Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Security & Risk Analysis

wordpress.org/plugins/coordinadora

Con nuestro plugin para envíos crea guías, imprime etiquetas y sigue tus envíos. Gratis para clientes con acuerdo comercial vigente con Coordinadora.

500 active installs v1.1.32 PHP 7.2+ WP 6.8.1+ Updated Dec 10, 2025
colombiacoordinadoradepartamentosenviosfulfillment
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Safe to Use in 2026?

Mostly Safe

Score 78/100

Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 3mo ago
Risk Assessment

The plugin 'coordinadora' v1.1.32 presents a mixed security posture. On the positive side, the static analysis reveals a commendably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed. Furthermore, the code signals show no dangerous functions, all SQL queries utilize prepared statements, and file operations are absent. The low number of external HTTP requests and a single capability check suggest a relatively contained plugin. However, a significant concern is the presence of one unpatched medium severity CVE related to Exposure of Sensitive Information to an Unauthorized Actor. This historical vulnerability, even if in the past, indicates a potential weakness that has not yet been addressed and could be exploited if similar issues re-emerge or if the existing vulnerability is still exploitable.

The lack of taint analysis results is neutral, as it could mean no significant flows were found or that the analysis was not comprehensive. The 80% proper output escaping is good but leaves room for improvement. The absence of nonce checks is a potential vulnerability if any of the (currently 0) entry points were to become exposed in future versions or if the count is inaccurate. Despite the small attack surface and good coding practices in SQL and file operations, the single unpatched CVE is a critical flag. The plugin's strengths lie in its contained attack surface and robust internal data handling, but the historical and unaddressed vulnerability overshadows these positives, warranting caution.

Key Concerns

  • Unpatched CVE found
  • Output escaping is not 100% proper
  • Nonce checks are missing
Vulnerabilities
1

Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-57922medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Envíos Coordinadora Woocommerce <= 1.1.31 - Unauthenticated Sensitive Information Exposure

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

80% escaped5 total outputs
Attack Surface

Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionrest_api_initincludes\controllers\CM_Controller.php:8
actionrest_api_initincludes\controllers\server.php:6
actionwoocommerce_loadedincludes\controllers\v1\QC_WC_CM_REST_Orders_Controller.php:13
actionwp_enqueue_scriptsincludes\Coordinadora_WC_Droop_Shipping.php:21
actionwoocommerce_form_field_textincludes\Coordinadora_WC_Droop_Shipping.php:22
actionwoocommerce_admin_order_data_after_order_detailsincludes\Coordinadora_WC_Order_Custom_Fields.php:6
actionwoocommerce_process_shop_order_metaincludes\Coordinadora_WC_Order_Custom_Fields.php:7
actionadmin_menuincludes\Coordinadora_WP_Menu.php:6
actionwoocommerce_shipping_initindex.php:54
actionbefore_woocommerce_initindex.php:56
actionwoocommerce_shipping_methodsindex.php:72
actionwoocommerce_order_status_processingindex.php:93
Maintenance & Trust

Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version7.2
Downloads15K

Community Trust

Rating50/100
Number of ratings4
Active installs500
Developer Profile

Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin Developer Profile

Coordinadora Mercantil S.A.

1 plugin · 500 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/coordinadora/assets/js/droop.js
Script Paths
/wp-content/plugins/coordinadora/assets/js/droop.js

HTML / DOM Fingerprints

Data Attributes
entry-parameterlogo-comercio
JS Globals
coordinadoraShippingSettings
REST Endpoints
/wp-json/cm/v1/orders
Shortcode Output
<puntos-drop id="wc-droop-coordinadora"
FAQ

Frequently Asked Questions about Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin