
Homerunner Security & Risk Analysis
wordpress.org/plugins/homerunner-smartcheckoutHomerunners modul hjælper dig til, at nemt håndtere fragtbestilling på dine ordre.
Is Homerunner Safe to Use in 2026?
Generally Safe
Score 99/100Homerunner has a strong security track record. Known vulnerabilities have been patched promptly.
The homerunner-smartcheckout plugin v1.0.34 exhibits a generally strong security posture based on the provided static analysis. The absence of direct SQL injection vulnerabilities, a high rate of output escaping, and the presence of nonce and capability checks on entry points are positive indicators. The limited attack surface of two AJAX handlers, with zero found to be unprotected, further bolsters this assessment. Taint analysis revealed no critical or high-severity unsanitized flows, which is excellent. The plugin also has no unpatched CVEs, indicating active maintenance concerning known security issues.
However, the presence of one past medium-severity vulnerability, specifically CSRF, is a point of concern, even though it is patched. While the plugin appears to have addressed this issue historically, it highlights a potential area for future attacks if not carefully managed. The plugin also makes 10 external HTTP requests, which, while not inherently a vulnerability, represents an increased attack surface and potential for supply chain attacks if any of these external services are compromised or respond maliciously. The lack of reported issues in the current static analysis is encouraging, but past vulnerabilities should always be a consideration for ongoing vigilance.
Key Concerns
- One past medium vulnerability (CSRF)
- 10 external HTTP requests
Homerunner Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Homerunner <= 1.0.30 - Cross-Site Request Forgery to Settings Update
Homerunner Code Analysis
Output Escaping
Data Flow Analysis
Homerunner Attack Surface
AJAX Handlers 2
WordPress Hooks 19
Maintenance & Trust
Homerunner Maintenance & Trust
Maintenance Signals
Community Trust
Homerunner Alternatives
Shipmondo for WooCommerce
shipmondo-for-woocommerce
Shipmondo for WooCommerce - Provide pick-up points in checkout and manage shipping easily
Weight Based Shipping Table Rate for WooCommerce – Flexible Shipping
flexible-shipping
Weight based shipping methods for WooCommerce. Flexible shipping with table rate rules by cart weight and order value. Accurate rates at checkout.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Weight Based Shipping for WooCommerce
weight-based-shipping-for-woocommerce
Weight Based Shipping is a flexible and widely-used solution to calculate shipping costs based on the total cart weight and value.
Advanced Shipment Tracking for WooCommerce
woo-advanced-shipment-tracking
Add shipment tracking info to WooCommerce orders, send tracking numbers to customers via email, and let them track deliveries from My Account.
Homerunner Developer Profile
1 plugin · 50 total installs
How We Detect Homerunner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/homerunner-smartcheckout/assets/css/checkout.css/wp-content/plugins/homerunner-smartcheckout/assets/js/checkout.js/wp-content/plugins/homerunner-smartcheckout/assets/js/checkout.jshomerunner-smartcheckout/assets/css/checkout.css?ver=homerunner-smartcheckout/assets/js/checkout.js?ver=HTML / DOM Fingerprints
homerunner-statushomerunner_operationshomerunner_tracking<!-- If this file is called directly, abort. --><!-- Deny access directly -->data-order_iddata-package_numbercheckout_script