RD Order Note Templates for WooCommerce Security & Risk Analysis

wordpress.org/plugins/rd-wc-enhanced-order-notes

Create predefined templates for order notes that you can apply to orders

70 active installs v1.1.2 PHP 7.2+ WP 5.0+ Updated Mar 1, 2026
admin-dashboardnotesorderstemplateswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is RD Order Note Templates for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

RD Order Note Templates for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'rd-wc-enhanced-order-notes' plugin version 1.1.2 demonstrates generally good security practices. The static analysis reveals a low attack surface with only one entry point, an AJAX handler. Crucially, 100% of SQL queries are prepared statements, and a high percentage of output is properly escaped, indicating a strong defense against common injection and XSS vulnerabilities. The plugin also incorporates a healthy number of nonce and capability checks, further bolstering its security.

However, a significant concern arises from the single AJAX handler lacking authentication checks. This presents an unprotected entry point that could potentially be exploited if it performs sensitive actions or exposes information. While the taint analysis found no critical or high-severity unsanitized paths, the presence of an unprotected AJAX endpoint warrants careful consideration. The plugin's history of zero recorded vulnerabilities is a positive indicator of its development quality and adherence to secure coding practices, suggesting the developers are proactive about security.

Key Concerns

  • AJAX handler without authentication check
Vulnerabilities
None known

RD Order Note Templates for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RD Order Note Templates for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
90 escaped
Nonce Checks
11
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped93 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
get_template_content (classes\class.rdwceon-ajax.php:234)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

RD Order Note Templates for WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_rdwceon_do_ajaxclasses\class.rdwceon-manager.php:102
WordPress Hooks 8
actionadmin_initclasses\class.rdwceon-manager.php:98
actionadmin_menuclasses\class.rdwceon-manager.php:99
actionadmin_noticesclasses\class.rdwceon-manager.php:100
actionadmin_enqueue_scriptsclasses\class.rdwceon-manager.php:101
actionadd_meta_boxes_shop_orderclasses\class.rdwceon-manager.php:103
actionadd_meta_boxes_woocommerce_page_wc-ordersclasses\class.rdwceon-manager.php:104
actionbefore_woocommerce_initclasses\class.rdwceon-manager.php:105
filterscript_loader_tagclasses\class.rdwceon-manager.php:110
Maintenance & Trust

RD Order Note Templates for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 1, 2026
PHP min version7.2
Downloads1K

Community Trust

Rating100/100
Number of ratings3
Active installs70
Developer Profile

RD Order Note Templates for WooCommerce Developer Profile

camper2020

2 plugins · 370 total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
398 days
View full developer profile
Detection Fingerprints

How We Detect RD Order Note Templates for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rd-wc-enhanced-order-notes/css/admin-menu.css/wp-content/plugins/rd-wc-enhanced-order-notes/css/admin.css/wp-content/plugins/rd-wc-enhanced-order-notes/js/admin.js
Script Paths
https://cdn.featurebot.com/widget.js
Version Parameters
rdwceon-admin-menu/css/admin-menu.css?ver=rdwceon-admin/css/admin.css?ver=rdwceon-admin/js/admin.js?ver=featurebot-widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
rdwceon-settingsrdwceon-admin-menu
Data Attributes
data-key="cmk171ayc000701r26j8436xq"
JS Globals
RDWCEONSettings
FAQ

Frequently Asked Questions about RD Order Note Templates for WooCommerce