Custom Shipment Tracker for WooCommerce Security & Risk Analysis

wordpress.org/plugins/custom-shipment-tracker-for-woocommerce

Track WooCommerce order shipment status with a timeline view. Admin can update status and choose whether to show dates.

10 active installs v1.0 PHP 7.4+ WP 5.8+ Updated Oct 27, 2025
delivery-statusorder-trackingshippingtimelinewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Custom Shipment Tracker for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Custom Shipment Tracker for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The custom-shipment-tracker-for-woocommerce plugin version 1.0 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals a complete absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests. Crucially, all identified output is properly escaped, and a nonce check is present, indicating good development practices against common web vulnerabilities. The plugin also has a clean vulnerability history with no recorded CVEs, which is a significant positive indicator. The complete lack of an observable attack surface (AJAX, REST API, shortcodes, cron events) further contributes to its secure standing. While the absence of capability checks is noted, the overall minimal attack surface and robust code hygiene suggest a very low risk profile for this version. The primary weakness, if any can be inferred, is the potential for future issues if the plugin's attack surface expands without corresponding security measures, but based on current data, it's highly secure.

Key Concerns

  • No capability checks on entry points
Vulnerabilities
None known

Custom Shipment Tracker for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Custom Shipment Tracker for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
9 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped9 total outputs
Attack Surface

Custom Shipment Tracker for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwoocommerce_checkout_update_order_metacustom-shipment-tracker.php:13
actionwoocommerce_admin_order_data_after_order_detailscustom-shipment-tracker.php:20
actionwoocommerce_process_shop_order_metacustom-shipment-tracker.php:54
actionwoocommerce_order_details_after_order_tablecustom-shipment-tracker.php:77
Maintenance & Trust

Custom Shipment Tracker for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 27, 2025
PHP min version7.4
Downloads165

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Custom Shipment Tracker for WooCommerce Developer Profile

Digitalgrub

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Shipment Tracker for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
shipment-timelinestepcompletedactivecirclelabeldateorder-shipment-status
Data Attributes
name="shipment_status"name="show_shipment_dates"name="shipment_status_nonce"
Shortcode Output
<h3>Shipment Tracker</h3><div class="shipment-timeline"><div class="step<div class="circle"></div>
FAQ

Frequently Asked Questions about Custom Shipment Tracker for WooCommerce