
Place Order Without Payment for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-place-order-without-paymentPlace Order Without Payment for WooCommerce will allow users to place orders directly without payment.
Is Place Order Without Payment for WooCommerce Safe to Use in 2026?
Generally Safe
Score 97/100Place Order Without Payment for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "wc-place-order-without-payment" plugin v2.7.5 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified attack vectors through AJAX, REST API, shortcodes, or cron events. The code demonstrates good practices with 100% of SQL queries using prepared statements and a high rate of output escaping (90%). There are no indications of dangerous functions, file operations, external HTTP requests, or unsanitized taint flows. This suggests a developer mindful of common web vulnerabilities.
However, a significant concern is the plugin's historical vulnerability record. It has one known critical CVE related to PHP Remote File Inclusion, and while currently unpatched, the historical data indicates a past critical vulnerability. The absence of nonce checks across the entire plugin is also a notable weakness, especially if there are any entry points that were not detected or are implicitly present. The inclusion of Freemius v1.0, while a bundled library, could pose a risk if it contains known vulnerabilities or if it is not kept up-to-date.
In conclusion, while the current code analysis suggests a relatively clean implementation with good SQL and output handling, the past critical vulnerability and lack of comprehensive nonce checks warrant caution. Developers should prioritize addressing the historical vulnerability and implement proper nonce checks for any potential future entry points to improve the overall security. The bundled Freemius library should also be monitored for updates.
Key Concerns
- Historically critical unpatched CVE
- 0 Nonce checks
- Bundled outdated library (Freemius v1.0)
Place Order Without Payment for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WC Place Order Without Payment <= 2.6.7 - Unauthenticated Local File Inclusion
Place Order Without Payment for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Place Order Without Payment for WooCommerce Attack Surface
WordPress Hooks 54
Maintenance & Trust
Place Order Without Payment for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Place Order Without Payment for WooCommerce Alternatives
PRENA – Product Pre-Orders for WooCommerce
product-pre-orders-for-woo
Easily set up your store to accept orders for unreleased products, allowing customers to purchase items in advance.
Boopis WooCommerce RFQ
boopis-woocommerce-rfq
Replaces products with a price of zero to an open form for inquiry
Approve Orders for WooCommerce
approve-orders
Approve Orders for WooCommerce adds an order approval workflow to your WooCommerce store, giving you greater control over order processing.
Pre-Orders for WooCommerce – PreCart
precart
Easily enable preorders for your WooCommerce store. Allow customers to pre-order products, set release dates, accept payments, and manage everything f …
Pre-Orders, Product Labels, Buy Now, Quick View, Discount Rules and More for WooCommerce – Merchant
merchant
Enhance your WooCommerce store with 40+ modules including Pre-Orders, Product Labels, Buy Now, Quick View & more
Place Order Without Payment for WooCommerce Developer Profile
7 plugins · 14K total installs
How We Detect Place Order Without Payment for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-place-order-without-payment/assets/css/wpowp-admin.css/wp-content/plugins/wc-place-order-without-payment/assets/css/wpowp-frontend.css/wp-content/plugins/wc-place-order-without-payment/assets/js/wpowp-admin.js/wp-content/plugins/wc-place-order-without-payment/assets/js/wpowp-frontend.js/wp-content/plugins/wc-place-order-without-payment/vendor/freemius/wordpress-sdk/start.phpwc-place-order-without-payment/assets/css/wpowp-admin.css?ver=wc-place-order-without-payment/assets/css/wpowp-frontend.css?ver=wc-place-order-without-payment/assets/js/wpowp-admin.js?ver=wc-place-order-without-payment/assets/js/wpowp-frontend.js?ver=HTML / DOM Fingerprints
wpowp-settings-wrapper<!-- Plugin Name: Place Order Without Payment for WooCommerce -->data-wpowp-settingsWPOWP_AdminWPOWP_FrontWPOWP_Rest_APIwpowp_fswpowp_plugin_slugwpowp_plugin_prefix+1 more/wp-json/wpowp/v1/settings/wp-json/wpowp/v1/rules