
Blowhorn Logistics Same Day Delivery Security & Risk Analysis
wordpress.org/plugins/blowhorn-logistics-same-day-deliveryBlowhorn Logistics Same Day Delivery plugin helps you ship out your products from the website making the fulfilment process seamless.
Is Blowhorn Logistics Same Day Delivery Safe to Use in 2026?
Generally Safe
Score 85/100Blowhorn Logistics Same Day Delivery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "blowhorn-logistics-same-day-delivery" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a remarkably small attack surface with zero identified entry points (AJAX, REST API, shortcodes, cron). This suggests a limited potential for direct external exploitation. Additionally, there are no recorded CVEs, which is a strong indicator of a secure history. However, there are significant concerns within the code analysis. The plugin performs SQL queries without using prepared statements, posing a risk of SQL injection. Furthermore, the taint analysis identified two flows with unsanitized paths, despite the reported zero critical or high severity issues. This, coupled with a lack of capability checks and nonce checks on potential entry points (even though there are none currently), suggests potential blind spots in sanitization and authorization that could become critical if the plugin evolves or if entry points are added. The external HTTP requests also warrant scrutiny for potential vulnerabilities. While the current lack of reported vulnerabilities and a small attack surface are positive, the identified code-level risks, particularly raw SQL and unsanitized paths, necessitate attention to prevent future security incidents.
Key Concerns
- 100% of SQL queries are not prepared
- Taint analysis found unsanitized paths
- No nonce checks implemented
- No capability checks implemented
- 68% of output is properly escaped (implies 32% is not)
- 4 external HTTP requests
Blowhorn Logistics Same Day Delivery Security Vulnerabilities
Blowhorn Logistics Same Day Delivery Release Timeline
Blowhorn Logistics Same Day Delivery Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Blowhorn Logistics Same Day Delivery Attack Surface
WordPress Hooks 15
Maintenance & Trust
Blowhorn Logistics Same Day Delivery Maintenance & Trust
Maintenance Signals
Community Trust
Blowhorn Logistics Same Day Delivery Alternatives
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Shipbubble – Shipping Automation for Woocommerce
shipbubble
[youtube https://www.youtube.com/watch?v=eGxMxB0QbXc]
RT Deliveries
rtdeliveries
Integrate WooCommerce with Road Train Deliveries (RTD) for automated shipping, tracking, and order syncing.
Ship Quik shipping
ship-quik
Ship-Quik: Simplifying Shipping, Saving Time
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
Blowhorn Logistics Same Day Delivery Developer Profile
1 plugin · 10 total installs
How We Detect Blowhorn Logistics Same Day Delivery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blowhorn-logistics-same-day-delivery/assets/css/blowhorn-tracking.css/wp-content/plugins/blowhorn-logistics-same-day-delivery/assets/js/blowhorn-tracking.jsblowhorn-logistics-same-day-delivery/assets/css/blowhorn-tracking.css?ver=blowhorn-logistics-same-day-delivery/assets/js/blowhorn-tracking.js?ver=HTML / DOM Fingerprints
track-information Copyright (C) 2021 Blowhorn (email : tech@blowhorn.net) This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2+12 moredata-bh_reference_numberdata-awb_number