Online Ordering Plus Custom Branded Apps For Clover Merchants Security & Risk Analysis

wordpress.org/plugins/orderem-online-ordering-for-clover

OrderEm Online Orders for Clover allows you to receive orders from your Wordpress website and have it sent directly to your Clover POS

10 active installs v1.0 PHP 5.5+ WP 3.7+ Updated Oct 18, 2018
cloverclover-online-ordersmunchem-online-ordersonline-orders-for-clover
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Online Ordering Plus Custom Branded Apps For Clover Merchants Safe to Use in 2026?

Generally Safe

Score 85/100

Online Ordering Plus Custom Branded Apps For Clover Merchants has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "orderem-online-ordering-for-clover" plugin version 1.0 exhibits a seemingly strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals indicate good development practices, with all SQL queries utilizing prepared statements, no file operations or external HTTP requests identified, and the presence of nonce and capability checks. Taint analysis showing no unsanitized flows further reinforces this positive outlook.

However, a closer examination of the code signals reveals a concerning statistic: only 33% of output is properly escaped. This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the application and executed by users. While the vulnerability history is clean, the lack of robust output sanitization remains a critical weakness that could be exploited even without known CVEs or complex attack chains.

In conclusion, while the plugin's architecture and data handling appear robust, the low percentage of properly escaped output is a major security concern. Developers should prioritize addressing this issue to prevent potential XSS attacks. The clean vulnerability history is a positive sign, but it should not overshadow the immediate risk posed by unescaped output.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Online Ordering Plus Custom Branded Apps For Clover Merchants Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Online Ordering Plus Custom Branded Apps For Clover Merchants Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Attack Surface

Online Ordering Plus Custom Branded Apps For Clover Merchants Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuindex.php:15
actionadmin_menuindex.php:16
actionadmin_initindex.php:186
Maintenance & Trust

Online Ordering Plus Custom Branded Apps For Clover Merchants Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedOct 18, 2018
PHP min version5.5
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Online Ordering Plus Custom Branded Apps For Clover Merchants Developer Profile

orderem

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Online Ordering Plus Custom Branded Apps For Clover Merchants

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orderem-online-ordering-for-clover/css/style.css

HTML / DOM Fingerprints

CSS Classes
iframe
Data Attributes
name='munch_plugin_options[munch_url]'id='munch_url'name='munch_plugin_options[chkbox1]'id='plugin_chk1'
Shortcode Output
<iframe class="iframe" src="" width="100%" height="1200px" frameborder="0" hspace="0" vspace="0" marginheight="0" marginwidth="0"></iframe>
FAQ

Frequently Asked Questions about Online Ordering Plus Custom Branded Apps For Clover Merchants