
APL – Auto-Pickup Locations for WooCommerce Security & Risk Analysis
wordpress.org/plugins/auto-pickup-locations-for-woocommerceAuto-Pickup Locations automatically assigns the nearest pickup location at checkout based on the customer's location. No Google Maps API needed.
Is APL – Auto-Pickup Locations for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100APL – Auto-Pickup Locations for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "auto-pickup-locations-for-woocommerce" plugin version 1.0.0 exhibits a mixed security posture. While it demonstrates strong output escaping practices, with 100% of outputs properly escaped, and a significant portion of SQL queries (71%) utilizing prepared statements, there are several areas of concern. The presence of a dangerous `unserialize` function, even if not directly linked to a critical taint flow in this analysis, represents a potential risk vector.
The plugin has a substantial attack surface with 14 AJAX handlers, 5 of which lack authentication checks. This is a significant concern as it exposes functionality to unauthenticated users. Furthermore, a high severity taint flow with unsanitized paths was identified. Coupled with only 2 capability checks across the entire codebase, this suggests that these unprotected AJAX handlers could be susceptible to exploitation if they interact with user-supplied data that is not properly validated or sanitized before being used in a sensitive operation.
The plugin's vulnerability history is notably clean, with no recorded CVEs. This is a positive indicator of past security diligence. However, the static analysis reveals weaknesses that, if left unaddressed, could lead to future vulnerabilities. The combination of a dangerous function, a high severity taint flow, and unprotected entry points indicates that while past security has been good, the current implementation has identifiable risks that require attention.
Key Concerns
- 5 unprotected AJAX handlers
- 1 dangerous function (unserialize)
- 1 high severity taint flow
- Only 2 capability checks
APL – Auto-Pickup Locations for WooCommerce Security Vulnerabilities
APL – Auto-Pickup Locations for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
APL – Auto-Pickup Locations for WooCommerce Attack Surface
AJAX Handlers 14
WordPress Hooks 23
Maintenance & Trust
APL – Auto-Pickup Locations for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
APL – Auto-Pickup Locations for WooCommerce Alternatives
Hide Shipping Method For WooCommerce
hide-shipping-method-for-woocommerce
Allows store owners to hide shipping methods based on specific conditions!
Zorem Local Pickup
advanced-local-pickup-for-woocommerce
Zorem Local Pickup plugin enhances WooCommerce by streamlining in-store pickups, offering a dedicated workflow for local pickup fulfillment.
ELEX Hide WooCommerce Shipping Methods
elex-hide-woocommerce-shipping-methods-basic
The ELEX Hide WooCommerce Shipping Methods is a free plugin allows you to hide certain shipping methods based on shipping class, order weight, other e …
WC Hide Shipping Methods Except Pont
wc-hide-shipping-methods-except-pont
This plugin automatically hides all other shipping methods when “free shipping” is available.
Disable Local Pickup on Ship to Different Address for WooCommerce
woo-disable-local-pickup-on-ship-to-different-address
An extension that disables WooCommerce built-in Local Pickup shipping method on CLASSIC checkout when a customer chooses to ship to a different addres …
APL – Auto-Pickup Locations for WooCommerce Developer Profile
5 plugins · 850 total installs
How We Detect APL – Auto-Pickup Locations for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-pickup-locations-for-woocommerce/assets/js/custom-select2.js/wp-content/plugins/auto-pickup-locations-for-woocommerce/onboarding/enqueue.php/wp-content/plugins/auto-pickup-locations-for-woocommerce/assets/img/menulogo.svghttps://digages.com/docs/https://digages.com/contact/assets/js/custom-select2.js?ver=HTML / DOM Fingerprints
data-digages-aplwoo-countrydata-digages-aplwoo-statedata-digages-aplwoo-citydata-digages-aplwoo-zipdata-digages-aplwoo-radiusdata-digages-aplwoo-latitude+1 moredigages_aplwoo_localpickup_ajax_object