Apaczka: integracja z WooCommerce Security & Risk Analysis

wordpress.org/plugins/apaczka-pl

Zarządzaj wysyłkami różnych kurierów w jednym miejscu

4K active installs v1.4.2 PHP 7.2+ WP 5.3+ Updated Mar 12, 2026
apaczkadhldpdinpostwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Apaczka: integracja z WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Apaczka: integracja z WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The "apaczka-pl" v1.4.2 plugin exhibits a generally strong security posture, adhering to several good practices. It boasts a minimal attack surface with only one AJAX handler, and crucially, this entry point appears to have authentication checks, as indicated by the zero unprotected entry points. The plugin also demonstrates excellent practices regarding database interactions, with all SQL queries utilizing prepared statements, and a high percentage of output properly escaped, significantly mitigating risks of cross-site scripting (XSS). File operations and external HTTP requests are present but limited, and the presence of a nonce check on the AJAX handler is a positive security measure.

However, the static analysis reveals a significant concern: the presence of two instances of the "unserialize" function. This function is notoriously dangerous when used with untrusted input, as it can lead to remote code execution (RCE) vulnerabilities if an attacker can control the serialized data. The taint analysis, while showing no critical or high severity flows, did identify two flows with "unsanitized paths." While the severity is not explicitly stated as critical, the combination of "unserialize" and "unsanitized paths" raises a red flag, suggesting a potential avenue for exploitation if user-supplied data, even if not directly flagged as critical, reaches the unserialize function without proper sanitization.

The vulnerability history of "apaczka-pl" is remarkably clean, with zero known CVEs. This indicates a history of stable and potentially secure development. However, past security is not a guarantee of future security, and the presence of the "unserialize" function remains a significant latent risk. In conclusion, "apaczka-pl" v1.4.2 has strengths in its minimal attack surface and database security, but the use of "unserialize" introduces a critical potential vulnerability that outweighs its otherwise positive security attributes. The lack of past vulnerabilities should not lead to complacency regarding this specific code signal.

Key Concerns

  • Use of unserialize function
  • Taint flows with unsanitized paths
  • No capability checks found
Vulnerabilities
None known

Apaczka: integracja z WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Apaczka: integracja z WooCommerce Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
18
94 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserialize$_apaczka = unserialize( $apaczka_wc_order_data_raw );src\Shipping_Method_Apaczka.php:947
unserialize$_apaczka = unserialize( $apaczka_wc_order_data_raw );src\Shipping_Method_Apaczka.php:986

Output Escaping

84% escaped112 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
get_waybill (src\Shipping_Method_Apaczka.php:1841)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Apaczka: integracja z WooCommerce Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_apaczkasrc\Ajax.php:16
WordPress Hooks 32
actionafter_setup_themeapaczka-pl.php:48
actionadmin_noticesapaczka-pl.php:74
actionbefore_woocommerce_initapaczka-pl.php:81
actionadmin_headsrc\Ajax.php:17
actionadmin_noticessrc\Alerts.php:73
actionwoocommerce_after_shipping_ratesrc\Apaczka_Shipping_Rates.php:17
filterflexible_shipping_integration_optionssrc\FSHooks.php:17
filterflexible_shipping_method_integration_colsrc\FSHooks.php:19
filterwoocommerce_settings_tabs_arraysrc\Global_Settings_Integration.php:33
filterwoocommerce_admin_settings_sanitize_optionsrc\Global_Settings_Integration.php:134
filterwc_subscriptions_object_datasrc\Integrations.php:38
actionwps_sfw_renewal_order_creationsrc\Integrations.php:39
actioninitsrc\Plugin\Abstract_Ilabs_Plugin.php:35
actionplugins_loadedsrc\Plugin\Abstract_Ilabs_Plugin.php:43
actionadmin_enqueue_scriptssrc\Plugin\Abstract_Ilabs_Plugin.php:82
actionwp_enqueue_scriptssrc\Plugin\Abstract_Ilabs_Plugin.php:86
filterwoocommerce_get_order_item_totalssrc\Plugin.php:52
actionwoocommerce_after_shipping_ratesrc\Plugin.php:54
filterwoocommerce_shipping_methodssrc\Plugin.php:72
actionwoocommerce_initsrc\Plugin.php:81
actionwoocommerce_settings_savedsrc\Plugin.php:132
filterwoocommerce_get_settings_pagessrc\Plugin.php:133
actionwoocommerce_admin_order_data_after_shipping_addresssrc\Plugin.php:145
actionadd_meta_boxessrc\Shipping_Method_Apaczka.php:132
actionwoocommerce_checkout_update_order_metasrc\Shipping_Method_Apaczka.php:134
actionsave_postsrc\Shipping_Method_Apaczka.php:141
actionwoocommerce_process_shop_order_metasrc\Shipping_Method_Apaczka.php:142
actionwoocommerce_after_checkout_validationsrc\Shipping_Method_Apaczka.php:144
actionadmin_footersrc\Shipping_Method_Apaczka.php:151
actionwoocommerce_store_api_checkout_update_order_from_requestsrc\Shipping_Method_Apaczka.php:153
actionwoocommerce_review_order_after_shippingsrc\Shipping_Method_Apaczka.php:161
actionwoocommerce_blocks_checkout_block_registrationsrc\Shipping_Method_Apaczka.php:167
Maintenance & Trust

Apaczka: integracja z WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version7.2
Downloads89K

Community Trust

Rating66/100
Number of ratings6
Active installs4K
Developer Profile

Apaczka: integracja z WooCommerce Developer Profile

ilabs

7 plugins · 17K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Apaczka: integracja z WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apaczka-pl/src/resources/css/admin.css/wp-content/plugins/apaczka-pl/src/resources/css/frontend.css/wp-content/plugins/apaczka-pl/src/resources/js/admin.js/wp-content/plugins/apaczka-pl/src/resources/js/frontend.js
Script Paths
/wp-content/plugins/apaczka-pl/src/resources/js/admin.js/wp-content/plugins/apaczka-pl/src/resources/js/frontend.js
Version Parameters
apaczka-pl/src/resources/css/admin.css?ver=apaczka-pl/src/resources/css/frontend.css?ver=apaczka-pl/src/resources/js/admin.js?ver=apaczka-pl/src/resources/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
apaczka-points-map-wrapper
Data Attributes
data-apaczka-carrier
Shortcode Output
[apaczka_points_map]
FAQ

Frequently Asked Questions about Apaczka: integracja z WooCommerce