Ultimate Order Combination Security & Risk Analysis

wordpress.org/plugins/woo-ultimate-order-combination

Merge and manage WooCommerce orders with ease.

400 active installs v2.0.1 PHP 7.0+ WP 4.4+ Updated Oct 26, 2025
combineconsolidatemergeorderswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Order Combination Safe to Use in 2026?

Generally Safe

Score 100/100

Ultimate Order Combination has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "woo-ultimate-order-combination" plugin v2.0.1 exhibits a mixed security posture. While it shows strengths like the absence of known CVEs and a lack of dangerous functions or file operations, several concerning areas require attention. The presence of 7 AJAX handlers, with 3 lacking authentication checks, creates a significant attack surface. Furthermore, the taint analysis identified 2 flows with unsanitized paths, both classified as high severity, indicating potential for data manipulation or execution vulnerabilities.

The plugin's vulnerability history is a positive sign, showing no recorded CVEs, which suggests a history of responsible development and patching or a lack of past exploitation. However, the static analysis findings, particularly the unprotected AJAX endpoints and the high-severity taint flows, present immediate risks that could be exploited if not addressed. The moderate rate of proper output escaping (42%) also contributes to potential Cross-Site Scripting (XSS) vulnerabilities, though the taint analysis didn't explicitly flag this as critical.

In conclusion, while the plugin benefits from a clean vulnerability history and the absence of critical code-level risks like raw SQL queries or bundled libraries, the unprotected AJAX endpoints and high-severity taint flows are substantial concerns. Addressing these would significantly improve the plugin's security posture. The low rate of output escaping also warrants review to prevent potential XSS.

Key Concerns

  • Unprotected AJAX handlers
  • High severity unsanitized taint flows
  • Low output escaping rate
Vulnerabilities
None known

Ultimate Order Combination Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ultimate Order Combination Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
9 prepared
Unescaped Output
55
40 escaped
Nonce Checks
5
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

69% prepared13 total queries

Output Escaping

42% escaped95 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
wuoc_settings_update (inc\functions.php:41)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Ultimate Order Combination Attack Surface

Entry Points7
Unprotected3

AJAX Handlers 7

authwp_ajax_get_orders_shipping_totalsinc\functions.php:1550
authwp_ajax_wuoc_logger_clear_loginc\functions.php:1677
authwp_ajax_wuoc_clear_meta_datainc\functions.php:1698
authwp_ajax_wuoc_update_rules_layersinc\functions.php:1744
authwp_ajax_wuoc_load_combined_ordersinc\functions.php:1790
authwp_ajax_wuoc_get_combined_orders_htmlindex.php:232
authwp_ajax_wuoc_get_trash_orders_htmlindex.php:234
WordPress Hooks 41
actionadmin_menuinc\functions-essentials.php:69
filterwoocommerce_can_reduce_order_stockinc\functions-essentials.php:88
filterwoocommerce_can_restore_order_stockinc\functions-essentials.php:138
filterwoocommerce_prevent_adjust_line_item_product_stockinc\functions-essentials.php:199
actionadmin_footerinc\functions-plus.php:23
actionhandle_bulk_actions-woocommerce_page_wc-ordersinc\functions-plus.php:25
actionload-edit.phpinc\functions-plus.php:26
filterwoocommerce_email_enabled_new_orderinc\functions-plus.php:1076
actionadmin_noticesinc\functions-plus.php:1085
filterwoocommerce_email_enabled_new_orderinc\functions-plus.php:1229
actionadmin_noticesinc\functions-plus.php:1759
filterwoocommerce_update_product_stock_queryinc\functions.php:240
filterwoocommerce_can_reduce_order_stockinc\functions.php:312
filterpost_row_actionsinc\functions.php:1400
actiontransition_post_statusinc\functions.php:1818
filterwuoc_update_post_meta_valueinc\functions.php:1859
filterwp_mailinc\wuoc-emails.php:2
actionadmin_enqueue_scriptsindex.php:181
actionadmin_enqueue_scriptsindex.php:187
actionadmin_initindex.php:190
actionadmin_headindex.php:191
actionwp_enqueue_scriptsindex.php:196
actionwp_headindex.php:199
actioninitindex.php:200
actionwoocommerce_analytics_update_order_statsindex.php:205
actionwoocommerce_analytics_update_productindex.php:206
actionwoocommerce_analytics_update_couponindex.php:207
actionwoocommerce_analytics_update_taxindex.php:208
filterwoocommerce_analytics_orders_query_argsindex.php:211
actionwoocommerce_reports_get_order_report_queryindex.php:213
actionwoocommerce_emailindex.php:216
actionadmin_initindex.php:223
actionadmin_footerindex.php:225
actionadd_meta_boxesindex.php:227
actionadd_meta_boxesindex.php:228
actionwuoc_general_settings_bodyindex.php:236
actionwuoc_combined_order_bodyindex.php:237
actionwuoc_general_settings_bodyindex.php:240
actionwuoc_crons_options_bodyindex.php:244
actionwoocommerce_thankyouindex.php:248
actioninitindex.php:251
Maintenance & Trust

Ultimate Order Combination Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 26, 2025
PHP min version7.0
Downloads22K

Community Trust

Rating76/100
Number of ratings9
Active installs400
Developer Profile

Ultimate Order Combination Developer Profile

Fahad Mahmood

40 plugins · 33K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
237 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Order Combination

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-ultimate-order-combination/assets/css/admin.css/wp-content/plugins/woo-ultimate-order-combination/assets/css/frontend.css/wp-content/plugins/woo-ultimate-order-combination/assets/js/admin.js/wp-content/plugins/woo-ultimate-order-combination/assets/js/frontend.js
Script Paths
/wp-content/plugins/woo-ultimate-order-combination/assets/js/admin.js/wp-content/plugins/woo-ultimate-order-combination/assets/js/frontend.js
Version Parameters
woo-ultimate-order-combination/assets/css/admin.css?ver=woo-ultimate-order-combination/assets/css/frontend.css?ver=woo-ultimate-order-combination/assets/js/admin.js?ver=woo-ultimate-order-combination/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wuoc_product_selectionwuoc_selected_productwuoc_product_combination
HTML Comments
<!-- Added by Ultimate Order Combination --><!-- Ultimate Order Combination -->
Data Attributes
data-wuoc-product-iddata-wuoc-rule-id
JS Globals
wuoc_paramswuoc_ajax_urlwuoc_product_list
Shortcode Output
[wuoc_product_selector][wuoc_order_combinations][wuoc_combine_button]
FAQ

Frequently Asked Questions about Ultimate Order Combination