
Order Delivery Date for WooCommerce Security & Risk Analysis
wordpress.org/plugins/order-delivery-date-for-woocommerceLet customers choose delivery dates & times on checkout. Simplify delivery management by blocking holidays & setting max deliveries per day.
Is Order Delivery Date for WooCommerce Safe to Use in 2026?
Generally Safe
Score 95/100Order Delivery Date for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The 'order-delivery-date-for-woocommerce' plugin v4.5.0 presents a mixed security posture. While it demonstrates strong practices in using prepared statements for SQL queries and a generally high percentage of properly escaped output, there are significant concerns regarding its attack surface and taint analysis. The presence of 8 AJAX handlers, with 4 lacking authentication checks, creates a substantial entry point for potential unauthorized actions. Furthermore, the taint analysis reveals one flow with an unsanitized path, categorized as high severity, which could lead to exploitable vulnerabilities if not properly addressed. The plugin's vulnerability history, though currently showing no unpatched CVEs, indicates a past pattern of medium severity issues including missing authorization, CSRF, and XSS. This history, coupled with the current static analysis findings, suggests a need for vigilance and prompt patching of any new vulnerabilities discovered.
In conclusion, the plugin benefits from robust SQL handling and output escaping. However, the identified unprotected AJAX handlers and the high-severity taint flow are critical weaknesses that expose the application to potential risks. The historical vulnerability types also highlight areas that require ongoing attention to ensure comprehensive security. A balanced approach, addressing the identified entry points and taint flows while maintaining awareness of past patterns, is crucial for mitigating risks associated with this plugin.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow with unsanitized path
- Past medium severity vulnerabilities
Order Delivery Date for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Order Delivery Date for WooCommerce <= 4.3.1 - Missing Authorization
Order Delivery Date for WooCommerce <= 4.1.0 - Missing Authorization
Order Delivery Date for WooCommerce <= 3.21.0 - Cross-Site Request Forgery to Notice Dismissal
Order Delivery Date for WooCommerce <= 3.20.0 - Reflected Cross-Site Scripting via 'orddd_lite_custom_startdate' and 'orddd_lite_custom_enddate'
Order Delivery Date for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Order Delivery Date for WooCommerce Attack Surface
AJAX Handlers 8
WordPress Hooks 106
Maintenance & Trust
Order Delivery Date for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Order Delivery Date for WooCommerce Alternatives
Delivery & Pickup Date Time for WooCommerce
woo-delivery
Gives the facility of selecting delivery/pickup/both date/time/both at order checkout page.
Order Delivery Date And Time
order-delivery-date-and-time
Order Delivery Date And Time plugin lets customers select delivery/pickup dates and times at checkout page.
WooODT Lite – Delivery & pickup date time location for WooCommerce
byconsole-woo-order-delivery-time
WooODT Lite is a WooCommerce Delivery & Pickup Date Time extension that gives the facility of selecting delivery/pickup date and time/time slot o …
PiWeb Delivery & Pickup Date Time for WooCommerce
pi-woocommerce-order-date-time-and-type
WooCommerce delivery date | delivery time | pickup date | pickup time | pickup location
Pickup | Delivery | Dine-in date time
restaurant-pickup-delivery-dine-in
WooCommerce based restaurant ordering system for dine in, pickup and delivery. Let you customers book a table online or place an order for delivery or …
Order Delivery Date for WooCommerce Developer Profile
20 plugins · 160K total installs
How We Detect Order Delivery Date for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/order-delivery-date-for-woocommerce/assets/js/admin-order-delivery-date-lite.js/wp-content/plugins/order-delivery-date-for-woocommerce/assets/js/frontend-order-delivery-date-lite.js/wp-content/plugins/order-delivery-date-for-woocommerce/assets/css/frontend-order-delivery-date-lite.css/wp-content/plugins/order-delivery-date-for-woocommerce/assets/css/admin-order-delivery-date-lite.css/wp-content/plugins/order-delivery-date-for-woocommerce/assets/js/delivery-calendar-admin.js/wp-content/plugins/order-delivery-date-for-woocommerce/assets/js/admin-order-delivery-date-lite.js/wp-content/plugins/order-delivery-date-for-woocommerce/assets/js/frontend-order-delivery-date-lite.js/wp-content/plugins/order-delivery-date-for-woocommerce/assets/js/delivery-calendar-admin.jsorder-delivery-date-for-woocommerce/assets/js/admin-order-delivery-date-lite.js?ver=order-delivery-date-for-woocommerce/assets/js/frontend-order-delivery-date-lite.js?ver=order-delivery-date-for-woocommerce/assets/css/frontend-order-delivery-date-lite.css?ver=order-delivery-date-for-woocommerce/assets/css/admin-order-delivery-date-lite.css?ver=order-delivery-date-for-woocommerce/assets/js/delivery-calendar-admin.js?ver=HTML / DOM Fingerprints
orddd-lite-date-field-wrapperorddd-lite-delivery-date-fieldorddd-lite-delivery-time-slot-fielddata-orddd-lite-order-iddata-orddd-lite-order-datedata-orddd-lite-order-timeorddd_lite_frontend_params