
Open One On Demand Delivery Security & Risk Analysis
wordpress.org/plugins/open-one-on-demand-deliveryOpen One On Demand Delivery is used to link a store developed in WooCommerce with the Open One API and in this way have a delivery system connected to …
Is Open One On Demand Delivery Safe to Use in 2026?
Generally Safe
Score 85/100Open One On Demand Delivery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "open-one-on-demand-delivery" plugin v2.1.3 presents a mixed security posture. On the positive side, the plugin exhibits excellent practices regarding SQL queries, exclusively using prepared statements, and shows no history of known vulnerabilities (CVEs). The static analysis also indicates a lack of dangerous functions, file operations, and external HTTP requests, which are common vectors for exploits. However, significant concerns arise from the output escaping and taint analysis. With only 20% of outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. Furthermore, the taint analysis revealing two flows with unsanitized paths, although not rated as critical or high, suggests potential for insecure data handling. The absence of nonce checks and capability checks on AJAX handlers and REST API routes (if any were present) further exacerbates these risks, as it implies that unauthenticated or low-privileged users might be able to trigger certain actions or access sensitive information. The lack of any recorded vulnerabilities historically, while positive, could also imply that the plugin hasn't been subjected to extensive security testing or that previous issues were not publicly disclosed. Overall, while the plugin avoids some common pitfalls, the poor output escaping and unsanitized data flows are significant weaknesses that require immediate attention.
Key Concerns
- Low percentage of properly escaped output
- Taint flows with unsanitized paths found
- No nonce checks found
- No capability checks found
Open One On Demand Delivery Security Vulnerabilities
Open One On Demand Delivery Release Timeline
Open One On Demand Delivery Code Analysis
Output Escaping
Data Flow Analysis
Open One On Demand Delivery Attack Surface
WordPress Hooks 9
Maintenance & Trust
Open One On Demand Delivery Maintenance & Trust
Maintenance Signals
Community Trust
Open One On Demand Delivery Alternatives
Gobuddy – The smart delivery solution
gobuddy-the-smart-delivery-solution
The official Gobuddy plugin for WooCommerce
Business to Customer REST APIs For WooCommerce
business-to-customer-rest-apis-for-woocommerce
Provides REST APIs for WooCommerce customers to purchase products via mobile or headless apps.
IBIZA Express Delivery Integration
ibiza-express-delivery-integration
Automate e-commerce orders with official IBIZA platform for WooCommerce. Send your order to IBIZA system and syc your package statuses.
LlegoYa Envíos
llegoya-envios
Este plugin permite a WooCommerce calcular el costo de envío mediante la API de LlegoYa y enviar los detalles del pedido a un servicio externo.
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
Open One On Demand Delivery Developer Profile
1 plugin · 0 total installs
How We Detect Open One On Demand Delivery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/open-one-on-demand-delivery/assets/css/openone.css/wp-content/plugins/open-one-on-demand-delivery/assets/js/openone.js/wp-content/plugins/open-one-on-demand-delivery/assets/js/openone.jsopen-one-on-demand-delivery/assets/css/openone.css?ver=open-one-on-demand-delivery/assets/js/openone.js?ver=HTML / DOM Fingerprints
open-inputopenone_apikeyopenone_secretkeyopenone_date_fromopenone_date_toopenone_store_selectedopenone_check_selected+3 more