Order Departments for WooCommerce Security & Risk Analysis

wordpress.org/plugins/runthings-wc-order-departments

Automatically assign WooCommerce orders to departments based on products/categories with email routing and AutomateWoo integration.

0 active installs v1.1.1 PHP 7.4+ WP 6.3+ Updated Jan 7, 2026
automationdepartmentsemail-routingorderswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Order Departments for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Order Departments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of the "runthings-wc-order-departments" v1.1.1 plugin reveals a very strong security posture from a code perspective. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, the plugin shows no external HTTP requests, file operations, or bundled libraries, which reduces potential attack vectors. The absence of any taint analysis findings or identified CVEs in its history further contributes to this positive outlook.

However, a significant concern arises from the complete lack of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) that are protected by authentication or capability checks. While the current version might not have exposed functionality, this zero-attack surface without authorization is highly unusual and could indicate that either the plugin's core functionality is not exposed via standard WordPress mechanisms, or there is an oversight in the static analysis tool's ability to detect these entry points. The 0 nonce checks and 0 capability checks also point to a potential lack of granular access control where it might be needed if functionality were to be added or discovered.

In conclusion, the code itself appears robust and follows secure coding practices. The main weakness lies in the potential for an undiscovered or unmonitored attack surface due to the reported lack of any entry points with authorization. While the vulnerability history is clean, this could be more a reflection of the lack of detected exposure rather than inherent invulnerability. A thorough manual review of the plugin's functionality and its integration points within WordPress would be prudent to ensure no hidden security risks exist.

Key Concerns

  • 0 capability checks found
  • 0 nonce checks found
  • 0 unprotected entry points reported
Vulnerabilities
None known

Order Departments for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Order Departments for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Order Departments for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionbefore_woocommerce_initrunthings-wc-order-departments.php:63
actionadmin_initrunthings-wc-order-departments.php:65
actionadmin_menurunthings-wc-order-departments.php:66
actionadmin_menurunthings-wc-order-departments.php:67
actionwoocommerce_order_list_table_restrict_manage_ordersrunthings-wc-order-departments.php:90
filterwoocommerce_order_list_table_prepare_items_query_argsrunthings-wc-order-departments.php:91
actionrestrict_manage_postsrunthings-wc-order-departments.php:94
Maintenance & Trust

Order Departments for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 7, 2026
PHP min version7.4
Downloads298

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Order Departments for WooCommerce Developer Profile

runthings.dev

11 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect Order Departments for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Order Departments for WooCommerce