
Order Delivery Date for Jigoshop Security & Risk Analysis
wordpress.org/plugins/order-delivery-date-for-jigoshopAllow the customers to choose an order delivery date on the checkout page for Jigoshop store owners.
Is Order Delivery Date for Jigoshop Safe to Use in 2026?
Generally Safe
Score 85/100Order Delivery Date for Jigoshop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis for "order-delivery-date-for-jigoshop" v1.0 reveals a generally strong security posture with a notably small attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are very few potential entry points for attackers to exploit. Furthermore, the plugin demonstrates good practice by using prepared statements for all SQL queries, significantly mitigating the risk of SQL injection vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests also contributes positively to its security. However, a significant concern arises from the total lack of output escaping. This indicates that data displayed to users might not be properly sanitized, potentially leading to Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is ever rendered without sanitization.
The taint analysis found two flows with unsanitized paths. While no critical or high severity vulnerabilities were identified here, the presence of unsanitized paths is a clear indicator of potential security weaknesses that could be leveraged if an attacker can control the data flowing through these paths. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign. This suggests that, at least historically, the plugin has not been a source of significant security flaws. However, the absence of past vulnerabilities should not be interpreted as a guarantee of future security, especially given the identified output escaping issue.
In conclusion, the "order-delivery-date-for-jigoshop" v1.0 plugin is strong in its limited attack surface and secure SQL handling. The primary weakness lies in the complete absence of output escaping, which presents a clear risk of XSS vulnerabilities. The taint analysis, while not revealing critical issues, highlights areas where data sanitization is likely lacking. The clean vulnerability history is a positive, but the code-level findings, particularly regarding output escaping, require attention to maintain a secure state.
Key Concerns
- No output escaping detected
- Unsanitized paths found in taint analysis
Order Delivery Date for Jigoshop Security Vulnerabilities
Order Delivery Date for Jigoshop Release Timeline
Order Delivery Date for Jigoshop Code Analysis
Output Escaping
Data Flow Analysis
Order Delivery Date for Jigoshop Attack Surface
WordPress Hooks 4
Maintenance & Trust
Order Delivery Date for Jigoshop Maintenance & Trust
Maintenance Signals
Community Trust
Order Delivery Date for Jigoshop Alternatives
Product Delivery Date for WooCommerce – Lite
product-delivery-date-for-woocommerce-lite
Choose delivery/pickup dates & times on product page. Simplify delivery management by setting minimum delivery time, max deliveries per day & more.
Order Delivery Date And Time
order-delivery-date-and-time
Order Delivery Date And Time plugin lets customers select delivery/pickup dates and times at checkout page.
Delivery Date for WooCommerce
delivery-date-for-woocommerce
This plugin adds a delivery date field to the checkout page.
Delivery Date checkout for Woocommerce
delivery-date-checkout-for-woocommerce
Ability to allow the customer to select Delivery date & time on the checkoutpage for the orders.
Professional Booking Management
professional-booking-management
Professional Booking Management adds service calendar, service schedule and customer checkout to your posts and pages for simple booking.
Order Delivery Date for Jigoshop Developer Profile
2 plugins · 20 total installs
How We Detect Order Delivery Date for Jigoshop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/order-delivery-date-for-jigoshop/datepicker.css/wp-content/plugins/order-delivery-date-for-jigoshop/initialize-datepicker.js/wp-content/plugins/order-delivery-date-for-jigoshop/initialize-datepicker.jsHTML / DOM Fingerprints
e_deliverydateAdds the script for the date picker before the checkout form.