
Cocolis Officiel : Méthodes de livraison pour WooCommerce Security & Risk Analysis
wordpress.org/plugins/cocolisL’extension Cocolis pour WooCommerce offre une livraison économique et écologique, intégrée à votre site pour une meilleure expérience client.
Is Cocolis Officiel : Méthodes de livraison pour WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Cocolis Officiel : Méthodes de livraison pour WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cocolis" plugin version 1.1.5 exhibits a concerning security posture primarily due to a significantly exposed attack surface. All 8 REST API routes lack permission callbacks, making them directly accessible to any user, including unauthenticated ones. This represents a critical weakness as it allows for potential manipulation or unintended execution of plugin functionality by unauthorized actors. While the plugin does not utilize dangerous functions, performs SQL queries using prepared statements, and has no file operations or external HTTP requests, these strengths are overshadowed by the lack of authorization on its primary interaction points. The absence of nonces and capability checks further exacerbates the risk of cross-site request forgery (CSRF) and privilege escalation, especially in conjunction with the unprotected REST API endpoints. The taint analysis revealed two flows with unsanitized paths, which could potentially lead to path traversal vulnerabilities if not properly handled within the application context, although the severity was not classified as critical or high. The lack of any recorded vulnerability history, while positive, does not mitigate the inherent risks identified in the current static analysis. This plugin requires immediate attention to implement proper authentication and authorization mechanisms on its REST API endpoints to secure its functionality.
Key Concerns
- REST API routes without permission callbacks
- Unsanitized paths in taint flows
- Missing nonce checks
- Missing capability checks
- Low output escaping percentage
Cocolis Officiel : Méthodes de livraison pour WooCommerce Security Vulnerabilities
Cocolis Officiel : Méthodes de livraison pour WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Cocolis Officiel : Méthodes de livraison pour WooCommerce Attack Surface
REST API Routes 8
WordPress Hooks 13
Maintenance & Trust
Cocolis Officiel : Méthodes de livraison pour WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Cocolis Officiel : Méthodes de livraison pour WooCommerce Alternatives
Smart COD for WooCommerce
wc-smart-cod
All the COD restrictions and extra fees you'll ever need, in a single plugin.
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Print Invoice & Delivery Notes for WooCommerce
woocommerce-delivery-notes
Create and print PDF invoices, delivery notes and receipts for your WooCommerce orders. Choose your document format from multiple templates.
Order Delivery Date for WooCommerce
order-delivery-date-for-woocommerce
Let customers choose delivery dates & times on checkout. Simplify delivery management by blocking holidays & setting max deliveries per day.
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Cocolis Officiel : Méthodes de livraison pour WooCommerce Developer Profile
1 plugin · 40 total installs
How We Detect Cocolis Officiel : Méthodes de livraison pour WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cocolis/assets/css/admin-cocolis.css/wp-content/plugins/cocolis/assets/css/shipping-cocolis.css/wp-content/plugins/cocolis/assets/js/admin-cocolis.js/wp-content/plugins/cocolis/assets/js/shipping-cocolis.js/wp-content/plugins/cocolis/assets/js/admin-cocolis.js/wp-content/plugins/cocolis/assets/js/shipping-cocolis.jscocolis/assets/css/admin-cocolis.css?ver=cocolis/assets/css/shipping-cocolis.css?ver=cocolis/assets/js/admin-cocolis.js?ver=cocolis/assets/js/shipping-cocolis.js?ver=HTML / DOM Fingerprints
cocolis-admin-notice<!-- The main address pieces: --><!-- The configuration of the Cocolis module is not correctly configured to fully use it. --><!-- The address entered in the Woocommerce settings is not properly configured to fully use the Cocolis module. --><!-- Check if WooCommerce is active -->+5 moredata-noncedata-order-idcocolis_admin_paramscocolis_shipping_params/wp-json/cocolis/v1/shipping-rates/wp-json/cocolis/v1/orders