DWP Courier & Delivery Management Security & Risk Analysis

wordpress.org/plugins/dwp-courier-delivery-management

Delivery management plugins for moving companies. Easy to create merchant account and delivery list in dashboard.

10 active installs v1.0.1 PHP + WP 6.0+ Updated Sep 23, 2024
courierdeliverylogisticsmanagementpickup
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DWP Courier & Delivery Management Safe to Use in 2026?

Generally Safe

Score 92/100

DWP Courier & Delivery Management has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The dwp-courier-delivery-management plugin version 1.0.1 exhibits a mixed security posture. While the absence of known CVEs and reported vulnerability history is a positive indicator, the static analysis reveals significant concerns. The plugin has a small but unprotected attack surface, with one AJAX handler lacking authentication checks. This presents a potential entry point for malicious actors to execute unauthorized actions.

Furthermore, the code analysis indicates potential weaknesses in input validation and authorization. Although SQL queries are largely prepared and output escaping is somewhat handled, the absence of capability checks on any entry points is a critical oversight. This means that even if an AJAX handler were secured with a nonce, an unauthenticated user could potentially trigger it if it's the only mechanism for protection.

In conclusion, the plugin's lack of historical vulnerabilities is encouraging, but the current version's static analysis flags serious security flaws, primarily the unprotected AJAX handler and the complete absence of capability checks. These issues, if exploited, could lead to unauthorized access or manipulation of the plugin's functionality. The presence of DataTables as a bundled library also warrants attention for potential versioning and vulnerability issues, although no specific data is provided here.

Key Concerns

  • Unprotected AJAX handler found
  • No capability checks on entry points
  • Bundled library (DataTables) without version info
Vulnerabilities
None known

DWP Courier & Delivery Management Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DWP Courier & Delivery Management Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
6 prepared
Unescaped Output
14
36 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

75% prepared8 total queries

Output Escaping

72% escaped50 total outputs
Attack Surface
1 unprotected

DWP Courier & Delivery Management Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_dwp_form_actionincludes\class-dwp-courier-management.php:165
WordPress Hooks 6
actionplugins_loadedincludes\class-dwp-courier-management.php:142
actionadmin_enqueue_scriptsincludes\class-dwp-courier-management.php:157
actionadmin_enqueue_scriptsincludes\class-dwp-courier-management.php:158
actionadmin_menuincludes\class-dwp-courier-management.php:161
actionwp_enqueue_scriptsincludes\class-dwp-courier-management.php:180
actionwp_enqueue_scriptsincludes\class-dwp-courier-management.php:181
Maintenance & Trust

DWP Courier & Delivery Management Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 23, 2024
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

DWP Courier & Delivery Management Developer Profile

Drag WP

5 plugins · 1K total installs

95
trust score
Avg Security Score
93/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect DWP Courier & Delivery Management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dwp-courier-delivery-management/admin/css/dwp-courier-management-admin.css/wp-content/plugins/dwp-courier-delivery-management/assets/css/bootstrap.min.css/wp-content/plugins/dwp-courier-delivery-management/assets/bootstrap/bootstrap-icons.css/wp-content/plugins/dwp-courier-delivery-management/assets/css/jquery.dataTables.min.css/wp-content/plugins/dwp-courier-delivery-management/assets/css/sweetalert.min.css/wp-content/plugins/dwp-courier-delivery-management/admin/js/dwp-courier-management-admin.js/wp-content/plugins/dwp-courier-delivery-management/assets/js/bootstrap.min.js/wp-content/plugins/dwp-courier-delivery-management/assets/js/jquery.dataTables.min.js+2 more
Script Paths
plugin_dir_url( __FILE__ ) . 'js/dwp-courier-management-admin.js'DWP_COURIER_MANAGEMENT_PLUGIN_URL . 'assets/js/bootstrap.min.js'DWP_COURIER_MANAGEMENT_PLUGIN_URL . 'assets/js/jquery.dataTables.min.js'DWP_COURIER_MANAGEMENT_PLUGIN_URL . 'assets/js/sweetalert.min.js'DWP_COURIER_MANAGEMENT_PLUGIN_URL . 'assets/js/main.js'
Version Parameters
dwp-courier-delivery-management-admin.css?ver=bootstrap.min.css?ver=bootstrap-icons.css?ver=jquery.dataTables.min.css?ver=sweetalert.min.css?ver=dwp-courier-management-admin.js?ver=bootstrap.min.js?ver=jquery.dataTables.min.js?ver=sweetalert.min.js?ver=main.js?ver=

HTML / DOM Fingerprints

CSS Classes
dwp-courier-management-admin-css
HTML Comments
This function is provided for demonstration purposes only.Activator MethodIncluding Activator Inside the DeactivatorDeactivator Method
Data Attributes
data-toggledata-targetdata-dismiss
JS Globals
DWP_COURIER_MANAGEMENT_VERSIONDWP_COURIER_MANAGEMENT_PLUGIN_URLDWP_COURIER_MANAGEMENT_PLUGIN_PATHplugin_nameversiontable_activator+12 more
FAQ

Frequently Asked Questions about DWP Courier & Delivery Management