
Track Order History for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-past-ordersWoocommerce supportive plugin for easy customer history and previously placed orders.
Is Track Order History for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Track Order History for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-past-orders" v1.4 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing SQL queries exclusively through prepared statements, and generally escaping output well. The absence of file operations, external HTTP requests, and known historical vulnerabilities is also a strong indicator of secure development. However, the plugin presents significant concerns due to its attack surface. With two AJAX handlers, both lacking any authentication or capability checks, there's a direct and unprotected entry point for malicious actors to potentially exploit. This is a critical oversight that significantly increases the risk of unauthorized actions or information disclosure.
The lack of nonce checks on these AJAX handlers, combined with the absence of capability checks, means that any unauthenticated user could potentially trigger these functionalities. While the static analysis did not reveal any critical taint flows or unsanitized paths, the unprotected entry points mean that if any vulnerabilities were introduced in the future within these handlers, they would be immediately exploitable by unauthenticated users. The vulnerability history being clean is positive, but it does not negate the inherent risk posed by the current design of the unprotected AJAX endpoints. In conclusion, while the plugin has strengths in its handling of SQL and output, the presence of unprotected AJAX handlers is a major weakness that elevates the overall risk considerably.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
Track Order History for WooCommerce Security Vulnerabilities
Track Order History for WooCommerce Code Analysis
Output Escaping
Track Order History for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
Track Order History for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Track Order History for WooCommerce Alternatives
Order Status History for WooCommerce
order-status-history-for-woocommerce
Speed up your daily processing of orders by getting to know more about who's ordering. Themed order status color swatches, Reports, CSV, free.
Customer Order History for WooCommerce
woohistory
Customer Order History Plugin for WooCommerce. View Previous Orders from the same customer, even if order as guest.
PureDevs Customer History for WooCommerce
puredevs-customer-history-for-woocommerce
Track your WooCommerce customers' order history, spending, and behaviour from a clean admin dashboard.
Sequential Order Numbers for WooCommerce
woocommerce-sequential-order-numbers
This plugin extends WooCommerce by setting sequential order numbers for new orders.
WC Order Test
woo-order-test
Test your WooCommerce order process in seconds to ensure your checkout works correctly.
Track Order History for WooCommerce Developer Profile
6 plugins · 80 total installs
How We Detect Track Order History for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-past-orders/assets/css/wptoh-admin.css/wp-content/plugins/wc-past-orders/assets/js/wptoh-admin.jswc-past-orders/assets/js/wptoh-admin.js?verHTML / DOM Fingerprints
column-order_keydata-order_idadmin_ajax_call