
Cargus Security & Risk Analysis
wordpress.org/plugins/cargusUse Cargus delivery methods to ship and deliver your orders.
Is Cargus Safe to Use in 2026?
Mostly Safe
Score 78/100Cargus is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'cargus' plugin v1.5.9 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL query handling, exclusively using prepared statements, and shows a good percentage of properly escaped outputs. The presence of nonce and capability checks, albeit limited, is also a positive sign. However, significant concerns arise from its attack surface. With 16 AJAX handlers, a substantial 12 of them lack authentication checks, creating a large entry point for unauthorized access and potential exploitation. The code analysis also flags 18 instances of dangerous function usage, specifically `unserialize`, which is notorious for enabling object injection vulnerabilities if not handled with extreme caution and proper validation.
The taint analysis reveals 2 flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data could be manipulated to affect program execution or data integrity, though no critical or high severity flows were identified. The vulnerability history reveals a past exposure of sensitive information to an unauthorized actor, marked by a medium severity CVE. The fact that one CVE remains unpatched is a critical concern, as it leaves existing installations vulnerable to known exploits.
In conclusion, while 'cargus' has some commendable security practices, the unauthenticated AJAX handlers and the presence of `unserialize` are significant risk factors. Combined with the unpatched CVE, the plugin presents a tangible threat that requires immediate attention. Further investigation into the specific use of `unserialize` and the nature of the unsanitized taint flows is highly recommended.
Key Concerns
- Unauthenticated AJAX handlers
- Dangerous function usage: unserialize
- Unpatched CVE
- Flows with unsanitized paths
- Insufficient nonce checks
- Insufficient capability checks
- Bundled outdated library: jQuery
- Bundled outdated library: Lodash
Cargus Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Cargus <= 1.5.8 - Unauthenticated Information Exposure
Cargus Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Cargus Attack Surface
AJAX Handlers 16
WordPress Hooks 90
Scheduled Events 5
Maintenance & Trust
Cargus Maintenance & Trust
Maintenance Signals
Community Trust
Cargus Alternatives
Recently Viewed Product for WooCommerce
recently-viewed-products-for-woocommerce
Recently Viewed Products for WooCommerce Listing page, you can easily add recently viewed product section by activate the plugin.
Swift Shop for WooCommerce – Get to WooCommerce checkout faster with a smooth and hassle-free experience
swift-shop-for-woocommerce
Short Description: Transform your WooCommerce store with Swift Shop, the fastest React JS based solution for smooth shopping and checkout experiences!
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Welcart e-Commerce
usc-e-shop
Welcart is a free e-commerce plugin for Wordpress with top market share in Japan.
External Product New Tab for WooCommerce
wc-external-product-new-tab
This plugin sets all external / affiliate product buy now links on a WooCommerce site to open in a new web browser tab.
Cargus Developer Profile
1 plugin · 600 total installs
How We Detect Cargus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cargus/admin/css/cargus-debug-tool.css/wp-content/plugins/cargus/admin/js/cargus-debug-tool.jscargus/admin/css/cargus-debug-tool.css?ver=cargus/admin/js/cargus-debug-tool.js?ver=HTML / DOM Fingerprints
cargus-file-managerid="select-all-files"id="delete-selected-files"window.cargusDebugTool/wp-json/cargus/v1/some-endpoint