HgE: Shipping Zones for FAN Courier Romania Security & Risk Analysis

wordpress.org/plugins/hge-zone-de-livrare-pentru-fan-courier-romania

Standard FAN Courier integration for WooCommerce with automatic AWB generation, PDF labels, real-time tracking, and dynamic shipping rates.

0 active installs v1.0.12 PHP 8.1+ WP 5.0+ Updated Mar 2, 2026
awbfan-courierromaniashipping-zoneswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HgE: Shipping Zones for FAN Courier Romania Safe to Use in 2026?

Generally Safe

Score 100/100

HgE: Shipping Zones for FAN Courier Romania has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

This plugin exhibits a generally strong security posture with several good practices in place. The extensive use of prepared statements for SQL queries and a high percentage of properly escaped outputs are positive indicators. The plugin also implements a reasonable number of nonce and capability checks for its entry points. However, the presence of one AJAX handler without authentication checks presents a notable security concern. While there are no recorded vulnerabilities in its history, this does not guarantee future immunity, especially with an unprotected entry point. The taint analysis did reveal flows with unsanitized paths, although they were not flagged as critical or high severity, which still warrants attention. Overall, the plugin has strengths in its secure coding practices but requires immediate attention to address the unprotected AJAX handler to mitigate potential risks.

Key Concerns

  • AJAX handler without authentication
  • Taint analysis with unsanitized paths
Vulnerabilities
None known

HgE: Shipping Zones for FAN Courier Romania Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

HgE: Shipping Zones for FAN Courier Romania Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
2
129 escaped
Nonce Checks
5
Capability Checks
13
File Operations
0
External Requests
7
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

98% escaped131 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

6 flows3 with unsanitized paths
bulk_awb_admin_notice (includes\class-hgezlpfcr-admin-order.php:957)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

HgE: Shipping Zones for FAN Courier Romania Attack Surface

Entry Points4
Unprotected1

AJAX Handlers 4

authwp_ajax_hgezlpfcr_generate_awb_ajaxincludes\class-hgezlpfcr-admin-order.php:195
authwp_ajax_hgezlpfcr_sync_awbincludes\class-hgezlpfcr-admin-order.php:196
authwp_ajax_hgezlpfcr_restore_awbincludes\class-hgezlpfcr-admin-order.php:197
authwp_ajax_hgezlpfcr_dismiss_activation_noticewoo-fancourier.php:153
WordPress Hooks 36
actionadd_meta_boxesincludes\class-hgezlpfcr-admin-order.php:162
actionadd_meta_boxes_shop_orderincludes\class-hgezlpfcr-admin-order.php:165
actionwoocommerce_initincludes\class-hgezlpfcr-admin-order.php:168
actionadmin_post_hgezlpfcr_generate_awbincludes\class-hgezlpfcr-admin-order.php:178
actionadmin_post_hgezlpfcr_download_awbincludes\class-hgezlpfcr-admin-order.php:179
actionadmin_post_hgezlpfcr_sync_awbincludes\class-hgezlpfcr-admin-order.php:180
filtermanage_edit-shop_order_columnsincludes\class-hgezlpfcr-admin-order.php:183
actionmanage_shop_order_posts_custom_columnincludes\class-hgezlpfcr-admin-order.php:184
filtermanage_woocommerce_page_wc-orders_columnsincludes\class-hgezlpfcr-admin-order.php:185
actionmanage_woocommerce_page_wc-orders_custom_columnincludes\class-hgezlpfcr-admin-order.php:186
filterbulk_actions-edit-shop_orderincludes\class-hgezlpfcr-admin-order.php:189
filterhandle_bulk_actions-edit-shop_orderincludes\class-hgezlpfcr-admin-order.php:190
filterbulk_actions-woocommerce_page_wc-ordersincludes\class-hgezlpfcr-admin-order.php:191
filterhandle_bulk_actions-woocommerce_page_wc-ordersincludes\class-hgezlpfcr-admin-order.php:192
actionhgezlpfcr_generate_awb_asyncincludes\class-hgezlpfcr-admin-order.php:200
actionhgezlpfcr_sync_awb_asyncincludes\class-hgezlpfcr-admin-order.php:201
actionhgezlpfcr_restore_awb_asyncincludes\class-hgezlpfcr-admin-order.php:202
actionadmin_noticesincludes\class-hgezlpfcr-admin-order.php:205
actionadmin_noticesincludes\class-hgezlpfcr-admin-order.php:206
actionadmin_enqueue_scriptsincludes\class-hgezlpfcr-admin-order.php:209
actionadmin_post_hgezlpfcr_clear_tokenincludes\class-hgezlpfcr-admin-order.php:212
actionadmin_post_hgezlpfcr_reset_order_markersincludes\class-hgezlpfcr-admin-order.php:213
actionadmin_menuincludes\class-hgezlpfcr-healthcheck.php:17
actionadmin_post_hgezlpfcr_hc_actionincludes\class-hgezlpfcr-healthcheck.php:18
actionwoocommerce_admin_menuincludes\class-hgezlpfcr-healthcheck.php:21
actionadmin_noticesincludes\class-hgezlpfcr-integrity.php:96
actionupgrader_process_completeincludes\class-hgezlpfcr-integrity.php:100
actionadmin_initincludes\class-hgezlpfcr-integrity.php:104
filterwoocommerce_get_settings_pagesincludes\class-hgezlpfcr-settings.php:6
actionbefore_woocommerce_initwoo-fancourier.php:22
filterplugin_row_metawoo-fancourier.php:92
actionadmin_noticeswoo-fancourier.php:101
actionadmin_initwoo-fancourier.php:159
actionplugins_loadedwoo-fancourier.php:210
actionadmin_noticeswoo-fancourier.php:216
filterwoocommerce_shipping_methodswoo-fancourier.php:248

