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
ondc_seller_app_subscription_page (admin\class-ondc-seller-app-admin.php:694)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

ONDC Woo Integration Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/ondc/v1/on_subscribeprotocol-layer\class-ondc-api-endpoints.php:84
WordPress Hooks 16
filterondcsellerapp_setup_wizardsadmin\class-ondc-setup-wizard.php:21
actionadmin_menuadmin\wisdm-setup\class-wisdm-setup-wizard.php:61
actionadmin_initadmin\wisdm-setup\class-wisdm-setup-wizard.php:62
actionplugins_loadedadmin\wisdm-setup\class-wisdm-setup-wizard.php:246
actionadd_meta_boxesincludes\class-ondc-seller-app.php:123
actionwoocommerce_product_options_pricingincludes\class-ondc-seller-app.php:126
actionsave_postincludes\class-ondc-seller-app.php:129
actionadmin_menuincludes\class-ondc-seller-app.php:132
actionadmin_enqueue_scriptsincludes\class-ondc-seller-app.php:135
filterwoocommerce_shop_order_list_table_columnsincludes\class-ondc-seller-app.php:138
actionwoocommerce_shop_order_list_table_custom_columnincludes\class-ondc-seller-app.php:141
actionadmin_initincludes\class-ondc-seller-app.php:143
actionrest_api_initprotocol-layer\class-ondc-api-endpoints.php:62
actionparse_requestprotocol-layer\class-ondc-api-endpoints.php:65
filtercron_schedulesprotocol-layer\class-ondc-queue-handler.php:20
actionondcsellerapp_message_schedule_cronprotocol-layer\class-ondc-queue-handler.php:23

Scheduled Events 1

ondcsellerapp_message_schedule_cron
Maintenance & Trust

ONDC Woo Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version
Downloads539

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ONDC Woo Integration Developer Profile

WisdmLabs

7 plugins · 15K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
147 days
View full developer profile
Detection Fingerprints

How We Detect ONDC Woo Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ondc-woo-integration/admin/js/ondc-seller-app-admin.js/wp-content/plugins/ondc-woo-integration/admin/css/ondc-seller-app-admin.css
Script Paths
/wp-content/plugins/ondc-woo-integration/admin/js/ondc-seller-app-admin.js
Version Parameters
ondc-woo-integration/admin/js/ondc-seller-app-admin.js?ver=ondc-woo-integration/admin/css/ondc-seller-app-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
ondc-categoriesondc-sub-categories
Data Attributes
ondcsellerapp_product_categoriesondcsellerapp_product_sub_categoriesondcsellerapp_product_sync
FAQ

Frequently Asked Questions about ONDC Woo Integration