
Order Item Details Column for WooCommerce Security & Risk Analysis
wordpress.org/plugins/order-item-details-column-for-woocommerceAdd an extra column in the WooCommerce Orders list to display product details, quantity, capacity attribute, subtotal, shipping fee and order total.
Is Order Item Details Column for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Order Item Details Column for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "order-item-details-column-for-woocommerce" plugin version 1.4.0 reveals a strong security posture in several key areas. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and a complete lack of taint analysis findings indicate a diligent approach to secure coding practices. The plugin also exclusively uses prepared statements for its SQL queries, which is an excellent security measure.
However, a significant concern arises from the output escaping. With only 27% of outputs properly escaped, this leaves a substantial portion vulnerable to cross-site scripting (XSS) attacks. The absence of nonce and capability checks on any potential entry points (though none were explicitly identified in the attack surface) also presents a theoretical risk, as it deviates from WordPress's standard security mechanisms. The vulnerability history being completely clean is a positive sign, suggesting a mature development process or a lack of past issues, but it does not mitigate the existing code-level risks.
In conclusion, while the plugin demonstrates strengths in minimizing its attack surface and secure data handling for SQL, the poor output escaping represents a critical weakness that could be exploited. The lack of observed vulnerability history is encouraging but should not overshadow the immediate code-level concerns. Addressing the output escaping vulnerabilities should be the primary focus for improving the security of this plugin.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Order Item Details Column for WooCommerce Security Vulnerabilities
Order Item Details Column for WooCommerce Release Timeline
Order Item Details Column for WooCommerce Code Analysis
Output Escaping
Order Item Details Column for WooCommerce Attack Surface
WordPress Hooks 8
Maintenance & Trust
Order Item Details Column for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Order Item Details Column for WooCommerce Alternatives
Notifications on Discord for WooCommerce
wc-discord-notifications
Send WooCommerce order and subscription notifications to Discord - rich embeds, customer details, mentions, low stock alerts, and more.
Autocomplete for WooCommerce Orders
autocomplete-for-woo-orders
Automatically complete WooCommerce orders after successful payment. Supports virtual, digital, downloadable products.
WS Multi-Location Intelligent Order for Woocommerce
ws-multi-location-intelligent-order-for-woocommerce
This is a simple plugin that adds a shipping zone column in the orders administartion menu.
Customer Related Orders for WooCommerce
customer-related-orders-for-woocommerce
Designed to streamline the process of accessing your customer's order history.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Order Item Details Column for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect Order Item Details Column for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
oidcwc_order_items