Pending Order Bot Security & Risk Analysis

wordpress.org/plugins/pending-order-bot

Send automated reminders to customers about their pending WooCommerce orders, reduce abandoned carts and improve sales on your e-commerce website.

0 active installs v1.0.2 PHP 7.4+ WP 4.0+ Updated Feb 16, 2025
botorderpendingreminderwoocommerce
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEAug 17, 2025
Safety Verdict

Is Pending Order Bot Safe to Use in 2026?

Mostly Safe

Score 70/100

Pending Order Bot is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Aug 17, 2025Updated 1yr ago
Risk Assessment

The static analysis of the "pending-order-bot" v1.0.2 plugin indicates a generally strong security posture, with excellent adherence to best practices such as 100% output escaping and 100% prepared statement usage for SQL queries. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. Critically, the plugin has zero entry points without proper authorization checks and no identified taint flows, suggesting the code itself is robust against common injection and manipulation vulnerabilities.

However, a significant concern is the existence of one known, unpatched medium severity vulnerability. While the static analysis did not uncover active exploits in this version, the historical vulnerability indicates a potential weakness, specifically Cross-Site Scripting, that has not been remediated. The presence of only two nonce checks across the entire plugin, while not directly flagged as an issue due to the absence of AJAX/REST API entry points without auth checks, might suggest a limited use of WordPress's built-in security mechanisms which could be a missed opportunity for enhanced protection.

In conclusion, "pending-order-bot" v1.0.2 demonstrates good development practices in its current code, but the unpatched vulnerability poses a tangible risk. Users should be aware of this history and consider whether the benefits of the plugin outweigh the risk of this known flaw. The lack of extensive entry points and robust code sanitization is a positive, but the single unaddressed CVE is a significant drawback to its overall security.

Key Concerns

  • Unpatched CVE
Vulnerabilities
1 published

Pending Order Bot Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49892medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pending Order Bot <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Aug 17, 2025Unpatched
Version History

Pending Order Bot Release Timeline

v1.0.2Current1 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Apr 16, 2026

Pending Order Bot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
36 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped36 total outputs
Attack Surface

Pending Order Bot Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initinc/Services/Admin.php:27
actionadmin_menuinc/Services/Admin.php:28
actionadmin_enqueue_scriptsinc/Services/Admin.php:29
actioninitinc/Services/Boot.php:25
actionwp_loadedinc/Services/Scheduler.php:27
actionpending_ordersinc/Services/Scheduler.php:28
filtercron_schedulesinc/Services/Scheduler.php:29
actionadmin_noticespending-order-bot.php:27

Scheduled Events 1

pending_orders
Maintenance & Trust

Pending Order Bot Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 16, 2025
PHP min version7.4
Downloads730

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pending Order Bot Developer Profile

badasswp

14 plugins · 3K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pending Order Bot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pending-order-bot/styles.css
Version Parameters
pending-order-bot/styles.css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
wrap
FAQ

Frequently Asked Questions about Pending Order Bot