Hi Express for WooCommerce Security & Risk Analysis

wordpress.org/plugins/hi-express-for-woocommerce

Integrate Hi Express shipping and delivery services with your WooCommerce store in Iraq.

0 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Feb 9, 2026
deliveryfulfillmentiraqshippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hi Express for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Hi Express for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "hi-express-for-woocommerce" v1.0.0 plugin exhibits a generally strong security posture, with a significant emphasis on secure coding practices. The plugin demonstrates excellent adherence to output escaping standards, with 99% of outputs being properly escaped. Furthermore, it utilizes prepared statements for all its SQL queries and has no recorded vulnerabilities, indicating a history of secure development. The presence of nonce and capability checks on 6 entry points also suggests a good understanding of WordPress security mechanisms.

However, there are a few areas that warrant attention. The plugin exposes one REST API route without permission callbacks, creating a potential avenue for unauthorized access if the functionality of this route is sensitive. While the taint analysis did not reveal critical or high-severity issues, one flow with an unsanitized path was identified. This, coupled with the single unprotected REST API endpoint, presents a minor but present risk that should be investigated and mitigated. The attack surface, while relatively small, does have a single unprotected entry point.

In conclusion, the plugin is built on a solid foundation of secure coding. The lack of historical vulnerabilities is a positive indicator. The primary concern lies with the unprotected REST API route, which, if handling sensitive operations, could be a point of exploitation. Addressing this single unprotected entry point and thoroughly reviewing the identified unsanitized path flow would significantly enhance the plugin's security.

Key Concerns

  • REST API route without permission callbacks
  • Flows with unsanitized paths
Vulnerabilities
None known

Hi Express for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hi Express for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
146 escaped
Nonce Checks
6
Capability Checks
6
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

99% escaped148 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

6 flows1 with unsanitized paths
bulk_admin_notices (includes\class-hi-express-orders.php:55)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Hi Express for WooCommerce Attack Surface

Entry Points8
Unprotected1

AJAX Handlers 7

authwp_ajax_hi_express_test_connectionadmin\class-hi-express-admin.php:31
authwp_ajax_hi_express_register_webhookadmin\class-hi-express-admin.php:32
authwp_ajax_hi_express_test_webhook_deliveryadmin\class-hi-express-admin.php:33
authwp_ajax_hi_express_print_labelincludes\class-hi-express-labels.php:26
authwp_ajax_hi_express_send_orderincludes\class-hi-express-orders.php:29
authwp_ajax_hi_express_track_orderincludes\class-hi-express-orders.php:30
authwp_ajax_hi_express_cancel_shipmentincludes\class-hi-express-orders.php:31

REST API Routes 1

POST/wp-json/hi-express/v1/webhookincludes\class-hi-express-webhooks.php:42
WordPress Hooks 24
actionadmin_menuadmin\class-hi-express-admin.php:28
actionadmin_initadmin\class-hi-express-admin.php:29
actionadmin_enqueue_scriptsadmin\class-hi-express-admin.php:30
actionadmin_noticesadmin\class-hi-express-admin.php:40
actionadmin_footeradmin\class-hi-express-admin.php:43
actionadmin_noticeshi-express-woocommerce.php:46
actionplugins_loadedhi-express-woocommerce.php:90
filterwoocommerce_shipping_methodshi-express-woocommerce.php:100
actionbefore_woocommerce_inithi-express-woocommerce.php:105
filterwoocommerce_countriesincludes\class-hi-express-checkout.php:25
filterwoocommerce_statesincludes\class-hi-express-checkout.php:28
actionadmin_menuincludes\class-hi-express-labels.php:29
actionadd_meta_boxesincludes\class-hi-express-orders.php:26
filterbulk_actions-edit-shop_orderincludes\class-hi-express-orders.php:34
filterbulk_actions-woocommerce_page_wc-ordersincludes\class-hi-express-orders.php:35
filterhandle_bulk_actions-edit-shop_orderincludes\class-hi-express-orders.php:36
filterhandle_bulk_actions-woocommerce_page_wc-ordersincludes\class-hi-express-orders.php:37
filtermanage_edit-shop_order_columnsincludes\class-hi-express-orders.php:40
filtermanage_woocommerce_page_wc-orders_columnsincludes\class-hi-express-orders.php:41
actionmanage_shop_order_posts_custom_columnincludes\class-hi-express-orders.php:42
actionmanage_woocommerce_page_wc-orders_custom_columnincludes\class-hi-express-orders.php:43
actionadmin_noticesincludes\class-hi-express-orders.php:49
actionwoocommerce_shipping_initincludes\class-hi-express-shipping.php:203
actionrest_api_initincludes\class-hi-express-webhooks.php:23
Maintenance & Trust

Hi Express for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version7.4
Downloads125

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hi Express for WooCommerce Developer Profile

hiexpress

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hi Express for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hi-express-for-woocommerce/admin/css/hi-express-admin.css/wp-content/plugins/hi-express-for-woocommerce/admin/js/hi-express-admin.js
Script Paths
/wp-content/plugins/hi-express-for-woocommerce/admin/js/hi-express-admin.js
Version Parameters
hi-express-for-woocommerce/admin/css/hi-express-admin.css?ver=hi-express-for-woocommerce/admin/js/hi-express-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
hi-express-bulk-loadinghi-express-spinnerhi-express-settings
Data Attributes
data-hi-express-key
JS Globals
hi_express_admin_params
FAQ

Frequently Asked Questions about Hi Express for WooCommerce