
CDEKDelivery Security & Risk Analysis
wordpress.org/plugins/cdekdeliveryIntegration with CDEK delivery for your WooCommerce store.
Is CDEKDelivery Safe to Use in 2026?
Generally Safe
Score 100/100CDEKDelivery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cdekdelivery" plugin v4.2.5 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good development practices by employing prepared statements for all SQL queries, a high percentage of properly escaped output, and robust nonce and capability checks. The absence of any recorded vulnerabilities (CVEs) further indicates a mature and secure development process or a lack of discovered weaknesses.
However, a significant concern arises from the presence of seven "dangerous functions," specifically the "assert" function, which can be exploited for code execution if not handled with extreme care. While the current static analysis did not identify any exploitable taint flows, the presence of "assert" itself introduces a potential risk vector that warrants scrutiny. The limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks, is a positive aspect that minimizes direct entry points for attackers.
In conclusion, "cdekdelivery" v4.2.5 is well-positioned from a security perspective due to its adherence to many security best practices and its clean vulnerability history. The primary area for improvement and heightened awareness lies in the identified use of the "assert" function, which, despite not manifesting in immediate vulnerabilities in this analysis, represents a latent risk that could be exploited in conjunction with other unforeseen issues or misconfigurations.
Key Concerns
- Presence of dangerous function 'assert'
- 16% of outputs not properly escaped
CDEKDelivery Security Vulnerabilities
CDEKDelivery Release Timeline
CDEKDelivery Code Analysis
Dangerous Functions Found
Output Escaping
CDEKDelivery Attack Surface
WordPress Hooks 35
Maintenance & Trust
CDEKDelivery Maintenance & Trust
Maintenance Signals
Community Trust
CDEKDelivery Alternatives
Flat Rate per State/Country/Region for WooCommerce
flat-rate-per-countryregion-for-woocommerce
This plugin allows you to set a flat delivery rate per States, Countries or World Regions on WooCommerce.
Shipping Additional Days for WooCommerce
woo-shipping-additional-days
Allows you to set additional days to your delivery date into Products and Shipping Classes.
Armada Delivery For WooCommerce
armada-delivery-for-woocommerce
A WooCommerce extension that integrates with Armada Delivery service, allowing merchants to easily ship orders, track deliveries, and manage shipping …
Lexiata Weight Based Shipping
lexiata-weight-based-shipping
Flexible WooCommerce shipping plugin that calculates costs by weight, with free-shipping and COD control options.
mpaqt for WooCommerce
mpaqt-for-woocommerce
mpaqt provides storage and fulfillment solutions for eCommerce merchants.
CDEKDelivery Developer Profile
1 plugin · 2K total installs
How We Detect CDEKDelivery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cdekdelivery/build/cdek-widget.umd.js/wp-content/plugins/cdekdelivery/build/cdek-checkout-map.js/wp-content/plugins/cdekdelivery/build/cdek-checkout-map.css/wp-content/plugins/cdekdelivery/build/cdek-widget.umd.js/wp-content/plugins/cdekdelivery/build/cdek-checkout-map.jscdekdelivery/build/cdek-checkout-map.js?ver=cdekdelivery/build/cdek-checkout-map.css?ver=HTML / DOM Fingerprints
data-noncedata-prefixcdek/wp-json/cdekdelivery/cb