BLPaczka Security & Risk Analysis

wordpress.org/plugins/blpaczka

English below. BLPaczka to wtyczka WooCommerce integrująca z BLPaczka, oferująca szeroki wybór przewoźników i punktów nadawczych dla łatwego zarządzan …

400 active installs v1.2.6 PHP 7.0+ WP 5.3+ Updated Feb 5, 2026
blpaczkapaczkaprzesylkishippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is BLPaczka Safe to Use in 2026?

Generally Safe

Score 100/100

BLPaczka has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "blpaczka" v1.2.6 plugin demonstrates a generally good security posture based on the provided static analysis. It has no recorded vulnerabilities and implements several important security practices, including using prepared statements for all SQL queries and properly escaping the vast majority of its output. The plugin also includes nonce and capability checks, which are crucial for preventing common WordPress attacks.

However, the analysis does highlight a couple of potential areas for concern. Specifically, the taint analysis revealed two flows with unsanitized paths. While classified as not critical or high severity, these could represent a weakness if user-supplied data is not handled with extreme care within these specific flows. Furthermore, the plugin makes external HTTP requests, which can introduce risks if the target endpoints are compromised or if the requests themselves are not properly secured and validated.

Overall, "blpaczka" appears to be a relatively safe plugin with a proactive approach to security. The absence of historical vulnerabilities is a strong positive indicator. The identified taint flows with unsanitized paths and the external HTTP requests are the primary areas that warrant further investigation and potential remediation to further strengthen its security.

Key Concerns

  • Flows with unsanitized paths
  • External HTTP requests made
Vulnerabilities
None known

BLPaczka Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BLPaczka Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
250 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

98% escaped254 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
BLPaczka_template_settings_content (src\BLPaczkaTemplates.php:18)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BLPaczka Attack Surface

Entry Points4
Unprotected0

REST API Routes 4

POST/wp-json/blpaczka/create-ordersrc\BLPaczkaRestRoutes.php:11
POST/wp-json/blpaczka/get-valuationsrc\BLPaczkaRestRoutes.php:18
GET/wp-json/blpaczka/check-instance-pudo-mapsrc\BLPaczkaRestRoutes.php:25
GET/wp-json/blpaczka/download-waybill/(?P<id>\d+)src\BLPaczkaRestRoutes.php:32
WordPress Hooks 36
actionadmin_noticesblpaczka.php:36
actionadd_meta_boxesblpaczka.php:163
filterwoocommerce_checkout_fieldsblpaczka.php:179
actionwoocommerce_checkout_processblpaczka.php:217
actionwoocommerce_checkout_update_order_metablpaczka.php:219
actionwoocommerce_after_shipping_rateblpaczka.php:280
actioncurrent_screenblpaczka.php:453
actionwp_enqueue_scriptsblpaczka.php:454
actionadmin_enqueue_scriptsblpaczka.php:455
actionwoocommerce_store_api_checkout_update_order_from_requestblpaczka.php:456
filterhttp_request_argsblpaczka.php:457
actionwoocommerce_blocks_checkout_block_registrationblpaczka.php:458
filtermanage_woocommerce_page_wc-orders_columnsblpaczka.php:467
filtermanage_edit-shop_order_columnsblpaczka.php:468
actionmanage_woocommerce_page_wc-orders_custom_columnblpaczka.php:483
actionmanage_shop_order_posts_custom_columnblpaczka.php:484
filterbulk_actions-woocommerce_page_wc-ordersblpaczka.php:547
filterbulk_actions-edit-shop_orderblpaczka.php:548
actionhandle_bulk_actions-woocommerce_page_wc-ordersblpaczka.php:556
actionhandle_bulk_actions-edit-shop_orderblpaczka.php:557
actionadmin_noticesblpaczka.php:659
filterflexible_shipping_integration_optionssrc\BLPaczkaFSHooks.php:21
filterflexible_shipping_method_integration_colsrc\BLPaczkaFSHooks.php:31
actionrest_api_initsrc\BLPaczkaRestRoutes.php:10
filterwoocommerce_settings_tabs_arraysrc\BLPaczkaTemplates.php:16
actionwoocommerce_settings_tabs_blpaczka_templatesrc\BLPaczkaTemplates.php:122
actionwoocommerce_update_options_blpaczka_templatesrc\BLPaczkaTemplates.php:188
actionadmin_initsrc\BLPaczkaTemplates.php:236
actionadmin_footersrc\BLPaczkaTemplates.php:256
actionwoocommerce_initsrc\settings.php:433
actionwoocommerce_sections_blpaczka_settingssrc\settings.php:444
actionwoocommerce_settings_blpaczka_settingssrc\settings.php:445
actionwoocommerce_settings_save_blpaczka_settingssrc\settings.php:446
actionwoocommerce_settings_tabs_blpaczka_settingssrc\settings.php:447
filterwoocommerce_settings_tabs_arraysrc\settings.php:448
actionadmin_enqueue_scriptssrc\settings.php:449
Maintenance & Trust

BLPaczka Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 5, 2026
PHP min version7.0
Downloads4K

Community Trust

Rating46/100
Number of ratings3
Active installs400
Developer Profile

BLPaczka Developer Profile

BLPaczka

1 plugin · 400 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BLPaczka

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blpaczka/assets/shipment-form.js/wp-content/plugins/blpaczka/assets/shipment-form.css
Script Paths
/wp-content/plugins/blpaczka/assets/shipment-form.js
Version Parameters
blpaczka/assets/shipment-form.js?ver=blpaczka/assets/shipment-form.css?ver=

HTML / DOM Fingerprints

CSS Classes
blpaczka-point
Data Attributes
data-blpaczka-api-url
JS Globals
blpaczkaApiUrl
REST Endpoints
/wp-json/blpaczka/v1/shipments
FAQ

Frequently Asked Questions about BLPaczka