
WC Order Split Security & Risk Analysis
wordpress.org/plugins/wc-order-splitA user friendly plugin to split WooCommerce orders.
Is WC Order Split Safe to Use in 2026?
Generally Safe
Score 92/100WC Order Split has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-order-split" plugin version 1.7.9 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of known CVEs and the careful use of prepared statements for SQL queries are significant strengths. Furthermore, the fact that there are no identified dangerous functions, file operations, or external HTTP requests suggests a well-contained codebase.
However, a notable concern lies in the output escaping. With 57 total outputs and only 42% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that data processed by the plugin and displayed to users might not be adequately sanitized, potentially allowing malicious scripts to be injected and executed in the user's browser.
While the plugin's attack surface appears limited (0 entry points), the potential for XSS due to insufficient output escaping represents the most immediate and tangible risk. The vulnerability history being clear of any past issues is a positive indicator of developer diligence, but it does not negate the current identified code quality concern. Overall, the plugin is built on solid foundations regarding data handling and access control, but the lack of comprehensive output sanitization requires attention.
Key Concerns
- Insufficient output escaping
WC Order Split Security Vulnerabilities
WC Order Split Code Analysis
Output Escaping
Data Flow Analysis
WC Order Split Attack Surface
WordPress Hooks 7
Maintenance & Trust
WC Order Split Maintenance & Trust
Maintenance Signals
Community Trust
WC Order Split Alternatives
Pre-Orders for WooCommerce
pre-orders-for-woocommerce
Ultimate Pre-Orders Plugin for WooCommerce.
Order Splitter for WooCommerce
woo-order-splitter
A great plugin to split WooCommerce orders. You can duplicate orders as well.
WC Backorder Split
wc-backorder-split
A simple plugin that helps you split the WooCommerce order for the products that you do not have in stock.
Pre-Orders – Extended Stock Status for WooCommerce
pre-orders-wc
Just another product stock status for your WooCommerce store.
Pre-Orders for WooCommerce – PreCart
precart
Easily enable preorders for your WooCommerce store. Allow customers to pre-order products, set release dates, accept payments, and manage everything f …
WC Order Split Developer Profile
40 plugins · 33K total installs
How We Detect WC Order Split
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-order-split/css/admin-style.css/wp-content/plugins/wc-order-split/css/bootstrap.min.css/wp-content/plugins/wc-order-split/css/fontawesome.min.css/wp-content/plugins/wc-order-split/js/admin-scripts.js/wp-content/plugins/wc-order-split/js/bootstrap.min.js/wp-content/plugins/wc-order-split/js/fontawesome.min.jsjs/bootstrap.min.jscss/bootstrap.min.cssjs/fontawesome.min.jscss/fontawesome.min.cssjs/admin-scripts.jscss/admin-style.csswc-order-split/js/bootstrap.min.js?ver=1.0wc-order-split/css/bootstrap.min.csswc-order-split/js/fontawesome.min.js?ver=1.0wc-order-split/css/fontawesome.min.csswc-order-split/js/admin-scripts.js?ver=1.0wc-order-split/css/admin-style.cssHTML / DOM Fingerprints
wcos_btnwcos_btn_donedata-wcos-split-nonce