
Dewa Kirim – WooCommerce Gojek / Gosend Security & Risk Analysis
wordpress.org/plugins/dewa-kirim-woocommerce-gojekDewa Kirim Gojek add shipping on demand services like gojek features to your website. Needs WooCommerce to work. WooCommerce 3.4.x compatible.
Is Dewa Kirim – WooCommerce Gojek / Gosend Safe to Use in 2026?
Generally Safe
Score 85/100Dewa Kirim – WooCommerce Gojek / Gosend has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "dewa-kirim-woocommerce-gojek" v1.0.0 plugin reveals a surprisingly small attack surface with zero identified entry points that lack authentication or permission checks. The plugin also demonstrates good practices by exclusively using prepared statements for all SQL queries and performing file operations. However, there are areas of concern. Notably, only 50% of output escaping is properly implemented, suggesting potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully in the unescaped outputs. Additionally, the lack of explicit nonce checks and capability checks on any potential (though currently unidentified) entry points is a significant weakness, leaving it vulnerable to CSRF attacks if such points were to exist or be added later. The plugin makes an external HTTP request, which, without further analysis of its purpose and destination, carries a moderate risk of being exploited for various attacks, such as information disclosure or further exploitation if the external service is compromised.
The vulnerability history is currently empty, showing zero known CVEs. This is a positive indicator, suggesting that the plugin has either been free of significant security flaws or that any past issues have been promptly addressed and patched. The absence of recorded vulnerabilities in its history, combined with the secure handling of SQL, is a strength. However, it's crucial to remember that a clean history doesn't guarantee future security, especially given the identified weaknesses in output escaping and the absence of nonce/capability checks. The plugin's current security posture is a mixed bag; it has a minimal attack surface and handles data storage securely, but critical security hygiene practices like thorough output escaping and robust authentication mechanisms for all actions are either missing or not evident from this analysis.
Key Concerns
- Partial output escaping
- Missing nonce checks
- Missing capability checks
- External HTTP requests without context
Dewa Kirim – WooCommerce Gojek / Gosend Security Vulnerabilities
Dewa Kirim – WooCommerce Gojek / Gosend Code Analysis
Output Escaping
Dewa Kirim – WooCommerce Gojek / Gosend Attack Surface
WordPress Hooks 11
Maintenance & Trust
Dewa Kirim – WooCommerce Gojek / Gosend Maintenance & Trust
Maintenance Signals
Community Trust
Dewa Kirim – WooCommerce Gojek / Gosend Alternatives
YITH WooCommerce Order & Shipment Tracking
yith-woocommerce-order-tracking
Add an easy tool to manage order shipping information of your shop and to notified your customers about the shipping.
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Sendle Shipping Plugin
official-sendle-shipping-method
Sendle is an award-winning, 100% carbon neutral, door-to-door shipping carrier, designed to help small businesses thrive with simple, reliable, afford …
SnappBox
snappbox
The SnappBox WordPress plugin offers a fast and simple way to register and manage order deliveries. By installing this plugin, you can send your store …
Custom Shipment Tracker for WooCommerce
custom-shipment-tracker-for-woocommerce
Track WooCommerce order shipment status with a timeline view. Admin can update status and choose whether to show dates.
Dewa Kirim – WooCommerce Gojek / Gosend Developer Profile
1 plugin · 10 total installs
How We Detect Dewa Kirim – WooCommerce Gojek / Gosend
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dewa-kirim-woocommerce-gojek/assets/img/pinpoint.pngdewa-kirim-woocommerce-gojek/style.css?ver=dewa-kirim-woocommerce-gojek/script.js?ver=HTML / DOM Fingerprints
display-nonegojek-errormodal-gojek-wrappermodal-gojek-centermodal-gojek-contentmodal-gojek-closegojek-pinpointimage-pinpoint+1 moredata-gojek-shippingwoocommerce_gojek_plugin_urlgoogleinitMapmapmarkergeocoder+3 more<div class="gojek-error">The choice of gojek delivery is not available due to the weight of the items in your shopping cart is [cart_weight], exceeding the shipping conditions is [max_weight].
</div>