
EnviFast Shipping Security & Risk Analysis
wordpress.org/plugins/envifast-shippingEste plugin te ayudará con la gestión de envíos en tu tienda en linea
Is EnviFast Shipping Safe to Use in 2026?
Generally Safe
Score 92/100EnviFast Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "envifast-shipping" plugin exhibits a generally good security posture based on the provided static analysis. A low attack surface with only one AJAX handler, which fortunately appears to have a nonce check, is a positive indicator. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output and the presence of a nonce check suggest a developer mindful of common web security pitfalls. The plugin's vulnerability history is also clean, with no known CVEs, indicating a lack of previously identified security flaws.
While the static analysis reveals no critical or high-severity issues in taint flows, and the overall code quality appears strong, a notable concern is the complete absence of capability checks. This means that even though an AJAX handler has a nonce check, any authenticated user, regardless of their role or permissions, could potentially interact with it. This could lead to unintended actions or information disclosure if the AJAX handler performs sensitive operations. The lack of specific permission enforcement on the sole entry point is the primary area for improvement, as it broadens the potential impact of any future, unforeseen vulnerabilities.
In conclusion, the "envifast-shipping" plugin demonstrates a strong foundation in secure coding practices, particularly in its handling of SQL and output. The lack of vulnerability history is also a significant positive. However, the absence of capability checks on its entry point represents a potential weakness that should be addressed to further harden its security. The developer has shown a good understanding of many security principles, but can enhance it by implementing role-based access control for its functionalities.
Key Concerns
- Missing capability checks on AJAX handler
EnviFast Shipping Security Vulnerabilities
EnviFast Shipping Code Analysis
Output Escaping
Data Flow Analysis
EnviFast Shipping Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
EnviFast Shipping Maintenance & Trust
Maintenance Signals
Community Trust
EnviFast Shipping Alternatives
Veryk Ship for WooCommerce
veryk-ship-for-woocommerce
Global logistics service platform for WooCommerce with carrier integration.
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
The Courier Guy Shipping for WooCommerce
the-courier-guy
This is the official WooCommerce extension to ship products using The Courier Guy.
AppScenic – Smart AI Dropshipping
appscenic
Expand your store catalogue with no upfront inventory cost. Source high-quality products from verified domestic suppliers and use AI in the process.
CDEKDelivery
cdekdelivery
Integration with CDEK delivery for your WooCommerce store.
EnviFast Shipping Developer Profile
1 plugin · 10 total installs
How We Detect EnviFast Shipping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/envifast-shipping/assets/js/envifast-shipping-admin.js/wp-content/plugins/envifast-shipping/assets/css/envifast-shipping-admin.css/wp-content/plugins/envifast-shipping/assets/js/envifast-shipping-admin.jsenvifast-shipping/assets/js/envifast-shipping-admin.js?ver=envifast-shipping/assets/css/envifast-shipping-admin.css?ver=HTML / DOM Fingerprints
envifast_ready<!-- Meta box for showing status of Order info sent to EnviFast or sending it manually --><!-- Ajax call back to process manual sending order details to EnviFast --><!-- Columns for EnviFast ready status to Products in Product List of admin panel --><!-- Validating products being added to cart to make sure it has dimensions and weight set -->title