
CoopCycle Security & Risk Analysis
wordpress.org/plugins/coopcycleCoopCycle plugin for WordPress.
Is CoopCycle Safe to Use in 2026?
Generally Safe
Score 100/100CoopCycle has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Coopcycle plugin v1.1.1 exhibits a concerning security posture, despite some positive indicators. The static analysis reveals a significant concern with its attack surface, specifically one unprotected REST API route. This single unprotected entry point represents a direct pathway for potential attackers to interact with the plugin's functionality without proper authorization, which is a critical oversight.
While the plugin demonstrates good practices in avoiding dangerous functions and using prepared statements for SQL queries, the low percentage of properly escaped output (44%) is a significant weakness. This indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected through user-provided data that is not adequately sanitized before being displayed. The absence of nonce checks and capability checks on any entry points further exacerbates this risk, leaving the plugin vulnerable to various attacks that rely on unauthenticated or unauthorized actions.
The vulnerability history being completely clear is a positive sign, suggesting that the plugin has not had publicly disclosed vulnerabilities. However, this should not be mistaken for perfect security. The identified weaknesses in the code analysis, particularly the unprotected REST API and insufficient output escaping, represent inherent risks that could be exploited. The plugin's overall security is thus a mixed bag, with strengths in some areas but critical weaknesses in others that demand immediate attention.
Key Concerns
- Unprotected REST API route
- Low percentage of properly escaped output
- Missing nonce checks on entry points
- Missing capability checks on entry points
CoopCycle Security Vulnerabilities
CoopCycle Code Analysis
Output Escaping
CoopCycle Attack Surface
REST API Routes 1
WordPress Hooks 22
Maintenance & Trust
CoopCycle Maintenance & Trust
Maintenance Signals
Community Trust
CoopCycle Alternatives
The Courier Guy Shipping for WooCommerce
the-courier-guy
This is the official WooCommerce extension to ship products using The Courier Guy.
AppScenic – Smart AI Dropshipping
appscenic
Expand your store catalogue with no upfront inventory cost. Source high-quality products from verified domestic suppliers and use AI in the process.
CDEKDelivery
cdekdelivery
Integration with CDEK delivery for your WooCommerce store.
DHL eCommerce (Benelux) for WooCommerce
dhlpwc
DHL eCommerce (Benelux) presents: The official DHL eCommerce for WooCommerce plugin to automate your e-commerce shipping process.
Flat Rate per State/Country/Region for WooCommerce
flat-rate-per-countryregion-for-woocommerce
This plugin allows you to set a flat delivery rate per States, Countries or World Regions on WooCommerce.
CoopCycle Developer Profile
1 plugin · 10 total installs
How We Detect CoopCycle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coopcycle/build/shipping-date-picker/index.js/wp-content/plugins/coopcycle/build/shipping-date-picker/index.asset.php/wp-content/plugins/coopcycle/coopcycle-blocks-integration.php/wp-content/plugins/coopcycle/coopcycle-extend-store-endpoint.php/wp-content/plugins/coopcycle/coopcycle-extend-woo-core.php/wp-content/plugins/coopcycle/legacy_shortcode.php/wp-content/plugins/coopcycle/custom_colums.php/wp-content/plugins/coopcycle/src/ShippingMethod.php+3 morecoopcycle/style.css?ver=coopcycle/script.js?ver=HTML / DOM Fingerprints
coopcycle-shipping-date-picker<!-- CoopCycle plugin for WordPress --><!-- Check if WooCommerce is active --><!-- https://github.com/woocommerce/woocommerce/blob/trunk/docs/extension-development/check-if-woo-is-active.md --><!-- Check if the shortcode is used -->+3 moredata-enqueue-shipping-date-pickercoopcycle_shipping_date_picker_params/coopcycle/v1/shipping-date-options