
WPC Order Notes for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-order-notesWPC Order Notes help you manage all order notes more easily. You can see all notes in one place and quickly view notes of an order in the popup.
Is WPC Order Notes for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100WPC Order Notes for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "woo-order-notes" v2.0.1 plugin exhibits a generally good security posture, with no critical or high-severity vulnerabilities identified in the recent code analysis. All AJAX entry points are protected by authentication checks, and there are no exposed REST API routes, shortcodes, or cron events, significantly limiting the plugin's attack surface. The high percentage of properly escaped outputs (91%) and the presence of nonce and capability checks on all identified entry points are positive indicators of secure development practices. The taint analysis also revealed no critical or high-severity unsanitized flows, suggesting a good effort to prevent common injection vulnerabilities.
However, there are a few areas for concern. The presence of the `unserialize` function is a potential risk, as it can lead to deserialization vulnerabilities if not handled with extreme care, especially if the input is not properly validated or comes from an untrusted source. Furthermore, the plugin executes a single SQL query that does not use prepared statements, which could be a vector for SQL injection if any dynamic data is incorporated into that query without sanitization. The plugin has a history of one medium-severity CVE, though it is currently patched. This indicates a past vulnerability that, while resolved, warrants continued vigilance.
In conclusion, the "woo-order-notes" v2.0.1 plugin has a strong foundation in terms of attack surface management and output escaping. The core security mechanisms appear to be in place. Nevertheless, the identified use of `unserialize` and raw SQL queries without prepared statements represent minor but notable risks that could be mitigated through stricter input validation and the adoption of prepared statements for all database interactions. The absence of currently unpatched vulnerabilities is reassuring.
Key Concerns
- Dangerous function unserialize used
- SQL queries not using prepared statements
WPC Order Notes for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPC Order Notes for WooCommerce <= 1.5.2 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
WPC Order Notes for WooCommerce Release Timeline
WPC Order Notes for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WPC Order Notes for WooCommerce Attack Surface
AJAX Handlers 8
WordPress Hooks 18
Maintenance & Trust
WPC Order Notes for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WPC Order Notes for WooCommerce Alternatives
Customer Notes for WooCommerce
customer-notes-for-woocommerce
The Customer Notes for WooCommerce plugin allows store owners to add specific notes for each customer, which are then displayed on the Edit Order page …
Admin and Customer Messages After Order for WooCommerce: OrderConvo
admin-and-client-message-after-order-for-woocommerce
OrderConvo: Enable seamless post-order communication between vendors/admins and customers in WooCommerce.
Note Finder for WooCommerce
note-finder-for-woocommerce
Search for WooCommerce order notes
WooComerce Colored Order Notes
colored-order-notes-for-woocommerce
This plugin allows you to customize order note color for each order status.
RD Order Note Templates for WooCommerce
rd-wc-enhanced-order-notes
Create predefined templates for order notes that you can apply to orders
WPC Order Notes for WooCommerce Developer Profile
73 plugins · 441K total installs
How We Detect WPC Order Notes for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-order-notes/assets/css/backend.css/wp-content/plugins/woo-order-notes/assets/js/backend.js/wp-content/plugins/woo-order-notes/assets/js/backend.jswoo-order-notes/assets/css/backend.css?ver=woo-order-notes/assets/js/backend.js?ver=HTML / DOM Fingerprints
wpclever_settings_pagewpclever_settings_page_headerwpclever_settings_page_header_logowpclever_settings_page_header_textwpclever_settings_page_titlewpclever_settings_page_navwpclever_settings_page_contentwpclever_settings_page_content_textdata-idWOOON_VERSIONWOOON_LITEWOOON_FILEWOOON_URIWOOON_DIRWOOON_REVIEWS+6 more