
Shop as Client for WooCommerce – Manual, Phone & Email Orders Security & Risk Analysis
wordpress.org/plugins/shop-as-clientCreate manual, phone, POS, or email orders in WooCommerce. Shop admins and staff can place customer orders directly from the frontend checkout.
Is Shop as Client for WooCommerce – Manual, Phone & Email Orders Safe to Use in 2026?
Generally Safe
Score 100/100Shop as Client for WooCommerce – Manual, Phone & Email Orders has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'shop-as-client' v7.3 plugin exhibits a mixed security posture. On the positive side, the code demonstrates good practices in several key areas. All SQL queries are properly prepared, and all output is correctly escaped, indicating a strong defense against common injection and cross-site scripting vulnerabilities. The absence of file operations and external HTTP requests further reduces the potential attack surface. The plugin also has a clean vulnerability history, with no recorded CVEs, suggesting a history of reasonably secure development.
However, a significant concern is the presence of an unprotected AJAX handler. This represents a critical entry point that lacks any authentication or capability checks. While no critical or high severity taint flows were identified, and dangerous functions are not used, this single unprotected AJAX endpoint could be exploited by an unauthenticated user to perform unintended actions, depending on what that handler does. The absence of nonce checks on this AJAX handler further exacerbates this risk, making it susceptible to Cross-Site Request Forgery (CSRF) attacks if the AJAX action is sensitive.
In conclusion, while the plugin benefits from secure coding practices in SQL and output handling and a lack of past vulnerabilities, the single unprotected AJAX endpoint is a notable weakness. This oversight introduces a tangible risk of unauthorized access and potential exploitation. Mitigation efforts should focus on securing this entry point immediately.
Key Concerns
- AJAX handler without authentication/capability checks
- AJAX handler without nonce check
Shop as Client for WooCommerce – Manual, Phone & Email Orders Security Vulnerabilities
Shop as Client for WooCommerce – Manual, Phone & Email Orders Release Timeline
Shop as Client for WooCommerce – Manual, Phone & Email Orders Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Shop as Client for WooCommerce – Manual, Phone & Email Orders Attack Surface
AJAX Handlers 1
WordPress Hooks 24
Maintenance & Trust
Shop as Client for WooCommerce – Manual, Phone & Email Orders Maintenance & Trust
Maintenance Signals
Community Trust
Shop as Client for WooCommerce – Manual, Phone & Email Orders Alternatives
iyzico for WooCommerce
iyzico-woocommerce
iyzico latest payment processing solution. Accept credit/debit cards, alternative digital wallets and bank accounts.
Kustom Checkout for WooCommerce
klarna-checkout-for-woocommerce
The leading checkout in the Nordics, built for higher conversion and returning shoppers. Easy to integrate, supports Klarna and all popular payment me …
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler
fluent-cart
Sell Subscriptions, Physical Products, Digital Downloads easier than ever. Built for performance, scalability, and flexibility.
Payment Button for PayPal
wp-paypal
Easily accept payment in WordPress by adding a PayPal button to your website. Add PayPal Buy Now, Add to Cart, Subscription or Donation button.
GoDaddy Payments for WooCommerce
godaddy-payments
A payment gateway plugin that enables your U.S. or Canadian business to accept credit card payments directly on your WooCommerce site.
Shop as Client for WooCommerce – Manual, Phone & Email Orders Developer Profile
9 plugins · 12K total installs
How We Detect Shop as Client for WooCommerce – Manual, Phone & Email Orders
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shop-as-client/assets/css/shop-as-client.css/wp-content/plugins/shop-as-client/assets/js/shop-as-client.js/wp-content/plugins/shop-as-client/assets/js/shop-as-client.jsshop-as-client/assets/css/shop-as-client.css?ver=shop-as-client/assets/js/shop-as-client.js?ver=HTML / DOM Fingerprints
shop-as-client-pro-settingsshop_as_client_pro_license_keyid="shop_as_client_options"