
Whats Order Security & Risk Analysis
wordpress.org/plugins/whats-orderAutomatically creates a shopping cart from images inserted in posts a/o articles. Order requests are sent to seller by Whatsapp messages.
Is Whats Order Safe to Use in 2026?
Generally Safe
Score 85/100Whats Order has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "whats-order" v0.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any detected taint flows, raw SQL queries, or significant attack surface points without authentication are positive indicators. Furthermore, the plugin demonstrates good practices in utilizing prepared statements for all SQL queries and a relatively high percentage of properly escaped output. The plugin also incorporates nonce and capability checks where appropriate.
However, a few areas warrant attention. The presence of the `move_uploaded_file` function, while not inherently vulnerable, represents a potential risk if not handled with extreme care, as it can be a vector for arbitrary file uploads. Additionally, the 83 total output operations with only 72% properly escaped suggests there might be opportunities for cross-site scripting (XSS) vulnerabilities in the remaining 28%. The lack of any recorded vulnerability history is a positive sign but doesn't guarantee future security, especially given the potential risks identified.
In conclusion, the "whats-order" v0.1.0 plugin is reasonably secure at first glance, with several good security implementations. The main concerns stem from the potential risk associated with `move_uploaded_file` and the incomplete output escaping. Addressing these areas would further solidify its security.
Key Concerns
- Dangerous function detected (move_uploaded_file)
- Output escaping is not fully implemented (28% not escaped)
Whats Order Security Vulnerabilities
Whats Order Release Timeline
Whats Order Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Whats Order Attack Surface
WordPress Hooks 25
Maintenance & Trust
Whats Order Maintenance & Trust
Maintenance Signals
Community Trust
Whats Order Alternatives
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Welcart e-Commerce
usc-e-shop
Welcart is a free e-commerce plugin for Wordpress with top market share in Japan.
Shopping Cart & eCommerce Store
wp-easycart
A FREE WordPress eCommerce & WordPress Shopping Cart plugin that can sell products, subscriptions, downloads, services, donations, and much more o …
Image Uploader for Welcart
image-uploader-for-welcart
Create metabox with image uploader for ‘Welcart e-Commerce’. It allows user to upload and sort images directory from each edit page.
Recently Viewed Product for WooCommerce
recently-viewed-products-for-woocommerce
Recently Viewed Products for WooCommerce Listing page, you can easily add recently viewed product section by activate the plugin.
Whats Order Developer Profile
7 plugins · 6K total installs
How We Detect Whats Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whats-order/assets/css/cart.css/wp-content/plugins/whats-order/assets/js/api.js/wp-content/plugins/whats-order/assets/js/cart.js/wp-content/plugins/whats-order/src/js/fe.jswhats-order/assets/css/cart.css?ver=whats-order/assets/js/api.js?ver=whats-order/assets/js/cart.js?ver=whats-order/src/js/fe.js?ver=HTML / DOM Fingerprints
wso-itemwindow.wso_api_keywindow.wso_fake_id/wp-json/whats-order/cart/wp-json/whats-order/order[whats_order]