Bykea Instant Delivery Security & Risk Analysis

wordpress.org/plugins/bykea-instant-delivery

Bykea is an instant delivery service in Pakistan which is currently operating in Karachi, Lahore, Rawalpindi & Islamabad.

10 active installs v1.0 PHP 5.6.28+ WP 4.0+ Updated Nov 18, 2020
instant-deliverykarachilogistics-bykeapakistanparcel-delivery
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bykea Instant Delivery Safe to Use in 2026?

Generally Safe

Score 85/100

Bykea Instant Delivery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "bykea-instant-delivery" v1.0 plugin exhibits a seemingly robust security posture based on the provided static analysis. There are no identified entry points for direct attacks such as AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, the absence of dangerous functions and a lack of recorded vulnerabilities in its history are positive indicators.

However, several areas warrant concern. The plugin has a notable lack of both nonce checks and capability checks, which are fundamental WordPress security mechanisms. This absence is particularly worrying given the presence of two taint analysis flows with unsanitized paths. While these flows are not flagged as critical or high severity, their presence, coupled with the missing authorization checks, suggests a potential avenue for security issues if user-supplied data is not adequately handled and validated before being used in operations.

In conclusion, while the plugin has avoided known vulnerabilities and doesn't expose a large attack surface, the lack of fundamental security checks like nonces and capability checks, combined with the identified unsanitized taint flows, presents a significant weakness. The plugin developers should prioritize implementing these missing security measures to mitigate potential risks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Taint flows with unsanitized paths
  • Output escaping is not fully proper (38% issues)
Vulnerabilities
None known

Bykea Instant Delivery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Bykea Instant Delivery Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
15 prepared
Unescaped Output
10
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
2
Bundled Libraries
0

SQL Query Safety

83% prepared18 total queries

Output Escaping

62% escaped26 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
bykea_custom_form_submissions (includes\functions.php:302)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bykea Instant Delivery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actioninitbykea-instant-delivery.php:16
filtermanage_edit-shop_order_columnsincludes\functions.php:8
actionmanage_shop_order_posts_custom_columnincludes\functions.php:10
filterbulk_actions-edit-shop_orderincludes\functions.php:12
filterhandle_bulk_actions-edit-shop_orderincludes\functions.php:14
actionadmin_noticesincludes\functions.php:16
actionadmin_head-edit.phpincludes\functions.php:18
actionadmin_footer-edit.phpincludes\functions.php:20
filterwoocommerce_settings_tabs_arrayincludes\functions.php:22
actionwoocommerce_settings_tabs_bykea_api_setingsincludes\functions.php:24
actionwoocommerce_settings_tabs_bykea_pickup_addressesincludes\functions.php:26
actionwoocommerce_update_options_bykea_api_setingsincludes\functions.php:28
actionadmin_enqueue_scriptsincludes\functions.php:30
actionwp_enqueue_scriptsincludes\functions.php:32
actionadd_meta_boxesincludes\meta-boxes\bykea-order-delivery-logs.php:12
actionsave_postincludes\meta-boxes\bykea-order-delivery-logs.php:177
Maintenance & Trust

Bykea Instant Delivery Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedNov 18, 2020
PHP min version5.6.28
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Bykea Instant Delivery Developer Profile

dizyn

2 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bykea Instant Delivery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bykea-instant-delivery/js/admin-script.js/wp-content/plugins/bykea-instant-delivery/js/client-script.js
Script Paths
/wp-content/plugins/bykea-instant-delivery/js/admin-script.js/wp-content/plugins/bykea-instant-delivery/js/client-script.js
Version Parameters
bykea-instant-delivery/js/admin-script.js?ver=bykea-instant-delivery/js/client-script.js?ver=

HTML / DOM Fingerprints

Data Attributes
onclick="bydiz_shipWithByKeaSingle(
JS Globals
bydiz_shipWithByKeaSingle
FAQ

Frequently Asked Questions about Bykea Instant Delivery