Aramex Logistics Security & Risk Analysis

wordpress.org/plugins/aramex-logistics

Seamlessly integrate Aramex Logistics with your WooCommerce store for efficient order management, inventory tracking, and shipping operations.

50 active installs v1.0.6 PHP 7.4+ WP 5.8+ Updated Nov 19, 2025
aramexinventorylogisticsshippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Aramex Logistics Safe to Use in 2026?

Generally Safe

Score 100/100

Aramex Logistics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'aramex-logistics' v1.0.6 plugin demonstrates generally good security practices, with a high percentage of SQL queries using prepared statements and output being properly escaped. The absence of any recorded vulnerabilities (CVEs) and zero critical or high severity taint flows are positive indicators. However, the plugin does present some areas of concern. A significant portion of its attack surface, specifically 2 out of 2 REST API routes, lacks permission callbacks, which could allow unauthorized access to sensitive functionalities if not properly protected by other means. Additionally, while the plugin uses nonces extensively, the complete absence of capability checks on any of its entry points is a notable weakness that could be exploited if a vulnerability were introduced.

Key Concerns

  • REST API routes without permission callbacks
  • No capability checks on entry points
Vulnerabilities
None known

Aramex Logistics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Aramex Logistics Code Analysis

Dangerous Functions
0
Raw SQL Queries
16
86 prepared
Unescaped Output
6
334 escaped
Nonce Checks
11
Capability Checks
0
File Operations
3
External Requests
7
Bundled Libraries
0

SQL Query Safety

84% prepared102 total queries

Output Escaping

98% escaped340 total outputs
Data Flows
All sanitized

Data Flow Analysis

7 flows
aramex_login_page (includes\admin-dashboard.php:37)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Aramex Logistics Attack Surface

Entry Points10
Unprotected2

AJAX Handlers 8

authwp_ajax_aramex_info_generate_full_csvaramex-logistics.php:151
noprivwp_ajax_aramex_info_generate_full_csvaramex-logistics.php:152
authwp_ajax_aramex_info_export_user_logs_csvaramex-logistics.php:386
noprivwp_ajax_aramex_info_export_user_logs_csvaramex-logistics.php:387
authwp_ajax_aramex_update_order_referenceincludes\ajax-handlers.php:9
authwp_ajax_aramex_update_order_waybillincludes\ajax-handlers.php:33
authwp_ajax_aramex_store_settingsincludes\ajax-handlers.php:57
authwp_ajax_fetch_aramex_settingsincludes\ajax-handlers.php:187

REST API Routes 2

POST/wp-json/aramex/v1/order-status/includes\order-status-webhook.php:304
POST/wp-json/aramex/v1/stock-sync/includes\stock-sync-webhook.php:156
WordPress Hooks 23
actionadmin_enqueue_scriptsaramex-logistics.php:113
filteradmin_body_classaramex-logistics.php:137
actionsave_post_productaramex-logistics.php:140
actionadmin_menuincludes\admin-dashboard.php:9
actionadmin_menuincludes\admin-dashboard.php:25
actionadmin_enqueue_scriptsincludes\admin-dashboard.php:243
actionaramex_delete_orders_cron_hookincludes\delete-aramex-order.php:39
actionaramex_delete_log_cron_hookincludes\delete-log.php:34
filtercron_schedulesincludes\order-status-sync.php:9
actionupdate_status_sync_settingsincludes\order-status-sync.php:57
actionaramex_status_sync_cron_hookincludes\order-status-sync.php:82
actionrest_api_initincludes\order-status-webhook.php:302
actionwoocommerce_order_status_changedincludes\order-sync.php:9
actionwoocommerce_delete_orderincludes\order-sync.php:82
filtercron_schedulesincludes\order-sync.php:249
actionupdate_importso_settingsincludes\order-sync.php:283
actionwoocommerce_new_orderincludes\order-sync.php:305
actionaramex_importso_cron_hookincludes\order-sync.php:344
actionrest_api_initincludes\stock-sync-webhook.php:155
filtercron_schedulesincludes\stock-sync.php:9
actionupdate_stock_sync_settingsincludes\stock-sync.php:54
actionaramex_stock_sync_cron_hookincludes\stock-sync.php:74
actionadmin_menuincludes\user-order-logs.php:8

Scheduled Events 9

aramex_delete_orders_cron_hook
aramex_delete_log_cron_hook
aramex_status_sync_cron_hook
aramex_status_sync_cron_hook
aramex_importso_cron_hook
aramex_importso_cron_hook
aramex_importso_cron_hook
aramex_stock_sync_cron_hook
aramex_stock_sync_cron_hook
Maintenance & Trust

Aramex Logistics Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 19, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Aramex Logistics Developer Profile

aramex

3 plugins · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Aramex Logistics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aramex-logistics/assets/css/style.css/wp-content/plugins/aramex-logistics/assets/js/script.js/wp-content/plugins/aramex-logistics/assets/js/admin-settings.js/wp-content/plugins/aramex-logistics/assets/js/echarts.min.js/wp-content/plugins/aramex-logistics/assets/js/aramex-admin.js
Version Parameters
aramex-logistics/assets/css/style.css?ver=aramex-logistics/assets/js/script.js?ver=aramex-logistics/assets/js/admin-settings.js?ver=aramex-logistics/assets/js/echarts.min.js?ver=aramex-logistics/assets/js/aramex-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
aramex-login-pagearamex-order-pagearamex-log-page
Data Attributes
data-nonce
JS Globals
aramexLogisticsaramex_settingsaramex_ajax
FAQ

Frequently Asked Questions about Aramex Logistics