
cancel unpaid order for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-cancel-unpaid-orderWc Cancel Order.
Is cancel unpaid order for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100cancel unpaid order for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-cancel-unpaid-order" v5.8 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. Furthermore, the code signals show no dangerous functions, no SQL queries executed without prepared statements, no file operations, and no external HTTP requests, all of which are positive security indicators. The vulnerability history is also clean, with zero known CVEs, suggesting a history of secure development.
However, there are a few areas for concern. The output escaping is only properly handled for 50% of the identified outputs, which could leave the plugin vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not sufficiently sanitized before being displayed. Additionally, the complete lack of nonce checks and capability checks, while not directly problematic given the zero entry points identified, represents a potential oversight. If future development introduces new entry points without these standard security measures, it could create vulnerabilities. The taint analysis shows no critical or high severity flows, but the analysis itself reported zero flows, which might suggest an incomplete analysis or that the plugin simply doesn't process user input in a way that would create such flows within the scope of the analysis performed.
In conclusion, the plugin is currently in a strong security position due to its limited attack surface and absence of critical code-level vulnerabilities. The primary weakness lies in the incomplete output escaping, which warrants attention. The lack of recorded vulnerabilities is positive, but the absence of nonce and capability checks suggests a potential for future risks if not addressed proactively. The plugin is generally well-developed from a security perspective, but the unescaped output remains a notable concern.
Key Concerns
- 50% of outputs are not properly escaped
- No nonce checks implemented
- No capability checks implemented
cancel unpaid order for WooCommerce Security Vulnerabilities
cancel unpaid order for WooCommerce Code Analysis
Output Escaping
cancel unpaid order for WooCommerce Attack Surface
WordPress Hooks 3
Maintenance & Trust
cancel unpaid order for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
cancel unpaid order for WooCommerce Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
cancel unpaid order for WooCommerce Developer Profile
2 plugins · 10 total installs
How We Detect cancel unpaid order for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
mbottomwrapname="woo-cancelorder-text1"name="woo-cancelorder-text2"name="woo-cancelorder-text3"name="woo-cancelorder-text4"name="woo-cancelorder-secondtext1"name="woo-cancelorder-thirdtext1"