
Shipi DHL Global Mail Shipping Security & Risk Analysis
wordpress.org/plugins/hitshipo-dhl-global-mail-shippingRealtime Shipping Rates, Order Creation automation included.
Is Shipi DHL Global Mail Shipping Safe to Use in 2026?
Generally Safe
Score 92/100Shipi DHL Global Mail Shipping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hitshipo-dhl-global-mail-shipping" v2.0.1 plugin exhibits a generally positive security posture due to the absence of known vulnerabilities and the use of prepared statements for all SQL queries. The code analysis indicates no dangerous functions are being used, and all output is properly escaped, which are strong indicators of good development practices in preventing common web vulnerabilities.
However, the static analysis reveals several areas for concern. The presence of 3 "flows with unsanitized paths" is particularly noteworthy, even though they are not classified as critical or high severity. This suggests a potential for path traversal or unintended file access if these flows are improperly handled downstream. Furthermore, the plugin makes 5 external HTTP requests, which can be a vector for vulnerabilities if the target endpoints are compromised or if sensitive data is transmitted insecurely. The complete lack of nonce and capability checks on any entry points, combined with zero protected AJAX handlers and REST API routes, indicates a significant potential attack surface that is entirely unprotected.
Key Concerns
- 3 flows with unsanitized paths detected
- 5 external HTTP requests
- 0 nonce checks
- 0 capability checks
- 0 unprotected AJAX handlers
- 0 unprotected REST API routes
Shipi DHL Global Mail Shipping Security Vulnerabilities
Shipi DHL Global Mail Shipping Code Analysis
Output Escaping
Data Flow Analysis
Shipi DHL Global Mail Shipping Attack Surface
WordPress Hooks 20
Maintenance & Trust
Shipi DHL Global Mail Shipping Maintenance & Trust
Maintenance Signals
Community Trust
Shipi DHL Global Mail Shipping Alternatives
WooCommerce Shipping
woocommerce-shipping
A free shipping plugin for US merchants to print discounted shipping labels and compare live label rates directly from your WooCommerce dashboard.
Apaczka: integracja z WooCommerce
apaczka-pl
Zarządzaj wysyłkami różnych kurierów w jednym miejscu
DHL Shipping Germany for WooCommerce
dhl-for-woocommerce
Automate e-commerce orders with Official DHL for WooCommerce. Covers DHL Paket and Deutsche Post International.
DHL eCommerce (Benelux) for WooCommerce
dhlpwc
DHL eCommerce (Benelux) presents: The official DHL eCommerce for WooCommerce plugin to automate your e-commerce shipping process.
Shipping Live Rates for DHL Express for WooCommerce
flexible-shipping-dhl-express
Display real-time DHL Express shipping live rates in your WooCommerce store. Connect with DHL Express API for accurate shipping costs.
Shipi DHL Global Mail Shipping Developer Profile
10 plugins · 610 total installs
How We Detect Shipi DHL Global Mail Shipping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hitshipo-dhl-global-mail-shipping/controllors/views/dhl_gm_settings_view.phpHTML / DOM Fingerprints
show_if_simpleshow_if_variable<!-- Exit if accessed directly. --><!-- Define WC_PLUGIN_FILE. --><!-- Include the main WooCommerce class. --><!-- Don't forget to exit() because wp_redirect doesn't exit automatically -->+1 moredata-tip="Enter commodity code for product (20 charcters max)."data-tip="Enter HS code for product (20 charcters max)."data-tip="Enter reason for export."wc_enhanced_selectchosen<label for="hits_dhl_gm_cc">Enter Commodity code</label><span class='woocommerce-help-tip' data-tip="Enter commodity code for product (20 charcters max)."></span><input type='text' id='hits_dhl_gm_cc' name='hits_dhl_gm_cc' maxlength="20" <label for="hits_dhl_gm_hs_code">Enter HS Code</label>