Epeken for Anteraja Security & Risk Analysis

wordpress.org/plugins/anteraja

Epeken for Anteraja adalah plugin wordpress untuk pengguna woocommerce dan plugin Epeken All Kurir di Indonesia yang berfungsi untuk mengintegrasikan …

50 active installs v2.2 PHP + WP 4.0+ Updated Jan 18, 2026
anterajaecommerceshippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Epeken for Anteraja Safe to Use in 2026?

Generally Safe

Score 100/100

Epeken for Anteraja has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "anteraja" v2.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in areas like SQL query preparation, with 100% of queries using prepared statements and a high percentage of output escaping (94%). The absence of any recorded vulnerabilities or CVEs is also a strong indicator of a well-maintained codebase historically. However, there are significant concerns regarding its attack surface and a lack of robust access controls in critical areas.

The static analysis reveals a notable attack surface with 8 AJAX handlers, and critically, 2 of these lack any authentication checks. This presents a direct pathway for unauthenticated users to interact with potentially sensitive plugin functionality. While the taint analysis shows no critical or high severity flows with unsanitized paths, the presence of 5 flows with unsanitized paths, even if classified lower, warrants attention as they could be exploited if combined with other weaknesses. The complete absence of capability checks is a major concern, implying that even authenticated users might be able to access functions they shouldn't.

Overall, while the plugin has strengths in code hygiene for SQL and output, the unprotected AJAX endpoints and lack of capability checks are substantial security weaknesses. These could allow for unauthorized actions or information disclosure. The lack of historical vulnerabilities is a positive but does not negate the risks identified in the current static analysis.

Key Concerns

  • Unprotected AJAX handlers
  • No capability checks
  • Flows with unsanitized paths
Vulnerabilities
None known

Epeken for Anteraja Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Epeken for Anteraja Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
255 escaped
Nonce Checks
3
Capability Checks
0
File Operations
4
External Requests
6
Bundled Libraries
0

Output Escaping

94% escaped271 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

6 flows5 with unsanitized paths
epkn_antr_metabox (epeken-anteraja.php:351)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Epeken for Anteraja Attack Surface

Entry Points8
Unprotected2

AJAX Handlers 8

authwp_ajax_get_anteraja_kecamatanepeken-anteraja.php:478
noprivwp_ajax_get_anteraja_kecamatanepeken-anteraja.php:479
authwp_ajax_request_anteraja_orderepeken-anteraja.php:480
noprivwp_ajax_request_anteraja_orderepeken-anteraja.php:481
authwp_ajax_refresh_data_anterajaepeken-anteraja.php:482
noprivwp_ajax_refresh_data_anterajaepeken-anteraja.php:483
authwp_ajax_cancel_anteraja_orderepeken-anteraja.php:484
noprivwp_ajax_cancel_anteraja_orderepeken-anteraja.php:485
WordPress Hooks 21
actionwoocommerce_update_options_shipping_methodsclass\shipping.php:53
actionadmin_enqueue_scriptsclass\shipping.php:55
actionwoocommerce_checkout_update_order_metaclass\shipping.php:56
actionupdated_optionclass\shipping.php:292
filterwoocommerce_available_payment_gatewaysclass\shipping.php:413
actionwoocommerce_review_order_after_shippingclass\shipping.php:429
actionadmin_noticesepeken-anteraja.php:12
actionadmin_noticesepeken-anteraja.php:131
actionwoocommerce_shipping_initepeken-anteraja.php:133
filterwoocommerce_shipping_methodsepeken-anteraja.php:140
actionadmin_enqueue_scriptsepeken-anteraja.php:154
actionadmin_enqueue_scriptsepeken-anteraja.php:155
actiondokan_enqueue_scriptsepeken-anteraja.php:156
actionwp_enqueue_scriptsepeken-anteraja.php:157
actionwoocommerce_checkout_update_order_metaepeken-anteraja.php:225
actionadd_meta_boxesepeken-anteraja.php:340
actionwoocommerce_order_details_after_order_tableepeken-anteraja.php:609
actionepeken_add_vendor_shipping_itemepeken-anteraja.php:637
actionepeken_save_vendor_shipping_itemepeken-anteraja.php:663
actiondokan_order_detail_after_order_itemsepeken-anteraja.php:682
actionepeken_custom_tariffepeken-anteraja.php:715
Maintenance & Trust

Epeken for Anteraja Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 18, 2026
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Epeken for Anteraja Developer Profile

epeken

2 plugins · 550 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Epeken for Anteraja

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anteraja/assets/css/admin.css/wp-content/plugins/anteraja/assets/js/admin.js/wp-content/plugins/anteraja/assets/js/order.js
Script Paths
/wp-content/plugins/anteraja/assets/js/admin.js/wp-content/plugins/anteraja/assets/js/order.js
Version Parameters
anteraja/assets/js/admin.js?ver=anteraja/assets/js/order.js?ver=

HTML / DOM Fingerprints

CSS Classes
settings-error
HTML Comments
<!-- Kirimkan email ke <strong>support@epeken.com</strong> untuk mendapatkan informasi - informasi koneksi Toko Online Kakak dengan Sistem Anteraja. -->
Data Attributes
data-slug="anteraja"data-parent="shipping"data-instance="1"data-settings-page="anteraja"
JS Globals
Admin_Anteraja
FAQ

Frequently Asked Questions about Epeken for Anteraja