
Online Ordering Plus Custom Branded Apps For Clover Merchants Security & Risk Analysis
wordpress.org/plugins/orderem-online-ordering-for-cloverOrderEm Online Orders for Clover allows you to receive orders from your Wordpress website and have it sent directly to your Clover POS
Is Online Ordering Plus Custom Branded Apps For Clover Merchants Safe to Use in 2026?
Generally Safe
Score 85/100Online Ordering Plus Custom Branded Apps For Clover Merchants has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "orderem-online-ordering-for-clover" plugin version 1.0 exhibits a seemingly strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals indicate good development practices, with all SQL queries utilizing prepared statements, no file operations or external HTTP requests identified, and the presence of nonce and capability checks. Taint analysis showing no unsanitized flows further reinforces this positive outlook.
However, a closer examination of the code signals reveals a concerning statistic: only 33% of output is properly escaped. This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the application and executed by users. While the vulnerability history is clean, the lack of robust output sanitization remains a critical weakness that could be exploited even without known CVEs or complex attack chains.
In conclusion, while the plugin's architecture and data handling appear robust, the low percentage of properly escaped output is a major security concern. Developers should prioritize addressing this issue to prevent potential XSS attacks. The clean vulnerability history is a positive sign, but it should not overshadow the immediate risk posed by unescaped output.
Key Concerns
- Low percentage of properly escaped output
Online Ordering Plus Custom Branded Apps For Clover Merchants Security Vulnerabilities
Online Ordering Plus Custom Branded Apps For Clover Merchants Code Analysis
Output Escaping
Online Ordering Plus Custom Branded Apps For Clover Merchants Attack Surface
WordPress Hooks 3
Maintenance & Trust
Online Ordering Plus Custom Branded Apps For Clover Merchants Maintenance & Trust
Maintenance Signals
Community Trust
Online Ordering Plus Custom Branded Apps For Clover Merchants Alternatives
Smart Online Order for Clover
clover-online-orders
Smart Online Order for Clover allows you to receive orders from your Wordpress website and have it sent directly to your Clover POS.
Clover Payments for WooCommerce
clover-payments-for-woocommerce
The Clover Payments plugin enables merchants that use WooCommerce to process online card payments using Clover.
WeeConnectPay – Clover Payment Gateway for WooCommerce
weeconnectpay
Accept payments easily and quickly with the Clover online Payment gateway by WeeConnectPay.
Clover Payment Gateway by Zaytech for WooCommerce
woo-clover-gateway-by-zaytech
Accept Clover POS payments from WooCommerce and auto-print orders to your Clover devices in minutes.
Online Ordering Plus Custom Branded Apps For Clover Merchants Developer Profile
1 plugin · 10 total installs
How We Detect Online Ordering Plus Custom Branded Apps For Clover Merchants
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/orderem-online-ordering-for-clover/css/style.cssHTML / DOM Fingerprints
iframename='munch_plugin_options[munch_url]'id='munch_url'name='munch_plugin_options[chkbox1]'id='plugin_chk1'<iframe class="iframe" src="" width="100%" height="1200px" frameborder="0" hspace="0" vspace="0" marginheight="0" marginwidth="0"></iframe>