
RD Order Modifier for WooCommerce Security & Risk Analysis
wordpress.org/plugins/rd-wc-order-modifierAllows editing order items pricing inclusive of tax or VAT and using unit cost instead of items totals.
Is RD Order Modifier for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100RD Order Modifier for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The 'rd-wc-order-modifier' plugin version 1.1.5 demonstrates a generally strong security posture with several good practices in place. The static analysis reveals a small attack surface with no unprotected entry points, and excellent adherence to secure coding principles like prepared statements for all SQL queries and robust output escaping (99%). The presence of nonce and capability checks on the identified entry points further bolsters its security. However, a past vulnerability history, specifically one medium severity CSRF vulnerability, should not be entirely overlooked, even though it is currently patched. While the taint analysis shows no concerning flows, and there are no obvious dangerous functions or file operations, the single historical vulnerability suggests a potential for oversight in secure coding practices in prior versions or specific edge cases.
Overall, the plugin appears to be well-maintained and conscious of security. The current version has effectively addressed past issues and implemented strong defensive measures. The minimal attack surface and near-perfect code signals are commendable. The main area for continued vigilance would be ensuring that future updates maintain this high standard and that any third-party components or future code additions are thoroughly vetted for potential vulnerabilities, particularly those related to user input handling that could lead to CSRF or other injection-type attacks. The strength in prepared statements and output escaping is a significant mitigating factor for many common web vulnerabilities.
Key Concerns
- Past medium severity CVE (CSRF)
RD Order Modifier for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
RD Order Modifier for WooCommerce <= 1.0.5 - Cross-Site Request Forgery
RD Order Modifier for WooCommerce Code Analysis
Output Escaping
RD Order Modifier for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
RD Order Modifier for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
RD Order Modifier for WooCommerce Alternatives
WooCommerce Tax (formerly WooCommerce Shipping & Tax)
woocommerce-services
We’re here to help with tax rates: collect accurate sales tax, automatically.
EU VAT Assistant for WooCommerce
woocommerce-eu-vat-assistant
Extends the standard WooCommerce sale process and assists in achieving compliance with the new EU VAT regime starting on the 1st of January 2015.
Contribuinte Checkout
contribuinte-checkout
With this plugin you can add VAT and VIES support to your WooCommerce store. The VAT field will be saved as '_billing_vat'.
Tax Switch for WooCommerce
tax-switch-for-woocommerce
Let customers toggle between inclusive and exclusive VAT pricing in your WooCommerce store.
Tax Exemption for WooCommerce
tax-exemption-woo
Tax Exemption plugin for WooCommerce. Allow customers to declare tax / VAT exemption eligibility, and provide tax exemption details.
RD Order Modifier for WooCommerce Developer Profile
2 plugins · 370 total installs
How We Detect RD Order Modifier for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rd-wc-order-modifier/css/rdwcom-admin.css/wp-content/plugins/rd-wc-order-modifier/js/rdwcom-admin.js/wp-content/plugins/rd-wc-order-modifier/js/rdwcom-admin.jsrdwcom-admin.css?ver=rdwcom-admin.js?ver=HTML / DOM Fingerprints
rdwcom-review-upgrade-noticeid="rdwcom-review-upgrade-notice"rdwcom_hide_review_upgrade_notice_ajax_urlrdwcom_hide_tax_item_required_notice_ajax_url