
Scheduled & Automatic Order Status Controller for WooCommerce Security & Risk Analysis
wordpress.org/plugins/order-status-rules-for-woocommerceAutomate WooCommerce order statuses. Beautifully.
Is Scheduled & Automatic Order Status Controller for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Scheduled & Automatic Order Status Controller for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of "order-status-rules-for-woocommerce" v3.9.0 reveals a generally good security posture in several key areas. The plugin demonstrates strong practices by having no dangerous functions, using prepared statements exclusively for all SQL queries, and performing no file operations or external HTTP requests. This significantly reduces the risk of common vulnerabilities like SQL injection and remote code execution. However, there are notable areas for improvement. The lack of nonce checks and capability checks across all entry points is a significant concern, as it leaves the plugin vulnerable to cross-site request forgery (CSRF) and unauthorized actions if any of its entry points become accessible without proper authentication. While the taint analysis shows no critical or high-severity unsanitized paths, the presence of two flows with unsanitized paths, even if not deemed critical, warrants further investigation.
The vulnerability history indicates that the plugin has had a past high-severity vulnerability related to URL Redirection to Untrusted Site. While there are currently no unpatched CVEs, the existence of past vulnerabilities, particularly a high-severity one, suggests a potential for recurring issues. The fact that the last vulnerability was in the future (2025-03-27) is a data anomaly and should be disregarded for a current assessment. The overall conclusion is that while the plugin has a solid foundation regarding data handling and external interactions, the absence of robust authentication and authorization checks on its entry points, coupled with a history of vulnerabilities, presents a moderate security risk that requires attention.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Two flows with unsanitized paths (taint)
- One past high severity vulnerability
- 67% of outputs properly escaped (not 100%)
Scheduled & Automatic Order Status Controller for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Scheduled & Automatic Order Status Controller for WooCommerce <= 3.7.1 - Open Redirect
Scheduled & Automatic Order Status Controller for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Scheduled & Automatic Order Status Controller for WooCommerce Attack Surface
WordPress Hooks 33
Scheduled Events 1
Maintenance & Trust
Scheduled & Automatic Order Status Controller for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Scheduled & Automatic Order Status Controller for WooCommerce Alternatives
Additional Custom Order Status for WooCommerce
order-status-for-woocommerce
Manage order statuses in WooCommerce. Beautifully.
Custom Order Status for WooCommerce
custom-order-statuses-woocommerce
Custom Order Status for WooCommerce allows you to create and manage order statuses. It improves order management & overall order workflow.
Order Tracking – WordPress Status Tracking Plugin
order-tracking
Order tracking, status and project management plugin. Create tickets and tracking numbers. Send email updates. Works standalone and with WooCommerce.
Ni WooCommerce Custom Order Status
ni-woocommerce-custom-order-status
WC requires at least: 4.0 WC tested up to: 9.7 Last Updated Date: 10-March-2026 WooCommerce Custom Order Status plug-in allows you to create and manag …
Dashify: WooCommerce admin dashboard theme
dashify
A modern design and UI for the WooCommerce admin. Manage, search, and navigate orders faster. Make the WordPress admin dashboard ecommerce-focused.
Scheduled & Automatic Order Status Controller for WooCommerce Developer Profile
63 plugins · 136K total installs
How We Detect Scheduled & Automatic Order Status Controller for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/order-status-rules-for-woocommerce/assets/css/alg-wc-asr-admin.css/wp-content/plugins/order-status-rules-for-woocommerce/assets/css/alg-wc-asr-public.css/wp-content/plugins/order-status-rules-for-woocommerce/assets/js/alg-wc-asr-admin.js/wp-content/plugins/order-status-rules-for-woocommerce/assets/js/alg-wc-asr-public.js/wp-content/plugins/order-status-rules-for-woocommerce/assets/css/alg-wc-asr-admin.css?ver=/wp-content/plugins/order-status-rules-for-woocommerce/assets/css/alg-wc-asr-public.css?ver=/wp-content/plugins/order-status-rules-for-woocommerce/assets/js/alg-wc-asr-admin.js?ver=/wp-content/plugins/order-status-rules-for-woocommerce/assets/js/alg-wc-asr-public.js?ver=HTML / DOM Fingerprints
alg-wc-asr-adminalg-wc-asr-public<!-- Order Status Rules for WooCommerce - Admin Class --><!-- Order Status Rules for WooCommerce -->data-alg-wc-asr-order-iddata-alg-wc-asr-rule-indexdata-alg-wc-asr-rule-titlealg_wc_asr_admin_paramsalg_wc_asr_public_params