Cyke Logistics Security & Risk Analysis

wordpress.org/plugins/cyke-logistics

Cyke official Woocommerce Plugin. Send delivery orders to your service provider right after any purchase on your website.

10 active installs v1.1.4 PHP 7.0+ WP 5.0+ Updated Nov 15, 2024
bicycledeliverieslogistics
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Cyke Logistics Safe to Use in 2026?

Generally Safe

Score 92/100

Cyke Logistics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The cyke-logistics plugin, version 1.1.4, exhibits a generally good security posture based on the provided static analysis. A significant strength is the complete absence of raw SQL queries; all are handled using prepared statements, which mitigates the risk of SQL injection. Furthermore, the plugin has no recorded vulnerability history, suggesting a good track record. However, there are areas for improvement. The presence of external HTTP requests, though not necessarily a vulnerability in itself, warrants careful review to ensure they are not susceptible to manipulation or information leakage. The reported 75% proper output escaping indicates that a quarter of outputs are not escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. The lack of capability checks is also a concern, as it implies that actions performed by the plugin may not be properly authorized, potentially allowing unauthorized users to trigger functionality.

While the static analysis shows no critical taint flows and a clean vulnerability history is a positive indicator, the identified areas of concern, particularly unescaped output and the absence of capability checks, present potential attack vectors. The external HTTP requests should be scrutinized to ensure they are implemented securely. Given the lack of critical issues or known vulnerabilities, the overall risk is currently assessed as moderate, but the identified code signals necessitate further investigation and remediation to strengthen the plugin's security.

Key Concerns

  • Unescaped output detected
  • No capability checks implemented
Vulnerabilities
None known

Cyke Logistics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Cyke Logistics Release Timeline

v1.1.4Current
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.12
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
Code Analysis
Analyzed Mar 17, 2026

Cyke Logistics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
21 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

75% escaped28 total outputs
Attack Surface

Cyke Logistics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
filterplugin_row_metacyke.php:40
actionplugins_loadedcyke.php:51
actionwp_enqueue_scriptscyke.php:78
actionwoocommerce_shipping_initcyke.php:88
filterwoocommerce_shipping_methodscyke.php:95
filterwoocommerce_get_sections_shippingcyke.php:107
filterwoocommerce_get_settings_shippingcyke.php:118
actionwoocommerce_review_order_after_shippingcyke.php:139
filtermanage_edit-shop_order_columnscyke.php:149
actionmanage_shop_order_posts_custom_columncyke.php:162
actionwoocommerce_checkout_processcyke.php:180
actionwoocommerce_checkout_update_order_metacyke.php:198
actionwoocommerce_order_status_changedcyke.php:248
actionwoocommerce_thankyoucyke.php:302
actionwoocommerce_email_before_order_tablecyke.php:310
actionwoocommerce_admin_order_data_after_shipping_addresscyke.php:336
Maintenance & Trust

Cyke Logistics Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedNov 15, 2024
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Cyke Logistics Developer Profile

Cyke

2 plugins · 20 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cyke Logistics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cyke-logistics/assets/date-picker.js/wp-content/plugins/cyke-logistics/assets/index.css
Script Paths
/wp-content/plugins/cyke-logistics/assets/date-picker.js
Version Parameters
cyke-logistics/assets/date-picker.js?ver=1.1.4cyke-logistics/assets/index.css?ver=1.1.4

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Cyke Logistics