
Ahamove WooCommerce Security & Risk Analysis
wordpress.org/plugins/giao-hang-sieu-tocPlugin hỗ trợ đặt đơn Ahamove (Giao hàng siêu tốc) với WooCommerce.
Is Ahamove WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Ahamove WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "giao-hang-sieu-toc" v1.0.0 plugin exhibits a significant security risk due to its unprotected AJAX endpoints. With 8 AJAX handlers identified and all of them lacking authentication checks, this plugin presents a wide attack surface for unauthorized access and execution of plugin functionalities. While the plugin demonstrates good practices in SQL query preparation (83%) and output escaping (96%), the absence of any nonce or capability checks on its AJAX endpoints is a critical oversight that bypasses fundamental WordPress security mechanisms.
The taint analysis, although with a small number of flows, shows that all three analyzed flows have unsanitized paths. While no critical or high severity taint issues were flagged, this indicates a potential for input validation and sanitization vulnerabilities that could be exploited, especially in conjunction with the unprotected AJAX handlers. The lack of any recorded vulnerability history in the past is a positive indicator, suggesting that the developers might have been diligent in addressing past issues. However, this does not negate the current, actively identified vulnerabilities in the code.
In conclusion, the plugin has strengths in its SQL and output handling, but these are overshadowed by the critical weakness of unprotected AJAX endpoints and concerning taint flow analysis. The total lack of nonce and capability checks on these critical entry points makes it highly vulnerable to various attacks, including unauthorized data manipulation or execution of arbitrary code within the plugin's context. This plugin should be considered high risk until these security deficiencies are addressed.
Key Concerns
- 8 unprotected AJAX handlers
- 0 Nonce checks on AJAX handlers
- 0 Capability checks on AJAX handlers
- 3 flows with unsanitized paths
- 17% of SQL queries not prepared
Ahamove WooCommerce Security Vulnerabilities
Ahamove WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ahamove WooCommerce Attack Surface
AJAX Handlers 8
WordPress Hooks 6
Maintenance & Trust
Ahamove WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Ahamove WooCommerce Alternatives
Shipping Viet Nam WooCommerce
shipping-viet-nam-woocommerce
Plugin hỗ trợ toàn diện giao vận tại Việt Nam cho WooCommerce. Khách hàng chủ động chọn đơn vị giao vận và các gói giao vận ( Nhanh, Chuẩn, Tiết Kiệm ) tuỳ theo hầu bao của mình, việc này tạo sự tin tưởng cho người mua vì công khai chi phí ship giúp tăng tỉ lệ đặt hàng cho quản trị shop. Quản trị shop dễ dàng đăng vận đơn lên các đơn vị giao vận tuỳ theo lựa chọn của khách hàng khi đặt hàng chỉ với 1 Click, cùng với đó là tra cứu trạng thái vận đơn ngay từ trang quản trị.
Vietnam Checkout for WooCommerce
woo-vietnam-checkout
Vietnam Checkout for WooCommerce - Thêm Tỉnh/Thành phố, Phường/Xã vào form checkout của Woo và tối giản form checkout cho phù hợp với Việt Nam
Multi-Step Checkout for WooCommerce
wp-multi-step-checkout
Split the different sections of the default WooCommerce checkout page into multiple steps. Allow your customers a faster and easier checkout process.
Magical Shop Builder – WooCommerce Template Builder for Elementor | Shop, Cart, Checkout & Product Page Builder
magical-products-display
The complete WooCommerce Shop Builder for Elementor. Build custom single product pages, cart, checkout, my account & shop archives with 60+ widgets.
Comunas de Chile para WooCommerce
comunas-de-chile-para-woocommerce
Agrega las Comunas de Chile a WooCommerce para mejorar la experiencia de envío.
Ahamove WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect Ahamove WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/giao-hang-sieu-toc/assets/css/admin.css/wp-content/plugins/giao-hang-sieu-toc/assets/js/admin.js/wp-content/plugins/giao-hang-sieu-toc/assets/js/admin.jsghst-admin1.0.0HTML / DOM Fingerprints
ghst_shippingghst_admin_paramsghst_admin_params/wp-json/ghstwoo/