
Epeken All Kurir for Woocommerce Security & Risk Analysis
wordpress.org/plugins/epeken-all-kurirEpeken All Kurir is a wordpress plugin for woocommerce to enable shipping method featuring many shipping companies for Indonesia e-commerce.
Is Epeken All Kurir for Woocommerce Safe to Use in 2026?
Use With Caution
Score 55/100Epeken All Kurir for Woocommerce has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The "epeken-all-kurir" v2.0.6 plugin exhibits a mixed security posture. While it demonstrates some good practices like a significant portion of SQL queries using prepared statements and a considerable number of output escapes, there are notable areas of concern. The static analysis reveals a substantial attack surface, with 11 total entry points, and importantly, one of these (a REST API route) lacks proper permission callbacks, presenting an immediate risk of unauthorized access or manipulation. Taint analysis indicates a significant number of flows with unsanitized paths (7 out of 9), although thankfully no critical or high-severity issues were identified in this analysis. The plugin's vulnerability history is a significant red flag. With three known CVEs, two of which remain unpatched, and a pattern of Cross-Site Scripting and Cross-Site Request Forgery vulnerabilities, it suggests a recurring weakness in input validation and access control. The most recent vulnerability being in the future also points to potential issues with versioning or reporting accuracy. The presence of unpatched vulnerabilities, coupled with an unprotected entry point and numerous unsanitized taint flows, elevates the risk associated with this plugin.
Key Concerns
- REST API route without permission callbacks
- Total known CVEs: 3
- Currently unpatched CVEs: 2
- Flows with unsanitized paths: 7
- Output escaping: 65% properly escaped
Epeken All Kurir for Woocommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Epeken All Kurir <= 2.0.2 - Authenticated (Shop manager+) Stored Cross-Site Scripting
Epeken All Kurir <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Epeken All Kurir <= 1.4.6.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Epeken All Kurir for Woocommerce Release Timeline
Epeken All Kurir for Woocommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Epeken All Kurir for Woocommerce Attack Surface
AJAX Handlers 8
REST API Routes 1
Shortcodes 2
WordPress Hooks 193
Maintenance & Trust
Epeken All Kurir for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Epeken All Kurir for Woocommerce Alternatives
Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce
ongkoskirim-id
OngkosKirim.id merupakan plugin ongkos kirim woocommerce dengan fitur terkomplit dan ekspedisi terlengkap, meliputi JNE, TIKI, POS, J&T, Sicepat, …
Shipping Discount for WooCommerce: Easy Make a Coupon for Shipping
shipping-discount
Want to make a strikeout price for shipping? It's easy to use the shipping discount plugin, all you have to do is set the shipping discount you w …
AgenWebsite Shipping – Plugin Ongkos Kirim & Generate Resi Otomatis Semua Kurir Indonesia
woocommerce-jne
Otomatisasi pengiriman WooCommerce dengan kurir terpercaya Indonesia. Tarif real-time, pelacakan instan, cetak resi otomatis - tanpa hitung manual!
JNE Shipping – Plugin Ongkos Kirim Resmi Untuk WooCommerce
jne-shipping-official
Plugin pengiriman JNE resmi untuk WooCommerce di Indonesia. Menyediakan tarif real-time, pembuatan AWB, dan pelacakan pengiriman.
JNE Indo Shipping
indo-shipping
Plugin shipping Indonesia yang khusus untuk diintegrasikan dengan plugin WP-Ecommerce.
Epeken All Kurir for Woocommerce Developer Profile
3 plugins · 450 total installs
How We Detect Epeken All Kurir for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/epeken-all-kurir/class/widget_cekresi.php/wp-content/plugins/epeken-all-kurir/includes/epeken_courier_ajax_backend.php/wp-content/plugins/epeken-all-kurir/includes/epeken_courier_end_points.php/wp-content/plugins/epeken-all-kurir/includes/epeken_konfirmasi_pembayaran.php/wp-content/plugins/epeken-all-kurir/class/shipping.php/wp-content/plugins/epeken-all-kurir/class/companies/lion.php/wp-content/plugins/epeken-all-kurir/class/companies/jmx.php/wp-content/plugins/epeken-all-kurir/class/companies/jnt.php+14 more/wp-content/plugins/epeken-all-kurir/style.css?ver=2.0.6HTML / DOM Fingerprints
epeken-kurirform-group epeken-form-groupepeken-kurir-header<!-- EPEKEN ALL KURIR FOR WOOCOMMERCE --><!-- EPEKEN ALL KURIR FOR WOOCOMMERCE -->data-jnedata-jne-truckingdata-posdata-wahanadata-sicepatdata-jnt+8 moreepeken_jvarsepeken_js_vars/wp-json/epeken/v1/jne_get_ongkir/wp-json/epeken/v1/jtr_get_ongkir/wp-json/epeken/v1/pos_get_ongkir/wp-json/epeken/v1/wahana_get_ongkir/wp-json/epeken/v1/sicepat_get_ongkir/wp-json/epeken/v1/jnt_get_ongkir/wp-json/epeken/v1/rpx_get_ongkir/wp-json/epeken/v1/jet_get_ongkir/wp-json/epeken/v1/dakota_get_ongkir/wp-json/epeken/v1/atlas_get_ongkir/wp-json/epeken/v1/custom_get_ongkir/wp-json/epeken/v1/nss_get_ongkir/wp-json/epeken/v1/jmx_get_ongkir/wp-json/epeken/v1/lion_get_ongkir/wp-json/epeken/v1/jne_trucking_get_ongkir/wp-json/epeken/v1/jne_get_tracking/wp-json/epeken/v1/jtr_get_tracking/wp-json/epeken/v1/pos_get_tracking/wp-json/epeken/v1/wahana_get_tracking/wp-json/epeken/v1/sicepat_get_tracking/wp-json/epeken/v1/jnt_get_tracking/wp-json/epeken/v1/rpx_get_tracking/wp-json/epeken/v1/jet_get_tracking/wp-json/epeken/v1/dakota_get_tracking/wp-json/epeken/v1/atlas_get_tracking/wp-json/epeken/v1/custom_get_tracking/wp-json/epeken/v1/nss_get_tracking/wp-json/epeken/v1/jmx_get_tracking/wp-json/epeken/v1/lion_get_tracking/wp-json/epeken/v1/jne_trucking_get_tracking