Datalogics Ecommerce Delivery – Datalogics Security & Risk Analysis

wordpress.org/plugins/datalogics

Datalogics Ecommerce Delivery enables seamless syncing of your WooCommerce orders with a variety of delivery companies, automating the entire shipping …

400 active installs v2.6.64 PHP 7.4+ WP 5.0+ Updated Apr 14, 2026
datalogicshfd%d7%a6%d7%99%d7%98%d7%94%d7%aa%d7%a4%d7%95%d7%96
88
A · Safe
CVEs total2
Unpatched0
Last CVEApr 8, 2026
Safety Verdict

Is Datalogics Ecommerce Delivery – Datalogics Safe to Use in 2026?

Generally Safe

Score 88/100

Datalogics Ecommerce Delivery – Datalogics has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Apr 8, 2026Updated 4d ago
Risk Assessment

The datalogics plugin v2.6.63 demonstrates a generally good security posture with several positive indicators. The absence of known vulnerabilities in its history is a significant strength. Static analysis reveals a relatively low number of entry points, with only one out of fifteen found to be unprotected. Furthermore, the plugin exhibits strong practices in output escaping, with 84% of outputs being properly escaped, and shows no critical or high severity taint flows, indicating safe handling of user-supplied data. The plugin also avoids dangerous functions and file operations, and doesn't bundle external libraries which could introduce vulnerabilities if outdated.

However, there are areas that warrant attention. The presence of 13 AJAX handlers and 1 REST API route without explicit permission callbacks represents a potential risk. While the total number of unprotected entry points is low, these specific instances could be exploited if not adequately secured by other means. The 50% usage of prepared statements for SQL queries, while not ideal, suggests that half of its database interactions might be vulnerable to SQL injection if the non-prepared queries are handling user-supplied data without proper sanitization. The plugin's reliance on external HTTP requests, though not inherently a vulnerability, adds a layer of dependency that could be a vector if those external services are compromised.

In conclusion, datalogics v2.6.63 is a well-maintained plugin with a clean vulnerability history and good output sanitization. The primary concerns revolve around the potential for unauthorized access via unprotected AJAX and REST API endpoints, and the less-than-ideal SQL query practices. Addressing these specific areas would further strengthen its security. The lack of known historical vulnerabilities is a strong positive indicator of ongoing security efforts.

Key Concerns

  • Unprotected REST API route
  • AJAX handlers without auth checks
  • SQL queries not using prepared statements
Vulnerabilities
2

Datalogics Ecommerce Delivery – Datalogics Security Vulnerabilities

CVEs by Year

2 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

Critical
2

2 total CVEs

CVE-2026-39583critical · 9.8Incorrect Privilege Assignment

Datalogics Ecommerce Delivery – Datalogics <= 2.6.62 - Unauthenticated Privilege Escalation

Apr 8, 2026 Patched in 2.6.63 (8d)
CVE-2026-2631critical · 9.8Improper Privilege Management

Datalogics Ecommerce Delivery – Datalogics < 2.6.60 - Unauthenticated Privilege Escalation

Mar 12, 2026 Patched in 2.6.60 (8d)
Version History

Datalogics Ecommerce Delivery – Datalogics Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Datalogics Ecommerce Delivery – Datalogics Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
68
369 escaped
Nonce Checks
10
Capability Checks
0
File Operations
0
External Requests
8
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

84% escaped437 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
datalogics_validate_key (actions.php:76)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Datalogics Ecommerce Delivery – Datalogics Attack Surface

Entry Points15
Unprotected1

AJAX Handlers 13

authwp_ajax_datalogics_registeractions.php:4
authwp_ajax_datalogics_validate_keyactions.php:75
authwp_ajax_datalogics_update_shipment_dataactions.php:197
authwp_ajax_datalogics_add_orderactions.php:242
authwp_ajax_datalogics_log_printactions.php:615
authwp_ajax_datalogics_create_shippingactions.php:648
authwp_ajax_datalogics_cancel_shippingactions.php:778
authwp_ajax_datalogics_get_locationsactions.php:960
noprivwp_ajax_datalogics_get_locationsactions.php:961
authwp_ajax_datalogics_track_shippingactions.php:1442
noprivwp_ajax_datalogics_track_shippingactions.php:1443
authwp_ajax_datalogics_get_close_locationsactions.php:1592
noprivwp_ajax_datalogics_get_close_locationsactions.php:1593

