Dewa Kirim – WooCommerce Gojek / Gosend Security & Risk Analysis

wordpress.org/plugins/dewa-kirim-woocommerce-gojek

Dewa Kirim Gojek add shipping on demand services like gojek features to your website. Needs WooCommerce to work. WooCommerce 3.4.x compatible.

10 active installs v1.0.0 PHP 5.2.4+ WP 4.0+ Updated Sep 28, 2018
carrierdeliveryshippingtrackingwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dewa Kirim – WooCommerce Gojek / Gosend Safe to Use in 2026?

Generally Safe

Score 85/100

Dewa Kirim – WooCommerce Gojek / Gosend has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of the "dewa-kirim-woocommerce-gojek" v1.0.0 plugin reveals a surprisingly small attack surface with zero identified entry points that lack authentication or permission checks. The plugin also demonstrates good practices by exclusively using prepared statements for all SQL queries and performing file operations. However, there are areas of concern. Notably, only 50% of output escaping is properly implemented, suggesting potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully in the unescaped outputs. Additionally, the lack of explicit nonce checks and capability checks on any potential (though currently unidentified) entry points is a significant weakness, leaving it vulnerable to CSRF attacks if such points were to exist or be added later. The plugin makes an external HTTP request, which, without further analysis of its purpose and destination, carries a moderate risk of being exploited for various attacks, such as information disclosure or further exploitation if the external service is compromised.

The vulnerability history is currently empty, showing zero known CVEs. This is a positive indicator, suggesting that the plugin has either been free of significant security flaws or that any past issues have been promptly addressed and patched. The absence of recorded vulnerabilities in its history, combined with the secure handling of SQL, is a strength. However, it's crucial to remember that a clean history doesn't guarantee future security, especially given the identified weaknesses in output escaping and the absence of nonce/capability checks. The plugin's current security posture is a mixed bag; it has a minimal attack surface and handles data storage securely, but critical security hygiene practices like thorough output escaping and robust authentication mechanisms for all actions are either missing or not evident from this analysis.

Key Concerns

  • Partial output escaping
  • Missing nonce checks
  • Missing capability checks
  • External HTTP requests without context
Vulnerabilities
None known

Dewa Kirim – WooCommerce Gojek / Gosend Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Dewa Kirim – WooCommerce Gojek / Gosend Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

50% escaped8 total outputs
Attack Surface

Dewa Kirim – WooCommerce Gojek / Gosend Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionwoocommerce_after_order_notesincludes\shipping-frontend.php:50
actionwoocommerce_checkout_update_order_metaincludes\shipping-frontend.php:69
actionwp_footerincludes\shipping-frontend.php:450
actionwp_enqueue_scriptsincludes\shipping-frontend.php:473
actionwoocommerce_checkout_update_order_reviewincludes\shipping-frontend.php:475
actionwoocommerce_thankyouincludes\shipping-frontend.php:487
actionwoocommerce_view_orderincludes\shipping-frontend.php:488
actionwoocommerce_shipping_initincludes\shipping-method.php:541
filterwoocommerce_shipping_methodsincludes\shipping-method.php:549
actionadmin_enqueue_scriptsincludes\shipping-method.php:589
actionadd_meta_boxesincludes\shipping-method.php:591
Maintenance & Trust

Dewa Kirim – WooCommerce Gojek / Gosend Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedSep 28, 2018
PHP min version5.2.4
Downloads3K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

Dewa Kirim – WooCommerce Gojek / Gosend Developer Profile

dewakirim

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dewa Kirim – WooCommerce Gojek / Gosend

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dewa-kirim-woocommerce-gojek/assets/img/pinpoint.png
Version Parameters
dewa-kirim-woocommerce-gojek/style.css?ver=dewa-kirim-woocommerce-gojek/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
display-nonegojek-errormodal-gojek-wrappermodal-gojek-centermodal-gojek-contentmodal-gojek-closegojek-pinpointimage-pinpoint+1 more
Data Attributes
data-gojek-shipping
JS Globals
woocommerce_gojek_plugin_urlgoogleinitMapmapmarkergeocoder+3 more
Shortcode Output
<div class="gojek-error">The choice of gojek delivery is not available due to the weight of the items in your shopping cart is [cart_weight], exceeding the shipping conditions is [max_weight]. </div>
FAQ

Frequently Asked Questions about Dewa Kirim – WooCommerce Gojek / Gosend