Automated PostNord label and pickup – HPOS Supported Security & Risk Analysis

wordpress.org/plugins/automated-postnord-shipping

Automated PostNord Shipping plugin for WooCommerce. Generate shipping labels, track orders, and manage pickups automatically.

60 active installs v1.2.4 PHP 5.6+ WP 4.0.1+ Updated Unknown
automatedpostnord-shipingreturn-labelshipping-labelshipping-rates
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Automated PostNord label and pickup – HPOS Supported Safe to Use in 2026?

Generally Safe

Score 100/100

Automated PostNord label and pickup – HPOS Supported has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "automated-postnord-shipping" plugin v1.2.4 demonstrates a generally good security posture with no known critical vulnerabilities or reported CVEs. The absence of detected dangerous functions, the use of prepared statements for all SQL queries, and the lack of reported historical vulnerabilities suggest a development team that prioritizes secure coding practices. However, several areas raise concerns. The static analysis reveals a concerning 61% of output escaping, meaning a significant portion of outputs are not properly sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis indicates three flows with unsanitized paths, all of which are currently flagged as not critical or high severity, but this still represents a potential risk that warrants investigation and remediation.

Despite the lack of directly exploitable vulnerabilities in the provided data, the identified issues with output escaping and unsanitized paths, coupled with zero nonce and capability checks, point to a potential for privilege escalation or information disclosure if an attacker can manipulate inputs. The presence of file operations and external HTTP requests, while not inherently insecure, increase the attack surface and could be vectors for more complex attacks if not handled with extreme care. The plugin's reliance on external services (implied by HTTP requests) also introduces supply chain risks. Overall, while the plugin is not demonstrably vulnerable in the provided snapshot, there are clear areas for improvement to enhance its security robustness.

Key Concerns

  • Significant percentage of unescaped output
  • Unsanitized paths found in taint analysis
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Automated PostNord label and pickup – HPOS Supported Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Automated PostNord label and pickup – HPOS Supported Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
75
116 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
9
Bundled Libraries
0

Output Escaping

61% escaped191 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
hit_order_status_update (hitshipo_pn_basic.php:1454)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Automated PostNord label and pickup – HPOS Supported Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 29
actionbefore_woocommerce_inithitshipo_pn_basic.php:35
actionwoocommerce_shipping_inithitshipo_pn_basic.php:61
actioninithitshipo_pn_basic.php:62
filterwoocommerce_shipping_methodshitshipo_pn_basic.php:63
actionadd_meta_boxeshitshipo_pn_basic.php:65
actionwoocommerce_process_shop_order_metahitshipo_pn_basic.php:67
actionsave_posthitshipo_pn_basic.php:69
filterbulk_actions-woocommerce_page_wc-ordershitshipo_pn_basic.php:72
filterhandle_bulk_actions-woocommerce_page_wc-ordershitshipo_pn_basic.php:73
filterbulk_actions-edit-shop_orderhitshipo_pn_basic.php:75
filterhandle_bulk_actions-edit-shop_orderhitshipo_pn_basic.php:76
actionadmin_noticeshitshipo_pn_basic.php:78
filterwoocommerce_product_data_tabshitshipo_pn_basic.php:79
actionwoocommerce_process_product_metahitshipo_pn_basic.php:80
filterwoocommerce_product_data_panelshitshipo_pn_basic.php:81
actionadmin_menuhitshipo_pn_basic.php:82
actionwoocommerce_order_status_processinghitshipo_pn_basic.php:86
actionwoocommerce_order_details_after_order_tablehitshipo_pn_basic.php:87
filtermanage_woocommerce_page_wc-orders_columnshitshipo_pn_basic.php:89
actionmanage_woocommerce_page_wc-orders_custom_columnhitshipo_pn_basic.php:90
filtermanage_edit-shop_order_columnshitshipo_pn_basic.php:92
actionmanage_shop_order_posts_custom_columnhitshipo_pn_basic.php:93
actionadmin_print_styleshitshipo_pn_basic.php:95
actionwoocommerce_product_options_shippinghitshipo_pn_basic.php:101
actionwoocommerce_process_product_metahitshipo_pn_basic.php:102
actionedit_user_profilehitshipo_pn_basic.php:105
actionedit_user_profile_updatehitshipo_pn_basic.php:106
actionwoocommerce_product_after_variable_attributeshitshipo_pn_basic.php:110
actionwoocommerce_save_product_variationhitshipo_pn_basic.php:111
Maintenance & Trust

Automated PostNord label and pickup – HPOS Supported Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version5.6
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Automated PostNord label and pickup – HPOS Supported Developer Profile

Aarsiv Groups

10 plugins · 610 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Automated PostNord label and pickup – HPOS Supported

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/automated-postnord-shipping/assets/css/style.css/wp-content/plugins/automated-postnord-shipping/assets/js/admin.js/wp-content/plugins/automated-postnord-shipping/assets/js/frontend.js
Script Paths
/wp-content/plugins/automated-postnord-shipping/assets/js/admin.js/wp-content/plugins/automated-postnord-shipping/assets/js/frontend.js
Version Parameters
automated-postnord-shipping/assets/css/style.css?ver=automated-postnord-shipping/assets/js/admin.js?ver=automated-postnord-shipping/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
hitshipo_pn_product_options_optionshits_pn_hs_codehits_pn_country_of_originhits_pn_product_descriptionhit_pn_shipping_meta_box
HTML Comments
<!-- Shipi - Postnord Product Fields --><!-- Product Data Start -->
Data Attributes
hits_pn_hs_codehits_pn_country_of_originhits_pn_product_descriptionhitshipo_pn_main_settingshitshipo_pn_countryhit_pn_shipping_meta_box
JS Globals
hitshipo_pn_admin_ajax_objecthits_pn_data
FAQ

Frequently Asked Questions about Automated PostNord label and pickup – HPOS Supported