Chwazi – Delivery & Pickup Scheduling for WooCommerce Security & Risk Analysis

wordpress.org/plugins/delivery-and-pickup-scheduling-for-woocommerce

Empower customers to select their preferred delivery or pickup time using a convenient datetime picker integrated into the WooCommerce checkout page.

600 active installs v1.4.9 PHP 7.4+ WP 5.7+ Updated Jan 6, 2026
datepickertimepickerwoocommercewoocommerce-delivery-datewoocommerce-pickup-date
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Chwazi – Delivery & Pickup Scheduling for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Chwazi – Delivery & Pickup Scheduling for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

This plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and properly escaping a high percentage of its output. The absence of known vulnerabilities and critical taint flows is also a strong indicator of a well-maintained codebase regarding historical issues and data sanitization. However, significant concerns arise from the static analysis. The presence of three unprotected AJAX handlers represents a substantial attack surface that could be exploited by unauthenticated users. The use of the 'unserialize' function, while not directly flagged as a critical vulnerability in taint analysis, is inherently risky and can lead to remote code execution if improperly handled with user-supplied data. The plugin also bundles the Freemius library, which, depending on its version and how it's integrated, could potentially introduce outdated components. While the lack of historical CVEs is encouraging, the direct code-level risks, particularly the unprotected AJAX endpoints and the use of unserialize, necessitate caution.

Key Concerns

  • Unprotected AJAX handlers
  • Use of dangerous function: unserialize
  • Bundled library: Freemius v1.0 (potential for outdated component)
Vulnerabilities
None known

Chwazi – Delivery & Pickup Scheduling for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Chwazi – Delivery & Pickup Scheduling for WooCommerce Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
0 prepared
Unescaped Output
6
111 escaped
Nonce Checks
1
Capability Checks
1
File Operations
32
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

unserialize$instance = @unserialize((string) $value);vendor-prefixed\nesbot\carbon\src\Carbon\Traits\Serialization.php:91
unserializeparent::__construct($date, unserialize($timezone));vendor-prefixed\nesbot\carbon\src\Carbon\Traits\Serialization.php:201
unserialize$this->__construct($date, unserialize($timezone));vendor-prefixed\nesbot\carbon\src\Carbon\Traits\Serialization.php:239

Bundled Libraries

Freemius1.0

Output Escaping

95% escaped117 total outputs
Attack Surface
3 unprotected

Chwazi – Delivery & Pickup Scheduling for WooCommerce Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_lpac_dps_dismiss_noticeincludes\Bootstrap\Main.php:215
authwp_ajax_lpac_dps_get_timesincludes\Bootstrap\Main.php:306
noprivwp_ajax_lpac_dps_get_timesincludes\Bootstrap\Main.php:307
WordPress Hooks 34
actionadmin_noticesdelivery-and-pickup-scheduling.php:42
actionadmin_noticesdelivery-and-pickup-scheduling.php:62
actionadmin_noticesdelivery-and-pickup-scheduling.php:95
actionafter_uninstalldelivery-and-pickup-scheduling.php:193
filterplugin_icondelivery-and-pickup-scheduling.php:194
actionbefore_woocommerce_initdelivery-and-pickup-scheduling.php:211
actionbefore_woocommerce_initdelivery-and-pickup-scheduling.php:217
actionplugins_loadeddelivery-and-pickup-scheduling.php:238
actionplugins_loadedincludes\Bootstrap\Main.php:149
actionadmin_menuincludes\Bootstrap\Main.php:182
actionadmin_enqueue_scriptsincludes\Bootstrap\Main.php:183
actionadmin_enqueue_scriptsincludes\Bootstrap\Main.php:184
filterplugin_action_linksincludes\Bootstrap\Main.php:185
filterwoocommerce_shop_order_list_table_columnsincludes\Bootstrap\Main.php:194
actionwoocommerce_shop_order_list_table_custom_columnincludes\Bootstrap\Main.php:195
filtermanage_edit-shop_order_columnsincludes\Bootstrap\Main.php:203
actionmanage_shop_order_posts_custom_columnincludes\Bootstrap\Main.php:204
actionadmin_noticesincludes\Bootstrap\Main.php:213
actionadd_meta_boxesincludes\Bootstrap\Main.php:217
actionadmin_initincludes\Bootstrap\Main.php:229
actionwp_enqueue_scriptsincludes\Bootstrap\Main.php:273
actionwp_enqueue_scriptsincludes\Bootstrap\Main.php:274
filterscript_loader_tagincludes\Bootstrap\Main.php:279
actionwoocommerce_checkout_update_order_reviewincludes\Bootstrap\Main.php:289
actionwoocommerce_after_checkout_validationincludes\Bootstrap\Main.php:311
actionwoocommerce_after_checkout_validationincludes\Bootstrap\Main.php:318
actionwoocommerce_after_checkout_validationincludes\Bootstrap\Main.php:325
actionwoocommerce_checkout_update_order_metaincludes\Bootstrap\Main.php:335
actionwoocommerce_order_details_after_order_tableincludes\Bootstrap\Main.php:339
filterwoocommerce_cart_shipping_packagesincludes\Bootstrap\Main.php:348
filterwoocommerce_package_ratesincludes\Bootstrap\Main.php:359
actionwoocommerce_cart_calculate_feesincludes\Bootstrap\Main.php:383
actiondps_for_wc_email_reminderincludes\Bootstrap\Main.php:400
actioncsf_loadedincludes\Views\Admin\Settings_Panel\RenderSettingsPanel.php:33

