
Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Security & Risk Analysis
wordpress.org/plugins/coordinadoraCon nuestro plugin para envíos crea guías, imprime etiquetas y sigue tus envíos. Gratis para clientes con acuerdo comercial vigente con Coordinadora.
Is Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Safe to Use in 2026?
Mostly Safe
Score 78/100Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin is generally safe to use. 1 past CVE were resolved. Keep it updated.
The plugin 'coordinadora' v1.1.32 presents a mixed security posture. On the positive side, the static analysis reveals a commendably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed. Furthermore, the code signals show no dangerous functions, all SQL queries utilize prepared statements, and file operations are absent. The low number of external HTTP requests and a single capability check suggest a relatively contained plugin. However, a significant concern is the presence of one unpatched medium severity CVE related to Exposure of Sensitive Information to an Unauthorized Actor. This historical vulnerability, even if in the past, indicates a potential weakness that has not yet been addressed and could be exploited if similar issues re-emerge or if the existing vulnerability is still exploitable.
The lack of taint analysis results is neutral, as it could mean no significant flows were found or that the analysis was not comprehensive. The 80% proper output escaping is good but leaves room for improvement. The absence of nonce checks is a potential vulnerability if any of the (currently 0) entry points were to become exposed in future versions or if the count is inaccurate. Despite the small attack surface and good coding practices in SQL and file operations, the single unpatched CVE is a critical flag. The plugin's strengths lie in its contained attack surface and robust internal data handling, but the historical and unaddressed vulnerability overshadows these positives, warranting caution.
Key Concerns
- Unpatched CVE found
- Output escaping is not 100% proper
- Nonce checks are missing
Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Envíos Coordinadora Woocommerce <= 1.1.31 - Unauthenticated Sensitive Information Exposure
Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Code Analysis
Output Escaping
Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Attack Surface
WordPress Hooks 12
Maintenance & Trust
Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Maintenance & Trust
Maintenance Signals
Community Trust
Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Alternatives
QCode – Departamentos y Ciudades de Colombia para Woocommerce
wc-departamentos-y-ciudades-colombia
Plugin para mostrar el campo departamento y ciudad como listas de selección. Compatible con el plugin de Coordinadora.
Departamentos y Ciudades de Colombia para Woocommerce
departamentos-y-ciudades-de-colombia-para-woocommerce
WordPress plugin that shows dropdowns for State and City Select for WooCommerce
Departamentos y Ciudades de Colombia para Contact Form 7
departamentos-y-ciudades-de-colombia-para-contact-form-7
Este plugin es un addon para Contact Form 7 que permite listar ciudades y departamentos de Colombia.
Moovin Delivery
moovin-delivery
Plugin para entregas de paquetes con Moovin Costa Rica en Woocommerce.
Wompi Portal de Pagos
wompi-portal-de-pagos
Pasarela de Pago de WooCommerce para Wompi
Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Developer Profile
1 plugin · 500 total installs
How We Detect Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coordinadora/assets/js/droop.js/wp-content/plugins/coordinadora/assets/js/droop.jsHTML / DOM Fingerprints
entry-parameterlogo-comerciocoordinadoraShippingSettings/wp-json/cm/v1/orders<puntos-drop id="wc-droop-coordinadora"