BOX NOW Delivery Croatia Security & Risk Analysis

wordpress.org/plugins/box-now-delivery-croatia

BOX NOW the future of parcel delivery.

700 active installs v3.0.1 PHP 8.0+ WP 6.2+ Updated Feb 18, 2026
boxnowdelivery
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is BOX NOW Delivery Croatia Safe to Use in 2026?

Generally Safe

Score 100/100

BOX NOW Delivery Croatia has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'box-now-delivery-croatia' plugin v3.0.1 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries by exclusively using prepared statements and shows a high percentage of properly escaped output. The absence of known vulnerabilities and dangerous functions in its history is also a significant strength, suggesting a history of security awareness. However, the plugin presents a considerable attack surface, with a significant number of unprotected AJAX handlers. The taint analysis, while not revealing critical or high-severity issues, identified several flows with unsanitized paths, indicating a potential for unexpected behavior or data manipulation if combined with other factors.

The primary concern lies in the 9 unprotected AJAX handlers, which represent direct entry points into the plugin's functionality that lack authentication checks. This could allow unauthenticated users to trigger potentially sensitive operations. While the vulnerability history is clean, the presence of unsanitized paths in the taint analysis warrants attention. Coupled with the unprotected AJAX handlers, these could become exploitable if specific input is provided. The limited number of nonce checks (3) further exacerbates the risk associated with the numerous unprotected AJAX endpoints.

In conclusion, the plugin has good internal coding practices for SQL and output handling, and a clean vulnerability record. Nevertheless, the large number of unprotected AJAX entry points and the identified unsanitized paths represent notable weaknesses that require immediate attention to mitigate potential security risks. The lack of capability checks on any entry points is also a significant oversight.

Key Concerns

  • 9 unprotected AJAX handlers
  • 5 flows with unsanitized paths
  • Lack of capability checks on entry points
  • Limited nonce checks (3)
Vulnerabilities
None known

BOX NOW Delivery Croatia Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BOX NOW Delivery Croatia Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
111 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
8
Bundled Libraries
0

Output Escaping

93% escaped119 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

7 flows5 with unsanitized paths
boxnow_cancel_voucher_ajax_handler (box-now-delivery.php:893)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
9 unprotected

BOX NOW Delivery Croatia Attack Surface

Entry Points12
Unprotected9

AJAX Handlers 12

authwp_ajax_boxnow_set_lockerbox-now-delivery.php:799
noprivwp_ajax_boxnow_set_lockerbox-now-delivery.php:800
authwp_ajax_bndp_set_boxnow_lockerbox-now-delivery.php:801
noprivwp_ajax_bndp_set_boxnow_lockerbox-now-delivery.php:802
authwp_ajax_bndp_clear_boxnow_lockerbox-now-delivery.php:812
authwp_ajax_cancel_voucherbox-now-delivery.php:941
noprivwp_ajax_cancel_voucherbox-now-delivery.php:942
authwp_ajax_create_box_now_vouchersbox-now-delivery.php:1002
authwp_ajax_print_box_now_voucherbox-now-delivery.php:1033
noprivwp_ajax_print_box_now_voucherbox-now-delivery.php:1034
authwp_ajax_thankyou_php_boxnowbox-now-delivery.php:1228
noprivwp_ajax_thankyou_php_boxnowbox-now-delivery.php:1229
WordPress Hooks 35
actionwp_enqueue_scriptsbox-now-delivery.php:59
actionwoocommerce_blocks_checkout_enqueue_databox-now-delivery.php:102
filterwoocommerce_checkout_fieldsbox-now-delivery.php:123
actionwp_footerbox-now-delivery.php:140
actionwp_footerbox-now-delivery.php:160
actionwoocommerce_admin_order_data_after_billing_addressbox-now-delivery.php:163
actionwoocommerce_process_shop_order_metabox-now-delivery.php:281
actionwoocommerce_checkout_create_orderbox-now-delivery.php:329
actionwoocommerce_store_api_checkout_order_processedbox-now-delivery.php:331
actionwoocommerce_store_api_checkout_update_order_from_requestbox-now-delivery.php:377
actionadmin_noticesbox-now-delivery.php:392
filterwoocommerce_gateway_titlebox-now-delivery.php:398
actionwoocommerce_order_status_completedbox-now-delivery.php:419
actionwoocommerce_review_order_before_paymentbox-now-delivery.php:784
actionwoocommerce_admin_order_data_after_shipping_addressbox-now-delivery.php:878
actionadmin_enqueue_scriptsbox-now-delivery.php:891
actionadmin_footerbox-now-delivery.php:1073
actionadmin_enqueue_scriptsbox-now-delivery.php:1075
actionwoocommerce_thankyoubox-now-delivery.php:1111
actionwp_enqueue_scriptsbox-now-delivery.php:1279
actionadmin_enqueue_scriptsincludes\box-now-delivery-admin-page.php:28
actionadmin_menuincludes\box-now-delivery-admin-page.php:214
actionadmin_initincludes\box-now-delivery-admin-page.php:215
actionadmin_enqueue_scriptsincludes\box-now-delivery-admin-page.php:227
actionadmin_enqueue_scriptsincludes\box-now-delivery-admin-page.php:235
actioninitincludes\box-now-delivery-cancel-order.php:4
filterwoocommerce_admin_order_actionsincludes\box-now-delivery-cancel-order.php:7
actionadmin_headincludes\box-now-delivery-cancel-order.php:8
actionwoocommerce_order_status_changedincludes\box-now-delivery-cancel-order.php:10
actiontransition_post_statusincludes\box-now-delivery-cancel-order.php:11
actionplugins_loadedincludes\box-now-delivery-shipping-method.php:10
filterwoocommerce_gateway_descriptionincludes\box-now-delivery-shipping-method.php:280
actionwoocommerce_review_order_before_paymentincludes\box-now-delivery-shipping-method.php:326
filterwoocommerce_shipping_methodsincludes\box-now-delivery-shipping-method.php:339
actionadmin_post_boxnow-settings-saveincludes\box-now-delivery-validation.php:7
Maintenance & Trust

BOX NOW Delivery Croatia Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version8.0
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs700
Developer Profile

BOX NOW Delivery Croatia Developer Profile

ivanbebek

1 plugin · 700 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BOX NOW Delivery Croatia

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/box-now-delivery-croatia/js/box-now-delivery.js/wp-content/plugins/box-now-delivery-croatia/css/box-now-delivery.css/wp-content/plugins/box-now-delivery-croatia/js/box-now-delivery-blocks.js
Script Paths
/wp-content/plugins/box-now-delivery-croatia/js/box-now-delivery.js/wp-content/plugins/box-now-delivery-croatia/js/box-now-delivery-blocks.js
Version Parameters
box-now-delivery-croatia/js/box-now-delivery.js?ver=1.0.0box-now-delivery-croatia/css/box-now-delivery.cssbox-now-delivery-croatia/js/box-now-delivery-blocks.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
boxnow-form-row-hiddenboxnow-locker-id-field
Data Attributes
data-plugin-name="BOX NOW Delivery"data-plugin-version="3.0.1"
JS Globals
boxNowDeliverySettings
FAQ

Frequently Asked Questions about BOX NOW Delivery Croatia