Scheduled Events 1

lpac_dps_remove_passed_maxed_dates
Maintenance & Trust

Chwazi – Delivery & Pickup Scheduling for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 6, 2026
PHP min version7.4
Downloads17K

Community Trust

Rating100/100
Number of ratings27
Active installs600
Developer Profile

Chwazi – Delivery & Pickup Scheduling for WooCommerce Developer Profile

Uriahs Victor

5 plugins · 3K total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Chwazi – Delivery & Pickup Scheduling for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/delivery-and-pickup-scheduling-for-woocommerce/assets/css/style.css/wp-content/plugins/delivery-and-pickup-scheduling-for-woocommerce/assets/js/script.js/wp-content/plugins/delivery-and-pickup-scheduling-for-woocommerce/assets/css/bootstrap.min.css/wp-content/plugins/delivery-and-pickup-scheduling-for-woocommerce/assets/js/bootstrap.min.js/wp-content/plugins/delivery-and-pickup-scheduling-for-woocommerce/assets/js/custom.js
Script Paths
/wp-content/plugins/delivery-and-pickup-scheduling-for-woocommerce/assets/js/script.js/wp-content/plugins/delivery-and-pickup-scheduling-for-woocommerce/assets/js/bootstrap.min.js/wp-content/plugins/delivery-and-pickup-scheduling-for-woocommerce/assets/js/custom.js
Version Parameters
delivery-and-pickup-scheduling-for-woocommerce/assets/css/style.css?ver=delivery-and-pickup-scheduling-for-woocommerce/assets/js/script.js?ver=delivery-and-pickup-scheduling-for-woocommerce/assets/css/bootstrap.min.css?ver=delivery-and-pickup-scheduling-for-woocommerce/assets/js/bootstrap.min.js?ver=delivery-and-pickup-scheduling-for-woocommerce/assets/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
lpac-dps-settings-page
HTML Comments
<!-- Plugin Name: Chwazi - Delivery & Pickup Scheduling for WooCommerce --><!-- Author: Uriahs Victor --><!-- Plugin URI: https://chwazidatetime.com --><!-- License: GPL-2.0+ -->+9 more
Data Attributes
data-plugin-name="delivery-and-pickup-scheduling-for-woocommerce"data-plugin-version="1.4.9"
JS Globals
window.chwazi_vars
REST Endpoints
/wp-json/lpac-dps/v1/settings
FAQ

Frequently Asked Questions about Chwazi – Delivery & Pickup Scheduling for WooCommerce