
Order approval for WCFM Security & Risk Analysis
wordpress.org/plugins/order-approval-for-wcfmThe Order Approval for WCFM plugin enables vendors to review and either accept or reject customer orders before any payment is made.
Is Order approval for WCFM Safe to Use in 2026?
Generally Safe
Score 85/100Order approval for WCFM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "order-approval-for-wcfm" plugin v1.0.4 exhibits a concerning security posture primarily due to its unprotected AJAX endpoints. While the plugin demonstrates good practices like using prepared statements for SQL queries and a high rate of output escaping, the presence of two AJAX handlers without any authentication or authorization checks presents a significant attack surface. This means any unauthenticated user could potentially interact with these endpoints, leading to unintended actions or information disclosure if vulnerabilities exist within them. The absence of any recorded CVEs or past vulnerabilities is a positive sign, suggesting that the plugin's authors may be diligent in addressing security issues or that the plugin hasn't been a target. However, this should not be a substitute for robust security measures within the code itself. The lack of taint analysis results also makes it difficult to assess the risk of data being passed unsafely through the application.
Key Concerns
- 2 AJAX handlers without auth checks
- Limited output escaping (87% escaped)
Order approval for WCFM Security Vulnerabilities
Order approval for WCFM Code Analysis
Output Escaping
Order approval for WCFM Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
Order approval for WCFM Maintenance & Trust
Maintenance Signals
Community Trust
Order approval for WCFM Alternatives
Order Approval for Woocommerce
order-approval-woocommerce
Approve or reject WooCommerce orders before payment. Manual order approval, email notifications, payment link, all gateways supported.
WCFM – WCFM Marketplace integrate Elementor
wc-frontend-manager-elementor
Create your marketplace store page using Elementor with your own design. Easily and Beatifully.
WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace
wc-frontend-manager-direct-paypal
Direct pay in vendor's PayPal account from customer account.
WholesaleX WCFM B2B Multivendor Marketplace
wholesalex-wcfm-b2b-multivendor-marketplace
Turn WCFM multivendor marketplace into a B2B multivendor marketplace with WholesaleX - the simplest B2B wholesale solution for WooCommerce.
Dokan Order Approval
dokan-order-approval
Dokan Vendor needs to approve order before payment is processed.
Order approval for WCFM Developer Profile
12 plugins · 3K total installs
How We Detect Order approval for WCFM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/order-approval-for-wcfm/admin/css/order-approval-for-wcfm-admin.css/wp-content/plugins/order-approval-for-wcfm/admin/js/order-approval-for-wcfm-admin.jsorder-approval-for-wcfm/admin/css/order-approval-for-wcfm-admin.css?ver=order-approval-for-wcfm/admin/js/order-approval-for-wcfm-admin.js?ver=HTML / DOM Fingerprints
sgits-oawcfmwcfmfadata-action="owfm_get_order_update"data-nonce="owfm-verify-nonce"data-updatedata-tipowfm_get_order_update