Cubicsofts Phone Order Tracker for Asaan Retail Security & Risk Analysis

wordpress.org/plugins/asaan-retail-phone-order-tracker

Order Tracking by Phone for Asaan Retail allows WooCommerce store owners to sync delivery status from Asaan Retail and lets customers track their orde …

0 active installs v1.1.1 PHP 7.4+ WP 6.6+ Updated Jan 7, 2026
courier-trackingorder-trackingpakistanwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cubicsofts Phone Order Tracker for Asaan Retail Safe to Use in 2026?

Generally Safe

Score 100/100

Cubicsofts Phone Order Tracker for Asaan Retail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "asaan-retail-phone-order-tracker" plugin v1.1.1 exhibits a strong security posture based on the provided static analysis. The complete absence of vulnerable code signals, such as dangerous functions, unsanitized taint flows, and file operations, is highly commendable. Furthermore, the plugin demonstrates excellent practices in output escaping, with 100% of outputs properly escaped, significantly reducing the risk of Cross-Site Scripting (XSS) vulnerabilities. The use of prepared statements for 80% of SQL queries and the presence of nonce and capability checks on entry points are also positive indicators of secure development.

While the static analysis reveals a very clean codebase, there are minor areas that could be strengthened. The presence of two external HTTP requests, while not inherently vulnerable without further context, represents a potential attack vector if the external services are compromised or return malicious data. The plugin also has a modest attack surface of three entry points (AJAX handlers and shortcodes), and while none are reported as unprotected, this is an area that should be continuously monitored, especially as the plugin evolves. The absence of any known vulnerabilities or CVEs in its history suggests a well-maintained and secure plugin, or at least one that hasn't been a target for public disclosure of vulnerabilities. Overall, this plugin appears to be developed with security in mind, with only minor areas for potential improvement in terms of external dependencies.

Key Concerns

  • External HTTP requests present
Vulnerabilities
None known

Cubicsofts Phone Order Tracker for Asaan Retail Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Cubicsofts Phone Order Tracker for Asaan Retail Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
0
21 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

80% prepared5 total queries

Output Escaping

100% escaped21 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
cubicsofts_asa_phone_lookup (asaan-retail-phone-order-tracker.php:338)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Cubicsofts Phone Order Tracker for Asaan Retail Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_cubicsofts_asa_phone_lookupasaan-retail-phone-order-tracker.php:335
noprivwp_ajax_cubicsofts_asa_phone_lookupasaan-retail-phone-order-tracker.php:336

Shortcodes 1

[asaan_phone_tracker] asaan-retail-phone-order-tracker.php:321
WordPress Hooks 6
filtercron_schedulesasaan-retail-phone-order-tracker.php:82
actionadmin_menuasaan-retail-phone-order-tracker.php:93
actionadmin_initasaan-retail-phone-order-tracker.php:112
actionwp_enqueue_scriptsasaan-retail-phone-order-tracker.php:136
actionadmin_initasaan-retail-phone-order-tracker.php:210
actioncubicsofts_asa_sync_cronasaan-retail-phone-order-tracker.php:232

Scheduled Events 1

cubicsofts_asa_sync_cron
Maintenance & Trust

Cubicsofts Phone Order Tracker for Asaan Retail Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 7, 2026
PHP min version7.4
Downloads93

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Cubicsofts Phone Order Tracker for Asaan Retail Developer Profile

cubicsofts

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cubicsofts Phone Order Tracker for Asaan Retail

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/asaan-retail-phone-order-tracker/asaan-retail-phone-order-tracker.php
Version Parameters
asaan-retail-phone-order-tracker/style.css?ver=asaan-retail-phone-order-tracker/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
asaan-cardasaan-status
Data Attributes
asaan-retail-phone-order-tracker
JS Globals
cubicsoftsAsa
FAQ

Frequently Asked Questions about Cubicsofts Phone Order Tracker for Asaan Retail