BLAZING Shipment Tracking Security & Risk Analysis
wordpress.org/plugins/blazing-woocommerce-shipment-trackingThis plugin adds courier and tracking number to the woocommerce order, and a dedicated email to send shipment tracking info to the customer.
Is BLAZING Shipment Tracking Safe to Use in 2026?
Generally Safe
Score 85/100BLAZING Shipment Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "blazing-woocommerce-shipment-tracking" plugin version 2.1.0 demonstrates a generally good security posture with several strengths. The static analysis reveals no identified dangerous functions, all SQL queries are properly prepared, and there are no recorded vulnerabilities in its history. The plugin also implements nonce and capability checks, and its limited attack surface is further mitigated by the absence of unprotected entry points.
However, a significant concern arises from the output escaping. With 15 total outputs, only 40% are properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities. While taint analysis didn't reveal any immediate unsanitized paths, this high percentage of unescaped output represents a tangible risk that attackers could exploit, especially in conjunction with the single AJAX handler. The lack of a vulnerability history is positive, but it doesn't negate the risks identified in the current code analysis, particularly regarding output sanitization.
In conclusion, while the plugin benefits from secure database practices and a controlled attack surface, the substantial number of unescaped outputs presents a notable weakness. Addressing the output escaping would significantly improve its security and mitigate the risk of XSS attacks.
Key Concerns
- High percentage of unescaped output (40%)
BLAZING Shipment Tracking Security Vulnerabilities
BLAZING Shipment Tracking Release Timeline
BLAZING Shipment Tracking Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
BLAZING Shipment Tracking Attack Surface
AJAX Handlers 1
WordPress Hooks 15
Maintenance & Trust
BLAZING Shipment Tracking Maintenance & Trust
Maintenance Signals
Community Trust
BLAZING Shipment Tracking Alternatives
Descartes ShipRush Integration
descartes-shiprush-integration
Export orders to My.ShipRush.com and update tracking details.
Tracking for Fedex USPS
tracking-for-fedex-usps
Once activated, this plugin generated a shortcode [tracking-fedex-usps] that you can insert into any post or page. The shortcode will be displayed as …
TrackingMore Order Tracking for WooCommerce (Free plan available)
trackingmore-woocommerce-tracking
All in one eCommerce order tracking, tracking page, customer notification and EDD. Support USPS, FedEx, UPS, DHL and 1100 carriers.
ReachShip WooCommerce Multi-Carrier & Conditional Shipping
elex-reachship-multi-carrier-conditional-shipping
Multi-carrier WooCommerce shipping plugin to get rates, print labels, pickups & track DHL, FedEx, UPS, USPS, Australia Post via ReachShip API.
Live Rates for ShipStation
live-rates-for-shipstation
Pulls live shipping rates from your favorite carriers connected to 3rd party provider ShipStation.
BLAZING Shipment Tracking Developer Profile
3 plugins · 3K total installs
How We Detect BLAZING Shipment Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blazing-woocommerce-shipment-tracking/assets/css/admin.css/wp-content/plugins/blazing-woocommerce-shipment-tracking/assets/css/bst-tracking-frontend.css/wp-content/plugins/blazing-woocommerce-shipment-tracking/assets/js/bst-tracking-frontend.js/wp-content/plugins/blazing-woocommerce-shipment-tracking/assets/js/bst-tracking-script.js/wp-content/plugins/blazing-woocommerce-shipment-tracking/assets/plugin/chosen/chosen.min.css/wp-content/plugins/blazing-woocommerce-shipment-tracking/assets/plugin/chosen/chosen.jquery.min.js/wp-content/plugins/blazing-woocommerce-shipment-tracking/assets/js/bst-tracking-frontend.js/wp-content/plugins/blazing-woocommerce-shipment-tracking/assets/js/bst-tracking-script.js/wp-content/plugins/blazing-woocommerce-shipment-tracking/assets/plugin/chosen/chosen.jquery.min.jsblazing-woocommerce-shipment-tracking/assets/css/admin.css?ver=blazing-woocommerce-shipment-tracking/assets/css/bst-tracking-frontend.css?ver=blazing-woocommerce-shipment-tracking/assets/js/bst-tracking-frontend.js?ver=blazing-woocommerce-shipment-tracking/assets/js/bst-tracking-script.js?ver=blazing-woocommerce-shipment-tracking/assets/plugin/chosen/chosen.min.css?ver=blazing-woocommerce-shipment-tracking/assets/plugin/chosen/chosen.jquery.min.js?ver=HTML / DOM Fingerprints
bst-tracking-section<!-- BLAZING Shipment Tracking Plugin<!-- BS_Shipment_Tracking class<!-- Constructor<!-- Required functions+4 moredata-tracking-order-email-noncedata-tracking-order-idbst_tracking_ajax_object/wp-json/bst-ship-track/v1[bs_tracking_details]