
Product Delivery Date for WooCommerce – Lite Security & Risk Analysis
wordpress.org/plugins/product-delivery-date-for-woocommerce-liteChoose delivery/pickup dates & times on product page. Simplify delivery management by setting minimum delivery time, max deliveries per day & more.
Is Product Delivery Date for WooCommerce – Lite Safe to Use in 2026?
Generally Safe
Score 95/100Product Delivery Date for WooCommerce – Lite has a strong security track record. Known vulnerabilities have been patched promptly.
The 'product-delivery-date-for-woocommerce-lite' plugin exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a reasonable number of nonce and capability checks, several areas raise concerns. The presence of two AJAX handlers without authentication checks creates a significant attack surface for unauthorized actions.
The static analysis reveals a concerning use of the `unserialize` function, which can be a vector for remote code execution if not handled with extreme caution and validation of the serialized data. While no critical or high severity taint flows were found, the two flows with unsanitized paths are indicative of potential injection vulnerabilities. The plugin's vulnerability history shows a concerning pattern of five medium-severity CVEs, primarily related to Cross-site Scripting and Missing Authorization, suggesting a recurring weakness in input validation and access control.
Overall, the plugin has strengths in its database interaction and some security controls. However, the unprotected AJAX endpoints and the use of `unserialize` are critical weaknesses that demand immediate attention. The historical prevalence of medium-severity vulnerabilities related to input handling and authorization further amplifies the risk. While there are no currently unpatched vulnerabilities, the identified structural weaknesses and past issues suggest a need for more robust security development practices.
Key Concerns
- AJAX handlers without authentication checks
- Use of unserialize function
- Flows with unsanitized paths
- Past medium severity CVEs (5 total)
- 58% of outputs properly escaped
Product Delivery Date for WooCommerce – Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Product Delivery Date for WooCommerce – Lite <= 3.2.0 - Missing Authorization
Product Delivery Date for WooCommerce - Lite <= 2.8.0 - Reflected Cross-Site Scripting
Product Delivery Date for WooCommerce – Lite <= 2.7.3 - Reflected Cross-Site Scripting
Product Delivery Date for WooCommerce – Lite <= 2.7.2 - Missing Authorization
Product Delivery Date for WooCommerce – Lite <= 2.7.0 - Missing Authorization
Product Delivery Date for WooCommerce – Lite Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Product Delivery Date for WooCommerce – Lite Attack Surface
AJAX Handlers 5
WordPress Hooks 51
Maintenance & Trust
Product Delivery Date for WooCommerce – Lite Maintenance & Trust
Maintenance Signals
Community Trust
Product Delivery Date for WooCommerce – Lite Alternatives
Schedule Product Delivery Date for WooCommerce
schedule-product-delivery-date-for-woocommerce
Schedule Product Delivery Date plugin allows weekly or monthly deliveries with selected dates and quantities.
Delivery Countdown Timer
delivery-countdown-timer
Show the nextday delivery timer with text based on cut off time.
Product Delivery Date
product-delivery-date
Product Delivery Date is a plugin that allows you to customize the delivery date of a product. With this plugin, you can add a delivery date field to …
Delivery Date for WooCommerce
delivery-date-for-woocommerce
This plugin adds a delivery date field to the checkout page.
Delivery Man Management with delivery report for Woocommerce
deliveryman-management
This plugin manages deliveryman for woocommerce Product orders.
Product Delivery Date for WooCommerce – Lite Developer Profile
20 plugins · 160K total installs
How We Detect Product Delivery Date for WooCommerce – Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-delivery-date-for-woocommerce-lite/assets/css/product-delivery-date.css/wp-content/plugins/product-delivery-date-for-woocommerce-lite/assets/js/product-delivery-date.js/wp-content/plugins/product-delivery-date-for-woocommerce-lite/assets/js/product-delivery-date.jsproduct-delivery-date-for-woocommerce-lite/assets/css/product-delivery-date.css?ver=product-delivery-date-for-woocommerce-lite/assets/js/product-delivery-date.js?ver=HTML / DOM Fingerprints
prdd-lite-delivery-date-fieldprdd-lite-delivery-date-field-wrapprdd-lite-delivery-date-label<!-- Added by Product Delivery Date for WooCommerce Lite --><!-- Lite Version -->data-prdd-lite-product-iddata-prdd-lite-enable-delivery-dateprdd_lite_delivery_settings