
Order Splitter for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-order-splitterA great plugin to split WooCommerce orders. You can duplicate orders as well.
Is Order Splitter for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Order Splitter for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "woo-order-splitter" plugin version 5.3.8 exhibits a mixed security posture. While it demonstrates good practices like a high percentage of SQL queries using prepared statements and a significant number of nonce and capability checks, several concerns warrant attention. The presence of 24 AJAX handlers, with three lacking authorization checks, creates a notable attack surface. Additionally, the taint analysis revealed 14 high-severity flows with unsanitized paths, indicating a potential for vulnerabilities related to how data is processed. The plugin also utilizes dangerous functions such as 'unserialize', which can be a vector for code injection if not handled with extreme caution, especially when dealing with untrusted input.
The vulnerability history shows two past medium-severity CVEs, specifically related to Missing Authorization and SQL Injection. Although there are no currently unpatched vulnerabilities, the past occurrence of these types of issues, coupled with the current taint analysis findings, suggests a pattern of susceptibility to authorization bypasses and potential SQL injection risks. The plugin's strengths lie in its proactive security measures like prepared statements and checks, but the identified gaps in AJAX handler authorization and the high-severity taint flows present clear risks that need to be addressed to improve its overall security. The last vulnerability being in 2026 is a typo and should not be considered in the current assessment.
Key Concerns
- AJAX handlers without authentication checks
- High severity unsanitized taint flows
- Dangerous function: unserialize
- Past medium severity CVEs (SQL Injection, Auth)
Order Splitter for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Order Splitter for WooCommerce <= 5.3.5 - Missing Authorization to Authenticated (Subscriber+) Order Information Exposure
Order Splitter for WooCommerce <= 5.3.0 - Authenticated (Subscriber+) SQL Injection
Order Splitter for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Order Splitter for WooCommerce Attack Surface
AJAX Handlers 24
WordPress Hooks 128
Maintenance & Trust
Order Splitter for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Order Splitter for WooCommerce Alternatives
Order Splitter for WooCommerce – Split / Duplicate / Merge Orders
wc-order-splitter
A plugin helps you to simply split and duplicate orders.
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
Yoast Duplicate Post
duplicate-post
The go-to tool for cloning posts and pages, including the powerful Rewrite & Republish feature.
WPvivid — Backup, Migration & Staging
wpvivid-backuprestore
Migrate, staging, backup WordPress, all in one.
Migrate Guru – Site Migration & Cloning
migrate-guru
Effortlessly migrate, clone, or transfer your WordPress site to over 5,000 web hosts with Migrate Guru, trusted by Cloudways, Pantheon, and Dreamhost.
Order Splitter for WooCommerce Developer Profile
40 plugins · 33K total installs
How We Detect Order Splitter for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-order-splitter/woo-order-splitter.phpwoo-order-splitter/woo-order-splitter.php?ver=