AW WooCommerce TIKI Shipping Security & Risk Analysis

wordpress.org/plugins/aw-woocommerce-tiki

Woocommerce TIKI adalah Plugin khusus Woocommerce yang digunakan untuk mengintegrasikan ongkos kirim dengan total belanja calon konsumen Anda.

10 active installs v4.0.3 PHP + WP 4.0+ Updated Mar 5, 2017
commerceecommerceshippingwoocommercewoothemes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AW WooCommerce TIKI Shipping Safe to Use in 2026?

Generally Safe

Score 85/100

AW WooCommerce TIKI Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'aw-woocommerce-tiki' plugin version 4.0.3 presents a generally good security posture, with no recorded vulnerabilities or CVEs. The static analysis shows a commendable absence of dangerous functions, raw SQL queries, file operations, and a significant attack surface. All identified SQL queries utilize prepared statements, which is a strong indicator of secure database interaction. The plugin also implements nonce checks and some capability checks, further reinforcing its security measures.

However, there are notable areas for improvement. The plugin exhibits a concerning 52% rate of properly escaped output, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals three flows with unsanitized paths, which, despite not being classified as critical or high severity, warrants attention as it suggests potential for unexpected behavior or information disclosure if these paths are ever exposed.

While the plugin's vulnerability history is clean, the issues identified in the static and taint analysis suggest a reactive rather than proactive approach to security. The lack of critical or high-severity findings is positive, but the presence of unescaped output and unsanitized paths indicates that the plugin could benefit from more rigorous input validation and output sanitization practices.

Key Concerns

  • High percentage of unescaped output
  • Taint flows with unsanitized paths
Vulnerabilities
None known

AW WooCommerce TIKI Shipping Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AW WooCommerce TIKI Shipping Release Timeline

v4.0.3Current
v4.0.2
v4.0.1
Code Analysis
Analyzed Apr 16, 2026

AW WooCommerce TIKI Shipping Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
29 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

52% escaped56 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
admin_options (includes/shipping/shipping-method.php:518)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AW WooCommerce TIKI Shipping Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionwp_enqueue_scriptsaw-woocommerce-tiki.php:138
actionadmin_enqueue_scriptsaw-woocommerce-tiki.php:139
actionadmin_noticesaw-woocommerce-tiki.php:140
filterwoocommerce_checkout_fieldsincludes/shipping/shipping-frontend.php:31
filterwoocommerce_billing_fieldsincludes/shipping/shipping-frontend.php:34
filterwoocommerce_shipping_fieldsincludes/shipping/shipping-frontend.php:37
filterwoocommerce_shipping_calculator_enable_cityincludes/shipping/shipping-frontend.php:40
actionwoocommerce_review_order_before_shippingincludes/shipping/shipping-frontend.php:43
actiontiki_admin_noticesincludes/shipping/shipping-method.php:428
actionwoocommerce_shipping_initincludes/shipping/shipping.php:35
filterwoocommerce_shipping_methodsincludes/shipping/shipping.php:44
filterwoocommerce_shipping_chosen_methodincludes/shipping/shipping.php:47
filterweight_unit_total_weightincludes/shipping/shipping.php:154
Maintenance & Trust

AW WooCommerce TIKI Shipping Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedMar 5, 2017
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AW WooCommerce TIKI Shipping Developer Profile

agenwebsite

3 plugins · 320 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AW WooCommerce TIKI Shipping

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aw-woocommerce-tiki/assets/css/admin.css/wp-content/plugins/aw-woocommerce-tiki/assets/js/admin.min.js/wp-content/plugins/aw-woocommerce-tiki/assets/js/admin.js/wp-content/plugins/aw-woocommerce-tiki/assets/js/shipping.min.js/wp-content/plugins/aw-woocommerce-tiki/assets/js/shipping.js
Script Paths
/wp-content/plugins/aw-woocommerce-tiki/assets/js/shipping.min.js/wp-content/plugins/aw-woocommerce-tiki/assets/js/shipping.js/wp-content/plugins/aw-woocommerce-tiki/assets/js/admin.min.js/wp-content/plugins/aw-woocommerce-tiki/assets/js/admin.js
Version Parameters
aw-woocommerce-tiki/assets/js/shipping.min.js?ver=aw-woocommerce-tiki/assets/js/shipping.js?ver=aw-woocommerce-tiki/assets/js/admin.min.js?ver=aw-woocommerce-tiki/assets/js/admin.js?ver=aw-woocommerce-tiki/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
woocommerce-tiki-shipping-fields
HTML Comments
<!-- AW WooCommerce TIKI Shipping --><!-- AW WooCommerce TIKI Shipping Admin -->
Data Attributes
data-nonce
JS Globals
agenwebsite_woocommerce_tiki_paramsagenwebsite_tiki_admin_params
FAQ

Frequently Asked Questions about AW WooCommerce TIKI Shipping