
User Who Last Viewed The Order Security & Risk Analysis
wordpress.org/plugins/order-user-last-viewedDisplays the user who last viewed a WooCommerce order in the admin panel, with timestamp.
Is User Who Last Viewed The Order Safe to Use in 2026?
Generally Safe
Score 100/100User Who Last Viewed The Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "order-user-last-viewed" plugin v1.0.3 demonstrates a generally good security posture, adhering to several best practices. Notably, all SQL queries are executed using prepared statements, and all identified output is properly escaped, mitigating risks of SQL injection and cross-site scripting (XSS) respectively. The plugin also correctly implements nonce checks and capability checks for its single entry point. Furthermore, the absence of any historical vulnerabilities or critical taint flows suggests a mature and well-maintained codebase.
However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks. This creates a direct attack vector for unauthenticated users to interact with this functionality, potentially leading to unintended consequences or information disclosure if the handler performs sensitive operations. While the static analysis did not reveal any direct vulnerabilities stemming from this, the unprotected entry point represents a notable weakness.
In conclusion, the plugin's foundation is strong, with sound practices in place for common web vulnerabilities. The sole vulnerability identified is the unprotected AJAX handler. Addressing this single point of failure should be the immediate priority to elevate the plugin's security to a more robust level.
Key Concerns
- Unprotected AJAX handler
User Who Last Viewed The Order Security Vulnerabilities
User Who Last Viewed The Order Code Analysis
Output Escaping
User Who Last Viewed The Order Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
User Who Last Viewed The Order Maintenance & Trust
Maintenance Signals
Community Trust
User Who Last Viewed The Order Alternatives
Orders Tracking for WooCommerce
woo-orders-tracking
Easily import/manage your tracking numbers, add tracking numbers to PayPal and send email notifications to customers.
Dashify: WooCommerce admin dashboard theme
dashify
A modern design and UI for the WooCommerce admin. Manage, search, and navigate orders faster. Make the WordPress admin dashboard ecommerce-focused.
Purchased Items Column for WooCommerce Orders
purchased-items-column-woocommerce
Display a "Purchased Items" column on the WooCommerce orders page.
List Orders with Backorders for WooCommerce
list-backorders-for-woocommerce
A Wordpress Plugin to List Orders with Backordered items on them. This helps the store manager with a list of orders that need items to complete fulfi …
RD Order Note Templates for WooCommerce
rd-wc-enhanced-order-notes
Create predefined templates for order notes that you can apply to orders
User Who Last Viewed The Order Developer Profile
3 plugins · 20 total installs
How We Detect User Who Last Viewed The Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/order-user-last-viewed/assets/css/admin.css/wp-content/plugins/order-user-last-viewed/assets/js/admin.jsorder-user-last-viewed/assets/css/admin.css?ver=order-user-last-viewed/assets/js/admin.js?ver=HTML / DOM Fingerprints
oulvo-statusoulvo-not-viewedoulvo-vieweddata-nonce="oulvo_last_viewed"OULVO