
Pending Order Bot Security & Risk Analysis
wordpress.org/plugins/pending-order-botSend automated reminders to customers about their pending WooCommerce orders, reduce abandoned carts and improve sales on your e-commerce website.
Is Pending Order Bot Safe to Use in 2026?
Mostly Safe
Score 70/100Pending Order Bot is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The static analysis of the "pending-order-bot" v1.0.2 plugin indicates a generally strong security posture, with excellent adherence to best practices such as 100% output escaping and 100% prepared statement usage for SQL queries. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. Critically, the plugin has zero entry points without proper authorization checks and no identified taint flows, suggesting the code itself is robust against common injection and manipulation vulnerabilities.
However, a significant concern is the existence of one known, unpatched medium severity vulnerability. While the static analysis did not uncover active exploits in this version, the historical vulnerability indicates a potential weakness, specifically Cross-Site Scripting, that has not been remediated. The presence of only two nonce checks across the entire plugin, while not directly flagged as an issue due to the absence of AJAX/REST API entry points without auth checks, might suggest a limited use of WordPress's built-in security mechanisms which could be a missed opportunity for enhanced protection.
In conclusion, "pending-order-bot" v1.0.2 demonstrates good development practices in its current code, but the unpatched vulnerability poses a tangible risk. Users should be aware of this history and consider whether the benefits of the plugin outweigh the risk of this known flaw. The lack of extensive entry points and robust code sanitization is a positive, but the single unaddressed CVE is a significant drawback to its overall security.
Key Concerns
- Unpatched CVE
Pending Order Bot Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Pending Order Bot <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Pending Order Bot Release Timeline
Pending Order Bot Code Analysis
Output Escaping
Pending Order Bot Attack Surface
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
Pending Order Bot Maintenance & Trust
Maintenance Signals
Community Trust
Pending Order Bot Alternatives
Push Anything To Social
phongmy-push-anything-to-social
This's plugins help Owner push order from Woocommerce to Facebook messenger quickly base On CallmeBot API
Brightery Woo-Order-Api
brightery-woo-order-api
A secure, lightweight custom REST API designed to connect WooCommerce order tracking to customer service bots (ManyChat, Dialogflow, custom AI).
Easy Re-Order Reminder for WooCommerce
easy-re-order-reminder-for-woocommerce
Automatically remind customers to reorder products after a defined time period. Increase repeat sales with automated email reminders.
LuxCord Order Notification
luxcord-order-notification
Premium WooCommerce order notifications to Discord. Stay updated on every sale with beautiful, customizable messages.
Order Reminder For WooCommerce
order-reminder-for-woo
Automatically sets the caption of all images to your site's title.
Pending Order Bot Developer Profile
14 plugins · 3K total installs
How We Detect Pending Order Bot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pending-order-bot/styles.csspending-order-bot/styles.css?ver=1.0.0HTML / DOM Fingerprints
wrap