Frakt123 Security & Risk Analysis

wordpress.org/plugins/frakt123

Frakt123 makes B2C and B2B shipping in Norway easy and affordable. With this plugin, you can easily transfer order-data from WooCommerce to Frakt123.

90 active installs v3.6 PHP + WP 5.3+ Updated Feb 26, 2026
e-commerceorderpre-ordershipmentwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Frakt123 Safe to Use in 2026?

Generally Safe

Score 100/100

Frakt123 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "frakt123" v3.6 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing SQL queries exclusively with prepared statements, and properly escaping all identified output. It also has no known vulnerabilities in its history, suggesting a generally stable development approach. However, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers that lack any authentication checks, creating direct entry points for potential attackers to exploit. This absence of nonce and capability checks on these handlers is a critical oversight. While the taint analysis shows no immediate critical or high severity flows, the lack of protective measures on these entry points means that any future vulnerabilities introduced in the logic handling these AJAX requests could be easily exploited. The plugin's reliance on external HTTP requests, while not inherently a vulnerability, adds a minor indirect risk if the external services are compromised or unavailable, but this is not a direct code flaw.

In conclusion, "frakt123" v3.6 has strengths in its core code hygiene regarding SQL and output escaping. However, the unprotected AJAX endpoints are a substantial security weakness that significantly elevates its risk profile. The absence of any vulnerability history is encouraging but does not negate the immediate risks posed by the exposed AJAX handlers. The plugin would benefit greatly from implementing robust authentication and authorization checks on all its entry points.

Key Concerns

  • AJAX handlers without authentication
  • AJAX handlers without capability checks
  • No nonce checks on entry points
Vulnerabilities
None known

Frakt123 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Frakt123 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface
2 unprotected

Frakt123 Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_frakt123_response_saveincludes\class-frakt123-custom-shipping-order-sync-core.php:45
authwp_ajax_frakt123_shipment_saveincludes\class-frakt123-custom-shipping-order-sync-core.php:46
WordPress Hooks 6
actionadmin_enqueue_scriptsfrakt123.php:130
filterwoocommerce_get_settings_pagesfrakt123.php:225
actionadmin_initfrakt123.php:231
actionwoocommerce_order_status_completedincludes\class-frakt123-custom-shipping-order-sync-core.php:32
actionwoocommerce_order_status_partial-shippedincludes\class-frakt123-custom-shipping-order-sync-core.php:33
actionadd_meta_boxesincludes\class-frakt123-custom-shipping-order-sync-core.php:44
Maintenance & Trust

Frakt123 Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 26, 2026
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

Frakt123 Developer Profile

Per Waagen

1 plugin · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Frakt123

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/frakt123/assets/js/meta-boxes-order-frakt123.js
Script Paths
/wp-content/plugins/frakt123/assets/js/meta-boxes-order-frakt123.js
Version Parameters
frakt123/assets/js/meta-boxes-order-frakt123.js?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/frakt123/v1/response/wp-json/frakt123/v1/shipment
FAQ

Frequently Asked Questions about Frakt123