
City Express Shipment Security & Risk Analysis
wordpress.org/plugins/city-express-shipmentWooCommerce integration with City Express Pickup Point and Home Delivery shipping services.
Is City Express Shipment Safe to Use in 2026?
Generally Safe
Score 100/100City Express Shipment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'city-express-shipment' v1.0.0 plugin exhibits a generally good security posture, with several positive indicators. The code analysis reveals a strong reliance on prepared statements for SQL queries, near-perfect output escaping, and a substantial number of nonce and capability checks, suggesting developers have implemented common security best practices. The absence of any known vulnerabilities in its history further reinforces this positive impression.
However, a notable concern arises from the presence of one unprotected AJAX handler. This single entry point, if exposed, could potentially be leveraged by unauthenticated attackers to perform unintended actions. While the taint analysis shows no critical or high-severity issues and there are no dangerous functions identified, this unprotected AJAX handler represents a tangible risk that requires immediate attention. The plugin's attack surface is relatively small, but the presence of any unauthenticated entry point inherently increases the risk profile.
In conclusion, the plugin demonstrates commendable development practices, particularly in data handling and output sanitization. The lack of historical vulnerabilities is a significant strength. Nevertheless, the unprotected AJAX handler is a critical weakness that overshadows the otherwise positive findings. Addressing this specific vulnerability is paramount to improving the overall security of the plugin.
Key Concerns
- AJAX handler without auth checks
City Express Shipment Security Vulnerabilities
City Express Shipment Release Timeline
City Express Shipment Code Analysis
Output Escaping
Data Flow Analysis
City Express Shipment Attack Surface
AJAX Handlers 5
WordPress Hooks 25
Maintenance & Trust
City Express Shipment Maintenance & Trust
Maintenance Signals
Community Trust
City Express Shipment Alternatives
Express One Shipment
express-one-shipment
WooCommerce integration with Express One Pickup Point and Home Delivery shipping services.
Overseas Express Shipment
overseas-express-shipment
WooCommerce integration with Overseas Express Pickup Point and Home Delivery shipping services.
Local Delivery Drivers for WooCommerce
local-delivery-drivers-for-woocommerce
Improve the way you deliver, manage drivers, assign drivers to orders, send WhatsApp, SMS, and email notifications, route planning, navigation & more!
Woot
woot-ro
Unified shipping solution for WooCommerce. Integrates all popular couriers in Romania with real-time pricing and pickup point selection.
Uber Direct Integration
uber-direct-delivery-integration
Offer instant or scheduled delivery from your WooCommerce store with real-time quotes and Uber Direct integration
City Express Shipment Developer Profile
1 plugin · 0 total installs
How We Detect City Express Shipment
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/city-express-shipment/assets/vendor/leaflet/leaflet.css/wp-content/plugins/city-express-shipment/assets/vendor/leaflet/leaflet-control-geocoder.css/wp-content/plugins/city-express-shipment/assets/vendor/leaflet/leaflet.js/wp-content/plugins/city-express-shipment/assets/vendor/leaflet/leaflet-control-geocoder.js/wp-content/plugins/city-express-shipment/assets/js/checkout-map.js/wp-content/plugins/city-express-shipment/assets/images/marker-icon-blue.png/wp-content/plugins/city-express-shipment/assets/images/marker-icon-red.png/wp-content/plugins/city-express-shipment/assets/images/marker-shadow.png+1 morecity-express-shipment/assets/vendor/leaflet/leaflet.css?ver=city-express-shipment/assets/vendor/leaflet/leaflet-control-geocoder.css?ver=city-express-shipment/assets/vendor/leaflet/leaflet.js?ver=city-express-shipment/assets/vendor/leaflet/leaflet-control-geocoder.js?ver=city-express-shipment/assets/js/checkout-map.js?ver=city-express-shipment/assets/js/admin-main-settings.js?ver=HTML / DOM Fingerprints
wc-action-button-download_labelcityExpressPickupcityExpressAdmin