
DeliveryPlus Security & Risk Analysis
wordpress.org/plugins/deliveryplus-by-invisible-dragonDeliveryPlus provides a delivery option with rate calculation and filter rules. Also integrates with Gravity Forms and Advanced Custom Fields.
Is DeliveryPlus Safe to Use in 2026?
Generally Safe
Score 92/100DeliveryPlus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The deliveryplus-by-invisible-dragon plugin, version 1.7, presents a mixed security posture. While it shows strengths in its avoidance of dangerous functions, SQL injection vulnerabilities through prepared statements, and no recorded historical CVEs, significant concerns arise from its attack surface and output escaping. The plugin exposes two AJAX handlers without any authentication checks, creating a direct entry point for unauthorized actions or information disclosure if these handlers perform sensitive operations. Furthermore, a concerning 62% of its output is not properly escaped, posing a high risk of cross-site scripting (XSS) vulnerabilities. The absence of nonce checks on AJAX handlers exacerbates the risk associated with these unprotected entry points. The lack of historical vulnerabilities might indicate past diligence or simply a lack of exploitation attempts, but the current static analysis reveals clear areas for improvement.
Key Concerns
- AJAX handlers without authentication
- Unescaped output detected
- Missing nonce checks on AJAX handlers
DeliveryPlus Security Vulnerabilities
DeliveryPlus Release Timeline
DeliveryPlus Code Analysis
Output Escaping
Data Flow Analysis
DeliveryPlus Attack Surface
AJAX Handlers 2
WordPress Hooks 24
Maintenance & Trust
DeliveryPlus Maintenance & Trust
Maintenance Signals
Community Trust
DeliveryPlus Alternatives
Smart COD for WooCommerce
wc-smart-cod
All the COD restrictions and extra fees you'll ever need, in a single plugin.
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Print Invoice & Delivery Notes for WooCommerce
woocommerce-delivery-notes
Create and print PDF invoices, delivery notes and receipts for your WooCommerce orders. Choose your document format from multiple templates.
Order Delivery Date for WooCommerce
order-delivery-date-for-woocommerce
Let customers choose delivery dates & times on checkout. Simplify delivery management by blocking holidays & setting max deliveries per day.
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
DeliveryPlus Developer Profile
2 plugins · 20 total installs
How We Detect DeliveryPlus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/deliveryplus-by-invisible-dragon/assets/css/deliveryplus.css/wp-content/plugins/deliveryplus-by-invisible-dragon/assets/js/deliveryplus.jsdeliveryplus-by-invisible-dragon/assets/css/deliveryplus.css?ver=deliveryplus-by-invisible-dragon/assets/js/deliveryplus.js?ver=HTML / DOM Fingerprints
deliveryplus_shipping_formdata-gform_iddata-gform_form_iddeliveryplus_shipping/wp-json/deliveryplus/v1/shipping_rates