
Phone Orders for WooCommerce Security & Risk Analysis
wordpress.org/plugins/phone-orders-for-woocommerceEasy way to take a manual/phone order in WooCommerce
Is Phone Orders for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Phone Orders for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The phone-orders-for-woocommerce plugin, version 3.10.3, exhibits a generally good security posture with a well-protected attack surface. The static analysis indicates no direct entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected. The code also shows a strong adherence to secure coding practices, with a high percentage of SQL queries using prepared statements and a large majority of outputs being properly escaped. The presence of nonce and capability checks further bolsters its security. However, the plugin does make external HTTP requests, which can be a potential vector for supply chain attacks or information disclosure if not handled with extreme care. The taint analysis revealed one flow with an unsanitized path, which, while not classified as critical or high severity in this analysis, warrants attention as it could potentially be exploited under specific conditions. The vulnerability history shows a past of two known CVEs, one of high and one of medium severity, with the last vulnerability recorded in October 2022. While there are currently no unpatched vulnerabilities, the historical presence of high-severity issues, particularly CSRF and Missing Authorization, suggests a recurring need for diligent patching and potentially deeper code review to ensure such vulnerabilities do not resurface. Overall, the plugin has implemented many good security practices, but the historical vulnerabilities and the single taint flow with an unsanitized path indicate areas that require ongoing vigilance.
Key Concerns
- Historical High Severity Vulnerability
- Historical Medium Severity Vulnerability
- Taint flow with unsanitized path
- External HTTP requests (potential risk)
Phone Orders for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Phone Orders for WooCommerce <= 3.7.1 - Cross-Site Request Forgery
Phone Orders for WooCommerce <= 3.7.1 - Missing Authorization
Phone Orders for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Phone Orders for WooCommerce Attack Surface
WordPress Hooks 80
Maintenance & Trust
Phone Orders for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Phone Orders for WooCommerce Alternatives
CrossPeak OMS for WooCommerce
crosspeakoms
Easy eCommerce Order Management
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Phone Orders for WooCommerce Developer Profile
3 plugins · 121K total installs
How We Detect Phone Orders for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/phone-orders-for-woocommerce/assets/css/admin.css/wp-content/plugins/phone-orders-for-woocommerce/assets/css/frontend.css/wp-content/plugins/phone-orders-for-woocommerce/assets/js/admin-phone-orders.js/wp-content/plugins/phone-orders-for-woocommerce/assets/js/frontend-phone-orders.js/wp-content/plugins/phone-orders-for-woocommerce/assets/js/wpo-product-search.js/wp-content/plugins/phone-orders-for-woocommerce/assets/js/admin-phone-orders.js/wp-content/plugins/phone-orders-for-woocommerce/assets/js/frontend-phone-orders.js/wp-content/plugins/phone-orders-for-woocommerce/assets/js/wpo-product-search.jsphone-orders-for-woocommerce/assets/css/admin.css?ver=phone-orders-for-woocommerce/assets/css/frontend.css?ver=phone-orders-for-woocommerce/assets/js/admin-phone-orders.js?ver=phone-orders-for-woocommerce/assets/js/frontend-phone-orders.js?ver=phone-orders-for-woocommerce/assets/js/wpo-product-search.js?ver=HTML / DOM Fingerprints
phone_orders_add_product_inputphone_orders_add_product_namephone_orders_add_product_search_resultsphone_orders_add_product_buttonphone_orders_product_qtyphone_orders_price_inputphone_orders_discount_inputphone_orders_calc_discount_span+20 more<!-- Phone Orders for WooCommerce --><!-- WPO END PHONE ORDERS FOR WOOCOMMERCE -->data-product_iddata-product_namedata-product_skudata-product_pricedata-product_stockdata-wpo-product-id+27 morewpo_admin_paramswpo_frontend_params/wp-json/phone-orders-for-woocommerce/v1/product_search