WS Multi-Location Intelligent Order for Woocommerce Security & Risk Analysis

wordpress.org/plugins/ws-multi-location-intelligent-order-for-woocommerce

This is a simple plugin that adds a shipping zone column in the orders administartion menu.

10 active installs v1.0 PHP 5.6+ WP 4.9+ Updated Jan 9, 2020
e-commerceecommerceordersshipping-zoneswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WS Multi-Location Intelligent Order for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

WS Multi-Location Intelligent Order for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "ws-multi-location-intelligent-order-for-woocommerce" v1.0, based on the provided static analysis and vulnerability history, appears to have a relatively strong security posture in terms of direct attack vectors. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, all identified SQL queries utilize prepared statements, which is a critical security best practice for preventing SQL injection vulnerabilities. The plugin also has no known historical CVEs, suggesting a history of stable and secure development.

However, a significant concern arises from the output escaping. With 100% of identified outputs not being properly escaped, this plugin presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-provided data displayed on the frontend or backend that passes through these unescaped outputs could be exploited. While the taint analysis shows no unsanitized flows, this could be due to the limited scope of analysis or the absence of complex data processing that would trigger taint analysis. The lack of capability checks and nonce checks also means that even administrative functions, if present, would be accessible without proper authorization, though the current analysis indicates no such direct entry points.

In conclusion, the plugin demonstrates good practices in preventing common injection vulnerabilities like SQL injection and has a clean vulnerability history. The most prominent weakness is the complete lack of output escaping, creating a high risk of XSS. The absence of capability and nonce checks, while not immediately exploitable due to the limited attack surface, represents a potential vulnerability if new features are added that introduce direct entry points.

Key Concerns

  • 0% output escaping
  • 0 capability checks
  • 0 nonce checks
Vulnerabilities
None known

WS Multi-Location Intelligent Order for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WS Multi-Location Intelligent Order for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

0% escaped4 total outputs
Attack Surface

WS Multi-Location Intelligent Order for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtermanage_edit-shop_order_columnsws-woo-multi-location-intelligent-order\ws-woo-multi-location-intelligent-order.php:17
actionmanage_shop_order_posts_custom_columnws-woo-multi-location-intelligent-order\ws-woo-multi-location-intelligent-order.php:23
filtermanage_edit-shop_order_columnsws-woo-multi-location-intelligent-order.php:17
actionmanage_shop_order_posts_custom_columnws-woo-multi-location-intelligent-order.php:23
Maintenance & Trust

WS Multi-Location Intelligent Order for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedJan 9, 2020
PHP min version5.6
Downloads936

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WS Multi-Location Intelligent Order for Woocommerce Developer Profile

Konstantinos Alexiadis

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WS Multi-Location Intelligent Order for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WS Multi-Location Intelligent Order for Woocommerce