
Order On Mobile for WooCommerce Security & Risk Analysis
wordpress.org/plugins/order-on-mobile-for-woocommerceOrder On Mobile for WooCommerce allows your customers to submit their orders via WhatsApp, directly from the Woocommerce product page, single product …
Is Order On Mobile for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Order On Mobile for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "order-on-mobile-for-woocommerce" v2.2 plugin exhibits a concerning security posture due to a significant number of unprotected entry points. While the plugin demonstrates good practices in SQL query handling by exclusively using prepared statements and avoids risky file operations or external HTTP requests, the absence of authentication checks on two AJAX handlers is a critical oversight. This directly exposes these entry points to potential abuse by unauthenticated users, making them prime targets for attacks. The taint analysis reveals two flows with unsanitized paths, which, while not flagged as critical or high severity in this specific analysis, warrant attention as they indicate potential avenues for data manipulation or injection if combined with other weaknesses.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting that developers may have a good understanding of secure coding practices or that the plugin hasn't been extensively targeted or analyzed for vulnerabilities in the past. However, the lack of historical issues should not breed complacency, especially given the identified weaknesses in its current version. The core concern remains the unprotected AJAX endpoints, which significantly increases the attack surface. Overall, the plugin has strengths in its SQL handling and avoidance of certain risky functions, but the unauthenticated entry points present a clear and present danger that needs immediate remediation.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Lack of nonce checks on AJAX
- Low percentage of properly escaped output
Order On Mobile for WooCommerce Security Vulnerabilities
Order On Mobile for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Order On Mobile for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 19
Maintenance & Trust
Order On Mobile for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Order On Mobile for WooCommerce Alternatives
Chat notifications for Woocommerce
chat-notifications-for-woocommerce
Chat notifications for Woocommerce, allows users to automatically send WhatsApp custom templates to your customers when an Order status is updated.
Chat On Desk Order Notifications – WooCommerce
chat-on-desk
A plugin for sending whatsapp notification after placing orders using WooCommerce
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Social Chat – Click To Chat App Button
wp-whatsapp-chat
WhatsApp Chat🔥 allows you to enhance customer engagement! Integrate "WhatsApp" or "WhatsApp Business" with a single click.
WP Chat App
wp-whatsapp
Integrate WhatsApp experience directly into your WordPress website.
Order On Mobile for WooCommerce Developer Profile
2 plugins · 3K total installs
How We Detect Order On Mobile for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/order-on-mobile-for-woocommerce/admin/css/woocommerce-order-on-whatsapp-admin.css/wp-content/plugins/order-on-mobile-for-woocommerce/admin/js/woocommerce-order-on-whatsapp-admin.js/wp-content/plugins/order-on-mobile-for-woocommerce/admin/js/woocommerce-order-on-whatsapp-admin.jswoocommerce-order-on-whatsapp-admin.css?ver=woocommerce-order-on-whatsapp-admin.js?ver=HTML / DOM Fingerprints
woow_settings_tabdata-tabdata-hrefwoow_settings_tab