
Zorem Local Pickup Security & Risk Analysis
wordpress.org/plugins/advanced-local-pickup-for-woocommerceZorem Local Pickup plugin enhances WooCommerce by streamlining in-store pickups, offering a dedicated workflow for local pickup fulfillment.
Is Zorem Local Pickup Safe to Use in 2026?
Generally Safe
Score 98/100Zorem Local Pickup has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'advanced-local-pickup-for-woocommerce' v1.7.9 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, implementing nonces for its AJAX handlers, and performing capability checks. The vast majority of its output is properly escaped, and there are no identified file operations or shortcodes, reducing potential attack vectors. However, several concerning signals emerge from the static analysis and vulnerability history. The presence of 9 instances of the 'unserialize' function, combined with 5 taint flows with unsanitized paths, suggests a significant risk of deserialization vulnerabilities, potentially leading to remote code execution or unauthorized access. The plugin's history of 5 CVEs, including one high-severity and four medium-severity vulnerabilities, with the most recent in April 2024, indicates a recurring pattern of security weaknesses. While no currently unpatched CVEs are listed, the past issues, particularly around SQL injection, CSRF, and missing authorization, coupled with the identified taint flows, warrant careful consideration. The plugin uses a bundled library, Select2, which, while not explicitly flagged as outdated, could be a potential vector if not kept up-to-date. In conclusion, while the plugin has strengths in its basic security implementations, the significant risks posed by the 'unserialize' function and unsanitized taint flows, compounded by its historical vulnerability record, present a notable security concern.
Key Concerns
- 5 flows with unsanitized paths (taint analysis)
- 9 dangerous functions ('unserialize' detected)
- 1 high severity CVE in vulnerability history
- 4 medium severity CVEs in vulnerability history
- Bundled library (Select2)
Zorem Local Pickup Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Advanced Local Pickup for WooCommerce <= 1.6.1 - Missing Authorization to Notice Dismissal
Advanced Local Pickup for WooCommerce <= 1.6.2 - Missing Authorization
Advanced Local Pickup for WooCommerce <= 1.5.5 - Authenticated (Administrator+) SQL Injection
Advanced Local Pickup for WooCommerce <= 1.5.2 - Cross-Site Request Forgery
Advanced Local Pickup for WooCommerce <= 1.5.2 - Missing Authorization
Zorem Local Pickup Release Timeline
Zorem Local Pickup Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Zorem Local Pickup Attack Surface
AJAX Handlers 7
WordPress Hooks 40
Maintenance & Trust
Zorem Local Pickup Maintenance & Trust
Maintenance Signals
Community Trust
Zorem Local Pickup Alternatives
Hide Shipping Method For WooCommerce
hide-shipping-method-for-woocommerce
Allows store owners to hide shipping methods based on specific conditions!
No Shipping Message for WooCommerce
wc-no-shipping-message
Allows you to customize the messages WooCommerce displays on the cart and checkout pages when no shipping methods are available.
ELEX Hide WooCommerce Shipping Methods
elex-hide-woocommerce-shipping-methods-basic
The ELEX Hide WooCommerce Shipping Methods is a free plugin allows you to hide certain shipping methods based on shipping class, order weight, other e …
Shipping Notices and No shipping options found info for WooCommerce
octolize-shipping-notices
Change 'no shipping options found' message in WooCommerce. Prevent cart abandonment with custom notices and instructions or contact info.
GoSweetSpot Shipping Options
gosweetspot-shipping-options
Realtime address validated shipping options for your customers.
Zorem Local Pickup Developer Profile
4 plugins · 70K total installs
How We Detect Zorem Local Pickup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/css/admin-style.css/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/admin-script.js/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/frontend.js/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/css/frontend.css/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/vendor/jquery-ui.min.js/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/vendor/moment.min.js/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/vendor/datetimepicker.js/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/css/datetimepicker.css/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/admin-script.js/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/frontend.js/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/css/admin-style.css?ver=/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/admin-script.js?ver=/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/frontend.js?ver=/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/css/frontend.css?ver=/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/vendor/jquery-ui.min.js?ver=/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/vendor/moment.min.js?ver=/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/js/vendor/datetimepicker.js?ver=/wp-content/plugins/advanced-local-pickup-for-woocommerce/assets/css/datetimepicker.css?ver=HTML / DOM Fingerprints
alp-pickup-location-details<!-- Zorem Local Pickup --><!-- Zorem Local Pickup End --><!-- Zorem Local Pickup admin --><!-- Zorem Local Pickup admin End -->data-alp-location-iddata-order-iddata-noncealp_admin_script_params