Enviamelo (Argentina) Security & Risk Analysis

wordpress.org/plugins/enviamelo

Realiza tus envíos de WooCommerce con Enviamelo.

10 active installs v1.0.5 PHP 7.0+ WP 5.4.1+ Updated Dec 14, 2021
enviameloshipmentswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Enviamelo (Argentina) Safe to Use in 2026?

Generally Safe

Score 85/100

Enviamelo (Argentina) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "enviamelo" plugin v1.0.5 exhibits a generally strong security posture based on the provided static analysis. The complete absence of any known CVEs, coupled with the fact that all identified SQL queries use prepared statements, is a significant positive. The code also demonstrates a decent level of output escaping, with 63% of outputs being properly handled. However, the analysis does highlight some areas of concern. Notably, there are zero capability checks and zero nonce checks across all entry points. While the attack surface is currently zero, this lack of authentication and authorization mechanisms leaves the plugin highly vulnerable should any entry points be exposed or added in future versions. The fact that there are no taint flows analyzed and no critical or high severity issues found in the static analysis could indicate either robust code or an incomplete analysis, and should be treated with caution.

In conclusion, "enviamelo" v1.0.5 appears to be built with some good security practices in mind, particularly regarding SQL injection prevention. The lack of a vulnerability history is also reassuring. Nevertheless, the complete absence of capability and nonce checks is a critical weakness that significantly elevates the risk profile, especially if the plugin's functionality expands or interfaces with user-contributed data in the future. A more thorough taint analysis would also be beneficial to confirm the absence of hidden vulnerabilities.

Key Concerns

  • Missing capability checks on all entry points
  • Missing nonce checks on all entry points
  • Below average output escaping (63%)
  • Taint analysis not performed or reported
Vulnerabilities
None known

Enviamelo (Argentina) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Enviamelo (Argentina) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
43
73 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

63% escaped116 total outputs
Attack Surface

Enviamelo (Argentina) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
filterwoocommerce_shipping_methodsHooks.php:5
filterwoocommerce_package_ratesHooks.php:6
actionwoocommerce_order_status_changedHooks.php:9
actionadd_meta_boxesHooks.php:10
actionwoocommerce_order_actionsHooks.php:11
actionwoocommerce_order_action_wc_enviamelo_order_actionHooks.php:12
filterwoocommerce_checkout_fieldsHooks.php:15
actionwoocommerce_checkout_update_order_metaHooks.php:16
filterwoocommerce_admin_billing_fieldsHooks.php:17
filterwoocommerce_admin_shipping_fieldsHooks.php:18
filterwoocommerce_order_details_before_order_tableHooks.php:19
filterwoocommerce_billing_fieldsHooks.php:20
filterwoocommerce_shipping_fieldsHooks.php:21
actionwoocommerce_admin_order_data_after_order_detailsHooks.php:22
actionwoocommerce_process_shop_order_metaHooks.php:23
actionwoocommerce_after_shipping_rateHooks.php:24
filterwoocommerce_my_account_my_orders_columnsHooks.php:29
actionwoocommerce_my_account_my_orders_column_wc-enviamelo-trackingHooks.php:30
actionwoocommerce_api_wc-enviamelo-ordersHooks.php:33
filterwoocommerce_get_sections_shippingHooks.php:37
filterwoocommerce_get_settings_shippingHooks.php:38
actionwoocommerce_update_options_enviamelo_shipping_optionsHooks.php:39
actionplugins_loadedwoo-enviamelo-arg.php:18
Maintenance & Trust

Enviamelo (Argentina) Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 14, 2021
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Enviamelo (Argentina) Developer Profile

manuelaborghi

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Enviamelo (Argentina)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
container_enviamelo_point
FAQ

Frequently Asked Questions about Enviamelo (Argentina)