Order On Mobile for WooCommerce Security & Risk Analysis

wordpress.org/plugins/order-on-mobile-for-woocommerce

Order On Mobile for WooCommerce allows your customers to submit their orders via WhatsApp, directly from the Woocommerce product page, single product …

2K active installs v2.2 PHP 7.4+ WP 6.5+ Updated Jun 30, 2024
orderproductswhatsappwoocommercewoocommerce-whatsapp
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Order On Mobile for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Order On Mobile for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "order-on-mobile-for-woocommerce" v2.2 plugin exhibits a concerning security posture due to a significant number of unprotected entry points. While the plugin demonstrates good practices in SQL query handling by exclusively using prepared statements and avoids risky file operations or external HTTP requests, the absence of authentication checks on two AJAX handlers is a critical oversight. This directly exposes these entry points to potential abuse by unauthenticated users, making them prime targets for attacks. The taint analysis reveals two flows with unsanitized paths, which, while not flagged as critical or high severity in this specific analysis, warrant attention as they indicate potential avenues for data manipulation or injection if combined with other weaknesses.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting that developers may have a good understanding of secure coding practices or that the plugin hasn't been extensively targeted or analyzed for vulnerabilities in the past. However, the lack of historical issues should not breed complacency, especially given the identified weaknesses in its current version. The core concern remains the unprotected AJAX endpoints, which significantly increases the attack surface. Overall, the plugin has strengths in its SQL handling and avoidance of certain risky functions, but the unauthenticated entry points present a clear and present danger that needs immediate remediation.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
  • Lack of nonce checks on AJAX
  • Low percentage of properly escaped output
Vulnerabilities
None known

Order On Mobile for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Order On Mobile for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

41% escaped17 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
woow_add_settings_tab (admin\class-woocommerce-order-on-whatsapp-admin.php:138)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Order On Mobile for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_get_cart_contentsincludes\class-woocommerce-order-on-whatsapp.php:196
noprivwp_ajax_get_cart_contentsincludes\class-woocommerce-order-on-whatsapp.php:197
WordPress Hooks 19
filterplugin_action_linksadmin\class-woocommerce-order-on-whatsapp-admin.php:51
actionplugins_loadedincludes\class-woocommerce-order-on-whatsapp.php:143
actionadmin_enqueue_scriptsincludes\class-woocommerce-order-on-whatsapp.php:158
actionadmin_enqueue_scriptsincludes\class-woocommerce-order-on-whatsapp.php:159
actionadmin_noticesincludes\class-woocommerce-order-on-whatsapp.php:162
actionadmin_noticesincludes\class-woocommerce-order-on-whatsapp.php:164
actionwoocommerce_settings_tabsincludes\class-woocommerce-order-on-whatsapp.php:167
actionwoocommerce_settings_tabs_woow_settings_tabincludes\class-woocommerce-order-on-whatsapp.php:168
actionwoocommerce_update_options_woow_settings_tabincludes\class-woocommerce-order-on-whatsapp.php:169
actionadmin_footerincludes\class-woocommerce-order-on-whatsapp.php:171
actionwp_enqueue_scriptsincludes\class-woocommerce-order-on-whatsapp.php:185
actionwp_enqueue_scriptsincludes\class-woocommerce-order-on-whatsapp.php:186
actionwoocommerce_after_shop_loop_itemincludes\class-woocommerce-order-on-whatsapp.php:189
actionwoocommerce_shareincludes\class-woocommerce-order-on-whatsapp.php:192
actionwoocommerce_after_cart_totalsincludes\class-woocommerce-order-on-whatsapp.php:195
actionwoocommerce_after_shop_loop_itemincludes\class-woocommerce-order-on-whatsapp.php:200
actionwoocommerce_single_product_summaryincludes\class-woocommerce-order-on-whatsapp.php:201
actionwoocommerce_proceed_to_checkoutincludes\class-woocommerce-order-on-whatsapp.php:203
actionwoocommerce_widget_shopping_cart_buttonsincludes\class-woocommerce-order-on-whatsapp.php:204
Maintenance & Trust

Order On Mobile for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJun 30, 2024
PHP min version7.4
Downloads42K

Community Trust

Rating98/100
Number of ratings66
Active installs2K
Developer Profile

Order On Mobile for WooCommerce Developer Profile

intolap

2 plugins · 3K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Order On Mobile for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/order-on-mobile-for-woocommerce/admin/css/woocommerce-order-on-whatsapp-admin.css/wp-content/plugins/order-on-mobile-for-woocommerce/admin/js/woocommerce-order-on-whatsapp-admin.js
Script Paths
/wp-content/plugins/order-on-mobile-for-woocommerce/admin/js/woocommerce-order-on-whatsapp-admin.js
Version Parameters
woocommerce-order-on-whatsapp-admin.css?ver=woocommerce-order-on-whatsapp-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
woow_settings_tab
Data Attributes
data-tabdata-href
JS Globals
woow_settings_tab
FAQ

Frequently Asked Questions about Order On Mobile for WooCommerce