Delivery Date for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woocommerce-delivery-date

This plugin for woocommerce lets you select a number of days, and shopper can only choose delivery date after the number of days.

10 active installs v2.2.2 PHP 7.4+ WP 5.0+ Updated Unknown
deliverydelivery-datefreewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Delivery Date for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Delivery Date for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The WooCommerce Delivery Date plugin, version 2.2.2, exhibits a generally positive security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with exposed attack surfaces is a significant strength. Furthermore, the plugin utilizes prepared statements exclusively for its SQL queries, mitigating the risk of SQL injection vulnerabilities. However, there are notable areas for improvement. The low percentage of properly escaped output (54%) indicates a potential risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not consistently handled with care. The complete lack of nonce checks and capability checks on any potential entry points, though currently limited, presents a future risk if new functionalities are added without adequate security measures. The bundled Freemius library, at version 1.0, could also be a concern if it contains known vulnerabilities that are not addressed in this plugin version. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a responsible development approach to security thus far. Overall, the plugin demonstrates good practices in core areas like SQL, but the insufficient output escaping and lack of broader security checks on entry points warrant attention.

Key Concerns

  • Insufficient output escaping
  • Missing nonce checks
  • Missing capability checks
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
None known

Delivery Date for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Delivery Date for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

54% escaped28 total outputs
Attack Surface

Delivery Date for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actioninitsrc\Abstracts\AbstractAjax.php:13
actiontemplate_redirectsrc\Abstracts\AbstractAjax.php:14
actionwoocommerce_admin_order_data_after_order_detailssrc\Admin\Backend.php:9
actionadmin_menusrc\Admin\MenuManager.php:11
actionadmin_headsrc\BaseWebAdmin.php:14
actionwoocommerce_checkout_billingsrc\Site\Frontend.php:23
filterwoocommerce_checkout_fieldssrc\Site\Frontend.php:24
actionwoocommerce_checkout_update_order_metasrc\Site\Frontend.php:25
actionwoocommerce_email_after_order_tablesrc\Site\Frontend.php:31
actionwoocommerce_order_details_after_order_tablesrc\Site\Frontend.php:37
actionwoocommerce_thankyousrc\Site\Frontend.php:38
actioninitwoocommerce-delivery-date.php:48
actionplugins_loadedwoocommerce-delivery-date.php:144
filtershow_accountwoocommerce-delivery-date.php:150
filtershow_contactwoocommerce-delivery-date.php:151
filtershow_pricingwoocommerce-delivery-date.php:152
filteris_submenu_visiblewoocommerce-delivery-date.php:153
filterenable_anonymouswoocommerce-delivery-date.php:154
filterdisable_freemius_brandingwoocommerce-delivery-date.php:155
actionplugins_loadedwoocommerce-delivery-date.php:163
Maintenance & Trust

Delivery Date for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads12K

Community Trust

Rating72/100
Number of ratings5
Active installs10
Developer Profile

Delivery Date for WooCommerce Developer Profile

dreamfox

5 plugins · 410 total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
87 days
View full developer profile
Detection Fingerprints

How We Detect Delivery Date for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-delivery-date/assets/css/woocommerce-delivery-date.css/wp-content/plugins/woocommerce-delivery-date/assets/js/woocommerce-delivery-date.js
Script Paths
/wp-content/plugins/woocommerce-delivery-date/assets/js/woocommerce-delivery-date.js
Version Parameters
woocommerce-delivery-date/assets/css/woocommerce-delivery-date.css?ver=woocommerce-delivery-date/assets/js/woocommerce-delivery-date.js?ver=

HTML / DOM Fingerprints

CSS Classes
dreamfox-delivery-date-wrapper
HTML Comments
<!-- WooCommerce Delivery Date --><!-- END WooCommerce Delivery Date -->
Data Attributes
data-delivery-date-options
JS Globals
dreamfoxDeliveryDate
FAQ

Frequently Asked Questions about Delivery Date for WooCommerce