
BOX NOW Delivery Security & Risk Analysis
wordpress.org/plugins/box-now-deliveryBOX NOW the future of parcel delivery.
Is BOX NOW Delivery Safe to Use in 2026?
Mostly Safe
Score 78/100BOX NOW Delivery is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "box-now-delivery" plugin v3.0.2 exhibits a concerning security posture primarily due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and largely escaping output, the lack of authorization checks on 9 out of 12 entry points creates a substantial attack surface. The taint analysis did not reveal any critical or high-severity vulnerabilities, which is a positive sign. However, the presence of unsanitized paths in 5 out of 7 analyzed flows warrants further investigation, as these could potentially lead to issues if exploited in conjunction with other vulnerabilities.
The plugin's vulnerability history is a major red flag. It has a known, unpatched medium-severity CVE from early 2026, and the pattern of past vulnerabilities indicates a recurring issue with missing authorization. This suggests a consistent oversight in securing critical functionalities within the plugin. Despite the positive aspects like secure SQL handling and good output escaping, the combination of a large number of unprotected AJAX endpoints and a history of authorization-related vulnerabilities points to a medium-to-high overall risk for websites using this plugin.
Key Concerns
- 9 out of 12 AJAX handlers without auth checks
- 1 unpatched medium severity CVE
- 5 flows with unsanitized paths
- 3 nonce checks, but 9 AJAX handlers unprotected
BOX NOW Delivery Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BOX NOW Delivery <= 3.0.2 - Missing Authorization
BOX NOW Delivery Code Analysis
Output Escaping
Data Flow Analysis
BOX NOW Delivery Attack Surface
AJAX Handlers 12
WordPress Hooks 35
Maintenance & Trust
BOX NOW Delivery Maintenance & Trust
Maintenance Signals
Community Trust
BOX NOW Delivery Alternatives
BOX NOW Delivery Croatia
box-now-delivery-croatia
BOX NOW the future of parcel delivery.
SMTP2GO for WordPress – Email Made Easy
smtp2go
Resolve email delivery issues, increase inbox placement, track sent email, get 24/7 support, and real-time reporting.
Smart COD for WooCommerce
wc-smart-cod
All the COD restrictions and extra fees you'll ever need, in a single plugin.
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Print Invoice & Delivery Notes for WooCommerce
woocommerce-delivery-notes
Create and print PDF invoices, delivery notes and receipts for your WooCommerce orders. Choose your document format from multiple templates.
BOX NOW Delivery Developer Profile
1 plugin · 5K total installs
How We Detect BOX NOW Delivery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/box-now-delivery/js/box-now-delivery.js/wp-content/plugins/box-now-delivery/css/box-now-delivery.css/wp-content/plugins/box-now-delivery/js/box-now-delivery-blocks.js/wp-content/plugins/box-now-delivery/js/box-now-delivery.js/wp-content/plugins/box-now-delivery/js/box-now-delivery-blocks.jsHTML / DOM Fingerprints
boxnow-form-row-hiddenboxnow-locker-id-fielddata-boxnow-partner-iddata-boxnow-embedded-iframedata-boxnow-display-modedata-boxnow-button-colordata-boxnow-button-textdata-boxnow-locker-not-selected-message+3 moreboxNowDeliverySettings