
Order Pilot Security & Risk Analysis
wordpress.org/plugins/order-pilotCreate and manage custom WooCommerce order statuses with color badges, email alerts, frontend tracking, workflows, CSV import, and more.
Is Order Pilot Safe to Use in 2026?
Generally Safe
Score 100/100Order Pilot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'order-pilot' plugin v1.0.0 presents a mixed security posture. While it exhibits good practices such as a high percentage of prepared SQL statements and a solid number of nonce and capability checks, significant concerns arise from its attack surface and taint analysis. The presence of an unprotected AJAX handler is a critical security flaw, potentially allowing unauthorized actions. Furthermore, taint analysis revealing flows with unsanitized paths, specifically three high-severity instances, indicates a risk of data being processed in an insecure manner, even if no critical vulnerabilities have been discovered yet. The absence of any recorded CVEs or past vulnerabilities is positive, suggesting a potentially well-maintained codebase or a lack of past scrutiny. However, this should not overshadow the immediate risks identified in the static and taint analysis. The plugin has strengths in its coding practices but requires immediate attention to address the unprotected entry point and the identified high-severity taint flows.
Key Concerns
- AJAX handler without auth check
- High severity unsanitized taint flows (3)
- Low percentage of properly escaped output
Order Pilot Security Vulnerabilities
Order Pilot Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Order Pilot Attack Surface
AJAX Handlers 16
WordPress Hooks 22
Scheduled Events 2
Maintenance & Trust
Order Pilot Maintenance & Trust
Maintenance Signals
Community Trust
Order Pilot Alternatives
RIACO Custom Order Status for WooCommerce
riaco-custom-order-status-for-woocommerce
Create and manage custom WooCommerce order statuses with colors and admin integration.
Order Tracking – WordPress Status Tracking Plugin
order-tracking
Order tracking, status and project management plugin. Create tickets and tracking numbers. Send email updates. Works standalone and with WooCommerce.
Additional Custom Order Status for WooCommerce
order-status-for-woocommerce
Manage order statuses in WooCommerce. Beautifully.
Advanced Custom Order Status for WooCommerce
advanced-custom-order-status-for-woocommerce
Easily create, edit, and delete custom order status in WooCommerce. Add icon, color and action to enhance the visual representation of order statuses.
Advanced Order Status For WooCommerce – Custom Status Management & Workflow Automation
advanced-order-status-for-woocommerce
Create and manage custom WooCommerce order statuses with icons, colors, and bulk actions. Streamline your fulfillment workflow.
Order Pilot Developer Profile
2 plugins · 0 total installs
How We Detect Order Pilot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/order-pilot/assets/js/orderp-status-manager.js/wp-content/plugins/order-pilot/assets/css/orderp-design.css/wp-content/plugins/order-pilot/assets/js/orderp-custom-statuses.js/wp-content/plugins/order-pilot/assets/js/orderp-email-notifications.js/wp-content/plugins/order-pilot/assets/js/orderp-bulk-actions.js/wp-content/plugins/order-pilot/assets/js/orderp-automation-rules.js/wp-content/plugins/order-pilot/assets/css/orderp-admin.css/wp-content/plugins/order-pilot/assets/css/orderp-settings.css+2 more/wp-content/plugins/order-pilot/assets/js/orderp-status-manager.js/wp-content/plugins/order-pilot/assets/js/orderp-custom-statuses.js/wp-content/plugins/order-pilot/assets/js/orderp-email-notifications.js/wp-content/plugins/order-pilot/assets/js/orderp-bulk-actions.js/wp-content/plugins/order-pilot/assets/js/orderp-automation-rules.jsorderp-status-manager-script?ver=1.0.0orderp-status-manager-design?ver=1.0.0orderp-custom-statuses-script?ver=1.0.0orderp-email-notifications-script?ver=1.0.0orderp-bulk-actions-script?ver=1.0.0orderp-automation-rules-script?ver=1.0.0orderp-admin-design?ver=1.0.0orderp-settings-design?ver=1.0.0orderp-bulk-actions-design?ver=1.0.0orderp-automation-rules-design?ver=1.0.0HTML / DOM Fingerprints
orderp-status-manager-wraporderp-status-itemorderp-color-pickerorderp-status-iconorderp-status-nameorderp-status-slugorderp-status-colororderp-status-actions+19 more<!-- Prevent direct access --><!-- Main plugin class --><!-- Plugin instance --><!-- Constructor -->+17 moredata-orderp-status-iddata-orderp-status-slugdata-orderp-status-colordata-orderp-status-icondata-orderp-status-namedata-orderp-modal-target+7 moreorderp_status_manager_ajax_objectorderp_preview_email_ajax_objectorderp_duplicate_status_ajax_objectorderp_bulk_delete_statuses_ajax_objectorderp_get_usage_stats_ajax_objectOrderPilotAssets/wp-json/orderp/v1/statuses/wp-json/orderp/v1/status/(?P<id>\d+)/wp-json/orderp/v1/emails/wp-json/orderp/v1/email/(?P<id>\d+)/wp-json/orderp/v1/bulk-actions/wp-json/orderp/v1/automation-rules/wp-json/orderp/v1/automation-rule/(?P<id>\d+)/wp-json/orderp/v1/settings