
BOX NOW Delivery Croatia Security & Risk Analysis
wordpress.org/plugins/box-now-delivery-croatiaBOX NOW the future of parcel delivery.
Is BOX NOW Delivery Croatia Safe to Use in 2026?
Generally Safe
Score 100/100BOX NOW Delivery Croatia has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'box-now-delivery-croatia' plugin v3.0.1 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries by exclusively using prepared statements and shows a high percentage of properly escaped output. The absence of known vulnerabilities and dangerous functions in its history is also a significant strength, suggesting a history of security awareness. However, the plugin presents a considerable attack surface, with a significant number of unprotected AJAX handlers. The taint analysis, while not revealing critical or high-severity issues, identified several flows with unsanitized paths, indicating a potential for unexpected behavior or data manipulation if combined with other factors.
The primary concern lies in the 9 unprotected AJAX handlers, which represent direct entry points into the plugin's functionality that lack authentication checks. This could allow unauthenticated users to trigger potentially sensitive operations. While the vulnerability history is clean, the presence of unsanitized paths in the taint analysis warrants attention. Coupled with the unprotected AJAX handlers, these could become exploitable if specific input is provided. The limited number of nonce checks (3) further exacerbates the risk associated with the numerous unprotected AJAX endpoints.
In conclusion, the plugin has good internal coding practices for SQL and output handling, and a clean vulnerability record. Nevertheless, the large number of unprotected AJAX entry points and the identified unsanitized paths represent notable weaknesses that require immediate attention to mitigate potential security risks. The lack of capability checks on any entry points is also a significant oversight.
Key Concerns
- 9 unprotected AJAX handlers
- 5 flows with unsanitized paths
- Lack of capability checks on entry points
- Limited nonce checks (3)
BOX NOW Delivery Croatia Security Vulnerabilities
BOX NOW Delivery Croatia Code Analysis
Output Escaping
Data Flow Analysis
BOX NOW Delivery Croatia Attack Surface
AJAX Handlers 12
WordPress Hooks 35
Maintenance & Trust
BOX NOW Delivery Croatia Maintenance & Trust
Maintenance Signals
Community Trust
BOX NOW Delivery Croatia Alternatives
BOX NOW Delivery
box-now-delivery
BOX NOW the future of parcel delivery.
SMTP2GO for WordPress – Email Made Easy
smtp2go
Resolve email delivery issues, increase inbox placement, track sent email, get 24/7 support, and real-time reporting.
Smart COD for WooCommerce
wc-smart-cod
All the COD restrictions and extra fees you'll ever need, in a single plugin.
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Print Invoice & Delivery Notes for WooCommerce
woocommerce-delivery-notes
Create and print PDF invoices, delivery notes and receipts for your WooCommerce orders. Choose your document format from multiple templates.
BOX NOW Delivery Croatia Developer Profile
1 plugin · 700 total installs
How We Detect BOX NOW Delivery Croatia
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/box-now-delivery-croatia/js/box-now-delivery.js/wp-content/plugins/box-now-delivery-croatia/css/box-now-delivery.css/wp-content/plugins/box-now-delivery-croatia/js/box-now-delivery-blocks.js/wp-content/plugins/box-now-delivery-croatia/js/box-now-delivery.js/wp-content/plugins/box-now-delivery-croatia/js/box-now-delivery-blocks.jsbox-now-delivery-croatia/js/box-now-delivery.js?ver=1.0.0box-now-delivery-croatia/css/box-now-delivery.cssbox-now-delivery-croatia/js/box-now-delivery-blocks.js?ver=1.0.0HTML / DOM Fingerprints
boxnow-form-row-hiddenboxnow-locker-id-fielddata-plugin-name="BOX NOW Delivery"data-plugin-version="3.0.1"boxNowDeliverySettings