Order Tracker by Phone Number Security & Risk Analysis
wordpress.org/plugins/order-tracker-by-phone-numberAllow customers to track their WooCommerce orders using just their phone number with a sleek popup display.
Is Order Tracker by Phone Number Safe to Use in 2026?
Generally Safe
Score 100/100Order Tracker by Phone Number has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "order-tracker-by-phone-number" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. It correctly utilizes prepared statements for all SQL queries and demonstrates a high percentage of properly escaped output, significantly mitigating risks of SQL injection and cross-site scripting (XSS). The plugin also appears to have a limited attack surface, with a small number of entry points, none of which are immediately apparent as unprotected. The absence of any recorded vulnerabilities in its history further reinforces this positive assessment, suggesting a proactive approach to security or a lack of past exploitation.
However, a key concern arises from the complete lack of capability checks on its entry points. While nonce checks are present for one AJAX handler, the absence of capability checks means that any user, regardless of their role or permissions, could potentially interact with these functions. This could lead to unauthorized access or manipulation of plugin features. The presence of file operations without specific context also warrants a closer look, though without further information on how they are implemented, the risk is currently unclear. The zero taint analysis flows, while positive, could also be a result of limited or non-existent dynamic analysis, and therefore shouldn't be seen as a definitive guarantee of zero taint-related issues.
In conclusion, the plugin has implemented several critical security best practices, making it appear relatively secure. The primary weakness lies in the missing capability checks, which create a potential avenue for privilege escalation or unauthorized actions. Further investigation into the implementation of file operations and a more comprehensive taint analysis would be beneficial for a complete risk picture. The lack of historical vulnerabilities is a positive indicator, but the identified gaps in authorization require attention.
Key Concerns
- Missing capability checks on entry points
- Possible uninspected file operations
Order Tracker by Phone Number Security Vulnerabilities
Order Tracker by Phone Number Code Analysis
Output Escaping
Order Tracker by Phone Number Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Order Tracker by Phone Number Maintenance & Trust
Maintenance Signals
Community Trust
Order Tracker by Phone Number Alternatives
Order Tracking – WordPress Status Tracking Plugin
order-tracking
Order tracking, status and project management plugin. Create tickets and tracking numbers. Send email updates. Works standalone and with WooCommerce.
JCWT Order Timeline for WooCommerce
jcwt-order-timeline-for-woocommerce
A lightweight, HPOS-compatible order tracking timeline for WooCommerce with caching and mobile-responsive design.
Order Pilot
order-pilot
Create and manage custom WooCommerce order statuses with color badges, email alerts, frontend tracking, workflows, CSV import, and more.
Shipment Stream View for WooCommerce
shipment-stream-view-for-woocommerce
A modern, visual order tracking system for WooCommerce that displays order status with an elegant progress bar.
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
Order Tracker by Phone Number Developer Profile
1 plugin · 50 total installs
How We Detect Order Tracker by Phone Number
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/order-tracker-by-phone-number/css/style.css/wp-content/plugins/order-tracker-by-phone-number/js/script.js/wp-content/plugins/order-tracker-by-phone-number/js/script.jsorder-tracker-by-phone-number/css/style.css?ver=order-tracker-by-phone-number/js/script.js?ver=HTML / DOM Fingerprints
otbp-tracker-formotbp-modalotbp-modal-contentotbp-closeid="otbp-track-order-form"id="otbp-results-container"id="otbp-order-popup"id="otbp-popup-content"name="phone"wp_nonce_field('otbp_track_order', 'otbp_nonce')OTBP_AJAX_URLOTBP_NONCE/wp-json/otbp/v1/track-order<div class="otbp-tracker-form"<form id="otbp-track-order-form"<button type="submit"<div id="otbp-results-container"></div>