Scheduled Events 1

hgezlpfcr_delayed_awb_generation
Maintenance & Trust

HgE: Shipping Zones for FAN Courier Romania Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 2, 2026
PHP min version8.1
Downloads633

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

HgE: Shipping Zones for FAN Courier Romania Developer Profile

hge321

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HgE: Shipping Zones for FAN Courier Romania

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hge-zone-de-livrare-pentru-fan-courier-romania/assets/css/hge-zone-de-livrare-pentru-fan-courier-romania.css/wp-content/plugins/hge-zone-de-livrare-pentru-fan-courier-romania/assets/js/hge-zone-de-livrare-pentru-fan-courier-romania.js/wp-content/plugins/hge-zone-de-livrare-pentru-fan-courier-romania/assets/js/hge-zone-de-livrare-pentru-fan-courier-romania-admin.js/wp-content/plugins/hge-zone-de-livrare-pentru-fan-courier-romania/assets/js/hge-zone-de-livrare-pentru-fan-courier-romania-frontend.js
Script Paths
/wp-content/plugins/hge-zone-de-livrare-pentru-fan-courier-romania/assets/js/hge-zone-de-livrare-pentru-fan-courier-romania.js/wp-content/plugins/hge-zone-de-livrare-pentru-fan-courier-romania/assets/js/hge-zone-de-livrare-pentru-fan-courier-romania-admin.js/wp-content/plugins/hge-zone-de-livrare-pentru-fan-courier-romania/assets/js/hge-zone-de-livrare-pentru-fan-courier-romania-frontend.js
Version Parameters
hge-zone-de-livrare-pentru-fan-courier-romania/assets/css/hge-zone-de-livrare-pentru-fan-courier-romania.css?ver=hge-zone-de-livrare-pentru-fan-courier-romania/assets/js/hge-zone-de-livrare-pentru-fan-courier-romania.js?ver=hge-zone-de-livrare-pentru-fan-courier-romania/assets/js/hge-zone-de-livrare-pentru-fan-courier-romania-admin.js?ver=hge-zone-de-livrare-pentru-fan-courier-romania/assets/js/hge-zone-de-livrare-pentru-fan-courier-romania-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
hgezlpfcr-activation-notice
Data Attributes
data-plugin-name="HgE: Shipping Zones for FAN Courier Romania"data-plugin-version="1.0.12"
JS Globals
HGEZLPFCR_LOCK_TTLHGEZLPFCR_CACHE_TTLHGEZLPFCR_RATE_LIMIT_MAX_CALLSHGEZLPFCR_RATE_LIMIT_WINDOWHGEZLPFCR_TRACKING_BATCH_SIZEHGEZLPFCR_RETRY_DELAY_MS+10 more
FAQ

Frequently Asked Questions about HgE: Shipping Zones for FAN Courier Romania