Apaczka.pl WooCommerce Security & Risk Analysis

wordpress.org/plugins/apaczka

Zintegruj WooCommerce z Apaczka.pl. Dzięki integracji, możesz skorzystać z promocyjnej oferty na usługi UPS, DHL, K-EX, DPD, TNT, FedEx, InPost i Pocz …

1K active installs v1.4.8 PHP + WP 4.0+ Updated Jun 2, 2023
apaczkawoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Apaczka.pl WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Apaczka.pl WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin 'apaczka' v1.4.8 exhibits a generally good security posture with several positive indicators. The absence of any known CVEs and a clean vulnerability history suggest a well-maintained plugin. The static analysis reveals that all entry points (AJAX handlers) have nonce checks, and there's at least one capability check implemented. SQL queries are exclusively using prepared statements, which is a strong defense against SQL injection. However, there are some areas for concern. The presence of two 'unserialize' function calls is a significant risk, as unserialization of untrusted data is a well-known vector for remote code execution. Furthermore, the output escaping is only properly implemented for 38% of outputs, meaning a substantial portion of data rendered to users might be susceptible to cross-site scripting (XSS) attacks. The taint analysis shows one flow with unsanitized paths, which, while not flagged as critical or high, warrants attention due to the potential for unintended data handling. The combination of these factors presents a moderate risk profile, primarily driven by the potential for RCE via unserialization and XSS due to insufficient output escaping.

Key Concerns

  • Use of unserialize function calls
  • Insufficient output escaping (38% proper)
  • Taint flow with unsanitized paths
Vulnerabilities
None known

Apaczka.pl WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Apaczka.pl WooCommerce Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
38
23 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserialize$response = unserialize($raw_response['body']);classes\inspire\plugin4.php:192
unserialize$res = unserialize($request['body']);classes\inspire\plugin4.php:225

Output Escaping

38% escaped61 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
ajax_get_waybill (classes\shipping-method.php:753)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Apaczka.pl WooCommerce Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_save_parcel_machine_address_wc_sessionapaczka.php:115
noprivwp_ajax_save_parcel_machine_address_wc_sessionapaczka.php:116
authwp_ajax_apaczkaclasses\ajax.php:23
WordPress Hooks 29
actionplugins_loadedapaczka.php:78
filterwoocommerce_shipping_packagesapaczka.php:83
actionadmin_enqueue_scriptsapaczka.php:103
actionadmin_noticesapaczka.php:105
filterwoocommerce_shipping_methodsapaczka.php:107
actionwoocommerce_settings_savedapaczka.php:109
filterwoocommerce_order_formatted_shipping_addressapaczka.php:111
actionwoocommerce_cart_totals_after_order_totalapaczka.php:113
actionadmin_noticesapaczka.php:270
actionplugins_loadedapaczka.php:273
actionadmin_headclasses\ajax.php:24
filterflexible_shipping_integration_optionsclasses\class-apaczka-fs-hooks.php:16
filterflexible_shipping_method_integration_colclasses\class-apaczka-fs-hooks.php:17
actionmanage_shop_order_posts_custom_columnclasses\class-apaczka-orders-table.php:28
filtermanage_edit-shop_order_columnsclasses\class-apaczka-orders-table.php:30
actionplugins_loadedclasses\inspire\plugin4.php:74
filterpre_set_site_transient_update_pluginsclasses\inspire\plugin4.php:152
actionadd_meta_boxesclasses\shipping-method.php:64
actionwoocommerce_checkout_update_order_metaclasses\shipping-method.php:66
actionsave_postclasses\shipping-method.php:69
actionwoocommerce_after_checkout_validationclasses\shipping-method.php:71
actionwp_enqueue_scriptsclasses\shipx-api.php:31
actionadmin_enqueue_scriptsclasses\shipx-api.php:32
actionadmin_enqueue_scriptsclasses\shipx-api.php:33
actionadmin_enqueue_scriptsclasses\shipx-api.php:34
actionwp_footerclasses\shipx-api.php:35
actionadmin_footerclasses\shipx-api.php:36
actionwoocommerce_review_order_after_shippingclasses\shipx-api.php:38
actionwoocommerce_checkout_update_order_metaclasses\shipx-api.php:40
Maintenance & Trust

Apaczka.pl WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJun 2, 2023
PHP min version
Downloads37K

Community Trust

Rating34/100
Number of ratings6
Active installs1K
Developer Profile

Apaczka.pl WooCommerce Developer Profile

ilabs

7 plugins · 17K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Apaczka.pl WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apaczka/assets/css/backend.css/wp-content/plugins/apaczka/assets/css/frontend.css/wp-content/plugins/apaczka/assets/js/backend.js/wp-content/plugins/apaczka/assets/js/frontend.js
Script Paths
/wp-content/plugins/apaczka/assets/js/backend.js/wp-content/plugins/apaczka/assets/js/frontend.js
Version Parameters
apaczka/assets/css/backend.css?ver=apaczka/assets/css/frontend.css?ver=apaczka/assets/js/backend.js?ver=apaczka/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
apaczka-settings-wrap
Data Attributes
data-apaczka-countries-nonce
JS Globals
apaczka_settingsapaczka_ajax_url
FAQ

Frequently Asked Questions about Apaczka.pl WooCommerce