Blowhorn Logistics Same Day Delivery Security & Risk Analysis

wordpress.org/plugins/blowhorn-logistics-same-day-delivery

Blowhorn Logistics Same Day Delivery plugin helps you ship out your products from the website making the fulfilment process seamless.

10 active installs v1.0.0 PHP 7.2+ WP 5.2+ Updated Apr 27, 2021
blowhorncourierlogisticsshipmentshipping
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Blowhorn Logistics Same Day Delivery Safe to Use in 2026?

Generally Safe

Score 85/100

Blowhorn Logistics Same Day Delivery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "blowhorn-logistics-same-day-delivery" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a remarkably small attack surface with zero identified entry points (AJAX, REST API, shortcodes, cron). This suggests a limited potential for direct external exploitation. Additionally, there are no recorded CVEs, which is a strong indicator of a secure history. However, there are significant concerns within the code analysis. The plugin performs SQL queries without using prepared statements, posing a risk of SQL injection. Furthermore, the taint analysis identified two flows with unsanitized paths, despite the reported zero critical or high severity issues. This, coupled with a lack of capability checks and nonce checks on potential entry points (even though there are none currently), suggests potential blind spots in sanitization and authorization that could become critical if the plugin evolves or if entry points are added. The external HTTP requests also warrant scrutiny for potential vulnerabilities. While the current lack of reported vulnerabilities and a small attack surface are positive, the identified code-level risks, particularly raw SQL and unsanitized paths, necessitate attention to prevent future security incidents.

Key Concerns

  • 100% of SQL queries are not prepared
  • Taint analysis found unsanitized paths
  • No nonce checks implemented
  • No capability checks implemented
  • 68% of output is properly escaped (implies 32% is not)
  • 4 external HTTP requests
Vulnerabilities
None known

Blowhorn Logistics Same Day Delivery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Blowhorn Logistics Same Day Delivery Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Blowhorn Logistics Same Day Delivery Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
6
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

68% escaped19 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
blsdd_post_checkout_validation (class.bh-shipments.php:328)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Blowhorn Logistics Same Day Delivery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionadmin_menuclass.bh-shipments.php:24
actionadmin_initclass.bh-shipments.php:28
actionadd_meta_boxesclass.bh-shipments.php:32
actionwoocommerce_process_shop_order_metaclass.bh-shipments.php:36
actionadmin_noticesclass.bh-shipments.php:40
actionwoocommerce_after_checkout_validationclass.bh-shipments.php:44
actionwoocommerce_thankyouclass.bh-shipments.php:48
filterbulk_actions-edit-shop_orderclass.bh-shipments.php:54
filterhandle_bulk_actions-edit-shop_orderclass.bh-shipments.php:60
actionadmin_noticesclass.bh-shipments.php:66
filtermanage_edit-shop_order_columnsclass.bh-shipments.php:72
actionmanage_shop_order_posts_custom_columnclass.bh-shipments.php:77
actionblsdd_initinit.php:93
actionadmin_noticesinit.php:103
actionplugins_loadedinit.php:127
Maintenance & Trust

Blowhorn Logistics Same Day Delivery Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedApr 27, 2021
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Blowhorn Logistics Same Day Delivery Developer Profile

blowhorndev

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Blowhorn Logistics Same Day Delivery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blowhorn-logistics-same-day-delivery/assets/css/blowhorn-tracking.css/wp-content/plugins/blowhorn-logistics-same-day-delivery/assets/js/blowhorn-tracking.js
Version Parameters
blowhorn-logistics-same-day-delivery/assets/css/blowhorn-tracking.css?ver=blowhorn-logistics-same-day-delivery/assets/js/blowhorn-tracking.js?ver=

HTML / DOM Fingerprints

CSS Classes
track-information
HTML Comments
Copyright (C) 2021 Blowhorn (email : tech@blowhorn.net) This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2+12 more
Data Attributes
data-bh_reference_numberdata-awb_number
FAQ

Frequently Asked Questions about Blowhorn Logistics Same Day Delivery