REST API Routes 1

GET/wp-json/datalogics/v1/get-locationsactions.php:1821

Shortcodes 1

[datalogics_shipping_tracker] actions.php:1020
WordPress Hooks 41
actionwoocommerce_order_status_changedactions.php:411
filtercron_schedulesactions.php:585
actiondatalogics_update_locations_scheduleactions.php:592
filterwoocommerce_email_classesactions.php:868
filterupdate_post_metadataactions.php:915
filterbody_classactions.php:1024
actionwoocommerce_product_options_inventory_product_dataactions.php:1701
actionwoocommerce_process_product_metaactions.php:1734
actionwoocommerce_email_after_order_tableactions.php:1798
actionrest_api_initactions.php:1818
actionwp_enqueue_scriptsactions.php:1881
actionrest_api_initapi.php:38
actiondatalogics_shipping_customer_shipping_emailclass_wc_shipping_order_email.php:36
filterplugin_action_linksdata.php:16
actionadmin_menudata.php:18
actionadmin_headdata.php:64
actionadmin_enqueue_scriptsdata.php:69
filterwoocommerce_account_menu_itemsdata.php:181
actioninitdata.php:196
actionwoocommerce_account_d-shipment-tracking_endpointdata.php:201
actioninitdata.php:211
actiontemplate_includedata.php:216
filterthe_contentdata.php:223
actioninitdata.php:263
actionadmin_enqueue_scriptsorders.php:48
filteradmin_footerorders.php:112
actionadd_meta_boxesorders.php:276
filtermanage_edit-shop_order_columnsorders.php:689
filtermanage_woocommerce_page_wc-orders_columnsorders.php:690
actionmanage_shop_order_posts_custom_columnorders.php:877
actionmanage_woocommerce_page_wc-orders_custom_columnorders.php:878
actionadmin_noticesshipping_class.php:54
actionwp_enqueue_scriptsshipping_class.php:126
actionwoocommerce_shipping_initshipping_class.php:128
filterwoocommerce_shipping_methodsshipping_class.php:981
actionwoocommerce_after_checkout_formshipping_class.php:996
actionwoocommerce_after_shipping_rateshipping_class.php:1108
actionwoocommerce_after_checkout_validationshipping_class.php:1281
filterwoocommerce_checkout_fieldsshipping_class.php:1343
actionwoocommerce_store_api_checkout_update_order_from_requestshipping_class.php:1367
actionwoocommerce_checkout_update_order_metashipping_class.php:1379

Scheduled Events 1

datalogics_update_locations_schedule
Maintenance & Trust

Datalogics Ecommerce Delivery – Datalogics Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 14, 2026
PHP min version7.4
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs400
Developer Profile

Datalogics Ecommerce Delivery – Datalogics Developer Profile

Datalogics

1 plugin · 400 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Datalogics Ecommerce Delivery – Datalogics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/datalogics/css/style_admin.css/wp-content/plugins/datalogics/js/settings.js
Script Paths
/wp-content/plugins/datalogics/js/settings.js
Version Parameters
datalogics/css/style_admin.css?ver=datalogics/js/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
datalogics-dsb-spinnerdsp-boxdsp-box-contentdsp-licensedsp-hidedsp-keydsp-buttondsp-validation+6 more
Data Attributes
id="datalogics_loader_con"id="datalogics_loader_text"id="pluginwrap"class="settings-page"id="datalogics_token"id="datalogics_register"+1 more
JS Globals
datalogics_data_settings
REST Endpoints
/wp-json/datalogics/v1/w_register
FAQ

Frequently Asked Questions about Datalogics Ecommerce Delivery – Datalogics