
Pending Order Bot Security & Risk Analysis
wordpress.org/plugins/pending-order-botSend automated reminders to customers about their pending WooCommerce orders, reduce abandoned carts and improve sales on your e-commerce website.
Is Pending Order Bot Safe to Use in 2026?
Mostly Safe
Score 71/100Pending Order Bot is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The static analysis of the "pending-order-bot" v1.0.2 plugin indicates a generally strong security posture, with excellent adherence to best practices such as 100% output escaping and 100% prepared statement usage for SQL queries. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. Critically, the plugin has zero entry points without proper authorization checks and no identified taint flows, suggesting the code itself is robust against common injection and manipulation vulnerabilities.
However, a significant concern is the existence of one known, unpatched medium severity vulnerability. While the static analysis did not uncover active exploits in this version, the historical vulnerability indicates a potential weakness, specifically Cross-Site Scripting, that has not been remediated. The presence of only two nonce checks across the entire plugin, while not directly flagged as an issue due to the absence of AJAX/REST API entry points without auth checks, might suggest a limited use of WordPress's built-in security mechanisms which could be a missed opportunity for enhanced protection.
In conclusion, "pending-order-bot" v1.0.2 demonstrates good development practices in its current code, but the unpatched vulnerability poses a tangible risk. Users should be aware of this history and consider whether the benefits of the plugin outweigh the risk of this known flaw. The lack of extensive entry points and robust code sanitization is a positive, but the single unaddressed CVE is a significant drawback to its overall security.
Key Concerns
- Unpatched CVE
Pending Order Bot Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Pending Order Bot <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Pending Order Bot Release Timeline
Pending Order Bot Code Analysis
Output Escaping
Pending Order Bot Attack Surface
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
Pending Order Bot Maintenance & Trust
Maintenance Signals
Community Trust
Pending Order Bot Alternatives
Live Chat & AI Chatbot – onWebChat
onwebchat
Live chat + 24/7 AI chatbot that auto-syncs your WooCommerce products and answers "where is my order?" with live data. Works on any WP site.
Push Anything To Social
phongmy-push-anything-to-social
This's plugins help Owner push order from Woocommerce to Facebook messenger quickly base On CallmeBot API
Storebird AI Chat for WooCommerce
storebird-ai-chat-for-woocommerce
WooCommerce AI chatbot, sales assistant & email AI: answers product questions, tracks orders and drafts email replies from your live store data.
Brightery Woo-Order-Api
brightery-woo-order-api
A secure, lightweight custom REST API designed to connect WooCommerce order tracking to customer service bots (ManyChat, Dialogflow, custom AI).
Checkout Bot Shield
checkout-bot-shield
Blocks suspicious, rapid-fire checkout attempts so fake orders and carding bots cannot overwhelm your WooCommerce store.
Pending Order Bot Developer Profile
15 plugins · 2K total installs
How We Detect Pending Order Bot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pending-order-bot/styles.csspending-order-bot/styles.css?ver=1.0.0HTML / DOM Fingerprints
wrap