Grupo Logistico Andreani Security & Risk Analysis

wordpress.org/plugins/grupo-logistico-andreani

Plugin oficial de Andreani. Simplifica la gestión de tus envíos con Andreani. Este plugin te permite gestionar fácilmente todas tus entregas, optimiza …

100 active installs v1.0 PHP + WP 5.0+ Updated May 15, 2025
andreanigrupo-logistico-andreaniratesshippingwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Grupo Logistico Andreani Safe to Use in 2026?

Generally Safe

Score 92/100

Grupo Logistico Andreani has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "grupo-logistico-andreani" v1.0 exhibits a generally good security posture based on the static analysis. There are no identified direct entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication or permission checks. The code also demonstrates strong adherence to secure coding practices by exclusively using prepared statements for SQL queries and properly escaping almost all output, indicating a low risk of common injection vulnerabilities. The absence of file operations and the handling of external HTTP requests are not flagged as immediate concerns in this analysis.

However, the analysis does raise some minor concerns. The complete absence of nonce checks and capability checks, while not directly exploitable with the current entry points, suggests a lack of defense-in-depth. If new entry points were to be introduced or if existing handlers were found to be unprotected in a more detailed scan, these missing checks would significantly increase the risk. The presence of external HTTP requests, although only three and not flagged as problematic in taint analysis, warrants careful monitoring as they can sometimes be vectors for vulnerabilities if not handled with utmost care regarding input validation and response handling.

Furthermore, the plugin has no recorded vulnerability history, which is a positive sign. This could indicate either a very mature and secure codebase, infrequent updates that haven't exposed vulnerabilities, or simply a lack of public disclosure. While the current analysis shows no critical or high-severity issues, the lack of historical data makes it difficult to definitively assess long-term security trends or the plugin's responsiveness to past security challenges. Overall, the plugin is well-developed from a security perspective with the current data, but has areas for improvement in its defensive mechanisms.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • External HTTP requests without further context
Vulnerabilities
None known

Grupo Logistico Andreani Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Grupo Logistico Andreani Release Timeline

v2.1
v2.0
v1.0Current
Code Analysis
Analyzed Apr 16, 2026

Grupo Logistico Andreani Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
49 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

98% escaped50 total outputs
Attack Surface

Grupo Logistico Andreani Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_noticesgrupo-logistico-andreani.php:63
actionwoocommerce_shipping_initgrupo-logistico-andreani.php:70
filterwoocommerce_shipping_methodsgrupo-logistico-andreani.php:79
actionadmin_enqueue_scriptsgrupo-logistico-andreani.php:87
filterwoocommerce_checkout_fieldsgrupo-logistico-andreani.php:123
actionadmin_noticesincludes/funciones.php:6
actionwp_footerincludes/funciones.php:8
actionwoocommerce_thankyouincludes/funciones.php:203
actionwoocommerce_checkout_update_order_metaincludes/funciones.php:207
filterwoocommerce_form_fieldincludes/funciones.php:236
actionwoocommerce_before_order_notesincludes/funciones.php:276
actionwoocommerce_after_shipping_calculatorincludes/funciones.php:310
actionwoocommerce_view_orderincludes/funciones.php:329
actionwoocommerce_admin_order_data_after_order_detailsincludes/funciones.php:331
filterwoocommerce_checkout_fieldsincludes/funciones.php:344
actionwoocommerce_admin_order_data_after_billing_addressincludes/funciones.php:356
Maintenance & Trust

Grupo Logistico Andreani Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMay 15, 2025
PHP min version
Downloads2K

Community Trust

Rating20/100
Number of ratings3
Active installs100
Developer Profile

Grupo Logistico Andreani Developer Profile

Fernando Vazquez

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Grupo Logistico Andreani

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/grupo-logistico-andreani/includes/js/funciones.js
Script Paths
wp-content/plugins/grupo-logistico-andreani/includes/js/funciones.js
Version Parameters
grupo-logistico-andreani/style.css?ver=grupo-logistico-andreani/includes/js/funciones.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Exit if accessed directly --><!-- Add plugin page links in the admin area --><!-- Hook the notice function to the admin_notices hook --><!-- Enqueue admin scripts -->+2 more
Data Attributes
data-plugin-version="1.0.1"
JS Globals
ANDREANI_PLUGIN_URLANDREANI_VERSIONandreani_validar_cpandreani_enviar_ordenwp_session
FAQ

Frequently Asked Questions about Grupo Logistico Andreani